Penetration testing for healthcare: what's required, what it costs and what to buy
By The PenTest Index · Sources checked October 9, 2026
Penetration testing for healthcare is a permitted attack on healthcare systems, and the right test depends on what you run: a clinic or hospital network, health software, or a medical device. HIPAA doesn't name it today, but New York's hospital rule requires one every year. Pentest-Tools.com lists $3,400 for one web app tested without logins.
Below: which test fits your kind of organization, the rules that really apply to you, real offers side by side, and a brief you can copy and send. Hospital and clinic network tests are almost always quoted, so the brief matters most there.
Which test fits your kind of healthcare organization?
Start with what you run. "A healthcare pentest" isn't one product. Asking for one is like asking a builder for "a medical building": a dentist's office and a hospital wing are different jobs.
| You are | Start here | What could change it | You may not need to buy if |
|---|---|---|---|
| A clinic or practice with an office network and a hosted records system | A test of the network you own, from outside and inside | You need written authorization that covers testing of a system you don't own. Ask your records vendor for its own latest test summary | Your IT firm or a qualified staff member already runs a real test, and your risk analysis says that's enough |
| A hospital or health system | Outside and inside network tests, plus a check that clinical and device networks are walled off from the office network | Anything connected to a patient stays out of active testing. In New York, state rules require a yearly test | You have a qualified internal team. New York's rule allows "a qualified internal or external party" |
| A health-software company (patient portal, telehealth, billing, records add-on) | A web app and API test using logged-in test accounts for each role | Your customer decides what report they accept. Ask them first | A recent test already covers this version and your customer accepts it |
| A health plan or payer | App, API and network tests | New York's financial regulator has its own yearly testing rule for the firms it covers. Confirm whether that includes you | An existing testing program already covers it |
| A medical device maker | A device test | It's a different purchase. See medical device penetration testing | Not covered here |
| Anyone who takes card payments | Add the card systems to the scope | The card standard has its own 12-month rule | Card handling is fully outsourced, and your payment provider or assessor confirms it |
These are our suggested starting points. They don't decide which law applies to you.
A few plain definitions before we go on. A penetration test (pentest) is authorized testing that tries to break into your systems to show what a real attacker could do. A vulnerability scan is a tool checking for known weak spots. An API is the interface your software uses to exchange data with other software. Scope is the agreed list of what testers may and may not touch.
Already know your route? Compare the offers or copy the brief.
Is penetration testing required in healthcare?
It depends on which rule you answer to. HIPAA's current text doesn't name penetration testing. New York's hospital rule and the card-payment standard do. A proposed HIPAA update would add it, but it isn't law.
| Rule | Who it covers | What the text says | Status |
|---|---|---|---|
| HIPAA Security Rule, 45 CFR 164.308(a)(1)(ii)(A) and (a)(8) | Health plans, clearinghouses, most providers, and their business associates | Requires "an accurate and thorough" risk analysis and "a periodic technical and nontechnical evaluation." The words "penetration test" don't appear in this section | In force. Read October 9, 2026 |
| Proposed HIPAA Security Rule update | The same groups | HHS's fact sheet: "Require vulnerability scanning at least every six months and penetration testing at least once every 12 months." It also says "the current Security Rule remains in effect" | Proposed, not in force. Published January 6, 2025. Read October 9, 2026 |
| New York 10 NYCRR 405.46(f)(2)(i) | General hospitals licensed in New York | "penetration testing of the hospital's information systems by a qualified internal or external party at least annually based upon the hospital's risk assessment" | Adopted October 2, 2024, with one year to comply. Read October 9, 2026 |
| PCI DSS v4.0.1, requirements 11.4.2 and 11.4.3 | Anyone handling card data in scope | A test at least once every 12 months and after significant changes | In force. From our rule tracker, checked October 8, 2026 |
| New York financial regulation, 23 NYCRR 500.5(a)(1) | Firms that regulation covers and that aren't exempt | Testing at least annually | In force. From our rule tracker, checked October 8, 2026 |
| HHS Cybersecurity Performance Goals | Any healthcare organization | One "enhanced" goal covers weaknesses "discovered through penetration testing and attack simulations" | Voluntary. HHS calls the goals voluntary. Read October 9, 2026 |
| Your contracts: customers, business partners, cyber insurance | You | Whatever the contract says | Read your own document |
Your regulator, assessor, customer or insurer decides what they accept. We report what the text says. This isn't legal advice.
Does HIPAA require penetration testing?
Not by name. Today's rule requires a risk analysis and a periodic technical evaluation. A penetration test can provide evidence for that technical evaluation. It is not the risk analysis itself, and passing one doesn't prove you comply.
HHS also says the evaluation "can be performed internally by the covered entity or by an external organization" (HHS FAQ, read October 9, 2026). So HIPAA today doesn't force you to hire an outside firm either.
What would the proposed HIPAA rule change?
It would make a yearly penetration test an explicit duty. HHS's proposal says the test would be done by "qualified person(s)" at least once every 12 months, or more often if your risk analysis calls for it.
It isn't final. The federal regulatory agenda lists it under "Long-Term Actions" with final action projected for July 2027 (read October 9, 2026). That is a projection, not a deadline. If a vendor tells you HIPAA "now requires" annual testing, ask them for the final rule.
What does New York require of hospitals?
A penetration test at least once a year, done by a qualified internal or external party. The same rule lists scans as a separate item, right below the test. So under that text, running a scanner is not the penetration test.
The proposed HIPAA update draws the same line: scans every six months, a penetration test every twelve.
What if a customer, insurer or contract asks for it?
Then that document is your rule. Don't guess what it means. Send the person who asked three questions:
- "Which systems should the test cover, and is anything excluded?"
- "What must the report show, and by when?"
- "Does an outside firm have to do it? How do you define independent?"
Their answers go straight into your brief.
Read the current HIPAA Security Rule text
Which offers deserve a closer look?
Health-software buyers have real published prices to compare today. Hospital and clinic buyers mostly don't, so a shared brief is how they make quotes line up. Either way, get two things in writing before you sign: how patient data stays out of the test, and when the retest window closes.
We read each provider's own pages on October 9, 2026. The offer facts below come from those pages; the open questions and Purchase Check findings are ours. We have not bought these services or read a delivered report. Companies are A to Z in each group. This is not a ranking.
This site may contain affiliate or referral links. If you buy through one, we may be compensated.
Web app and API tests (health software)
| Offer | Published price (US dollars) and commitment | Retest terms as published | Healthcare notes and open questions |
|---|---|---|---|
| Astra, Pentest Expert | $5,999 per year, per target. One web app counts as one target, "including all APIs consumed." A yearly plan, not a one-time project | Two re-scans by experts. Must be requested within 30 days "from the date the vulnerabilities were reported." Extensions "case-by-case" | Patient-data handling and BAA terms not stated on the pages we read |
| Cobalt, credit packages | Quote required. Credits are "sold in annual packages." One credit is "the equivalent of 8 hours" of testing through automation and people. That is not eight hours of human work. Credits "do not roll over" | For Agile and Comprehensive Pentests, its docs give 6 months (Standard) or 12 months (Premium, Enterprise), provided the contract stays active. The cutoff is the tier period or 10 days before contract end at 23:59 UTC, whichever comes first. Its pricing FAQ says "unlimited on-demand retesting throughout your contract term." Ask which applies | Patient-data handling and BAA terms not stated on the pages we read |
| Pentest-Tools.com, managed web app test | $3,400 fixed for a test without logins. From $3,400 + $900 per user role for a test with logins | None found on the page we read | 3 working days (best effort) without logins; 4 or more with. API coverage isn't priced by the formula |
| Software Secured, Web & API Pentesting | Starts at $10,800 USD. Scope depends on "endpoints, codebase, auth, integrations" | The service card says "3 rounds over 12 months." The package grid on the same page says Standard includes 1 round, Standard Plus 3, Premium unlimited. Ask which package the starting price buys | Says it prefers staging or test environments and "we can sign your Business Associate Agreement (BAA)." States it is Canadian based |
View Astra's plans and pricing View Cobalt's pricing View the managed web app test View Software Secured's pricing
Sources: Astra pricing and rescan rules; Cobalt pricing and retest docs; Pentest-Tools.com service page; Software Secured pricing and healthcare page.
Network tests (hospitals and clinics)
| Offer | Published price and commitment | Retest terms as published | Healthcare notes and open questions |
|---|---|---|---|
| Clearwater, Technical Testing | Quote required. No price found | None found | A healthcare-focused firm. Its list includes internal and external penetration testing, web app, API, wireless, and medical device assessments. It describes "comprehensive manual testing." Ask which of these your quote includes |
| NetSPI, Network Penetration Testing | Quote required. No price found | None found on the network page we read | Describes its work as "Human-Led" by "350+ pentesters" who are "Employed, not outsourced." Clinical safety rules not stated |
| Software Secured, network tests | External from $5,400. Internal from $7,700. The page shows no currency on these two prices; its app prices are marked USD | External: 1 round over 12 months. Internal: 3 rounds over 12 months | General network offers, not hospital packages. Sites, size and clinical rules will change the quote |
View Clearwater's technical testing View NetSPI's network testing
Sources: Clearwater technical testing; NetSPI network testing; Software Secured pricing.
Offers led by AI are a separate group. See the full comparison and ask whoever needs your report whether they accept one.
Our read for a health-software buyer
Say you run a 45-person telehealth company. You have one patient web app and one API, with two roles: patient and clinician. A hospital customer wants a test done by people, a report, and proof that fixes were rechecked. Your engineers need 60 days after the report to finish fixes. You want one project, not a yearly plan. This company is made up.
For that buyer, we would ask Software Secured and Pentest-Tools.com for itemized quotes first. Astra's and Cobalt's published offers each miss one of this buyer's must-haves. Here is the check, one condition at a time:
| Must-have | Offer | Finding | Send this question |
|---|---|---|---|
| App, API and two logged-in roles | Pentest-Tools.com, test with logins | Supported, starting amount only. $3,400 + (2 × $900) = $5,200. The formula doesn't price the API or a retest | "For this app, its API and two roles, what is the full price?" |
| Fixes rechecked 60 days after the report | Astra Pentest Expert | Mismatch. Re-scans must be requested within 30 days of findings being reported. Day 60 is outside that | "Will you extend the re-scan window to 60 days in writing, and what does it cost?" |
| Fixes rechecked 60 days after the report | Software Secured | Supported on the window. Retests can be requested within 12 months of report delivery. How many rounds the starting price includes is unresolved | "Which package is this quote, and how many retest rounds does it include?" |
| Fixes rechecked 60 days after the report | Pentest-Tools.com | Unresolved. No retest terms found | "Is a retest at day 60 included? If not, what does it cost?" |
| One project, no yearly plan | Cobalt credit packages | Mismatch. Credits are sold in annual packages | "Can we buy a single test without an annual package?" |
| One project, no yearly plan | Astra Pentest Expert | Mismatch. The published plan is priced per year | "Is there a one-time option?" |
| Testers the hospital counts as independent | All four | Unresolved. It depends on the hospital's definition | To the hospital: "How do you define independent?" |
| No real patient data in the test, and a BAA if one is needed | Software Secured | Supported in part. It says it can sign one and prefers test environments. Nothing is signed until you sign it | "Will your testers be able to see patient data? Send us your data-handling terms." |
| No real patient data in the test, and a BAA if one is needed | Astra, Cobalt, Pentest-Tools.com | Unresolved. Not stated on the pages we read | The same question |
"Supported" means that one condition is backed by what the provider published. It says nothing about test quality, and it doesn't mean your customer will accept the report. A mismatch on a must-have takes that offer off this buyer's list until a written answer changes it.
Two cautions. First, $5,200 and $10,800 are not prices for the same job. One doesn't price the API or a retest. Don't choose on price until both quotes name the same scope. Second, change one condition and the list changes. If this buyer were happy with a yearly plan, Cobalt comes back, and its retest cutoff date becomes the question to settle.
Testing a portal, app or API of your own? The right offer depends on your roles, your customer's report needs and how long your fixes take. Find My PenTest Match asks a few quick questions, shows which compared offers fit, and gives you a brief to send. It's free, with no email or sign-up, and nothing is sent to providers.
Our read for a hospital
Say you're the security lead at a 120-bed community hospital in New York. The state rule asks for a yearly penetration test. You have an office network, a clinical network with monitors and pumps, and a records system your vendor hosts. This hospital is made up.
Your first question isn't "who do I hire?" It's "do we have a qualified internal party?" The rule allows one. If you don't, ask for outside and inside network tests, plus a check of the wall between office and clinical networks. Nothing connected to a patient gets actively tested.
Published starting prices exist only for general networks. Software Secured lists external from $5,400 and internal from $7,700. Together that's $13,100 as a starting figure for two general network tests. It is not a hospital quote. Your number of sites, the size of your network and your clinical rules will move it.
On the must-have that matters most here, every offer above is unresolved. None of the pages we read publishes written clinical safety rules: testing hours, what's off limits, and who can call a stop. You get those by asking for them. Clearwater is the healthcare-focused route on this list, and NetSPI describes an employed testing team. Both quote.
One more duty from the same New York rule: keep the records. Section (n) says documentation must be kept at least six years.
Running a hospital or clinic network? Copy the healthcare brief and send the same one to each firm.
How much does a healthcare penetration test cost?
For health software, three providers we checked publish starting figures from $3,400 to $10,800 for one web app. Hospital and clinic network tests are almost always quoted. We found no published price for a whole hospital.
You will meet four kinds of price. Keep them apart:
- A starting price is the least you could pay, with conditions. Pentest-Tools.com's $3,400 is for a test without logins.
- A formula gives a starting amount for your shape. $3,400 plus $900 per role is one.
- A yearly plan describes the commitment, not the number of tests. Astra's $5,999 is per year, per target.
- A quote is a price for your scope. Compare it only after the scope and terms are written.
What moves a healthcare quote: how many sites and networks, how the clinical network is handled, how many logged-in roles, after-hours testing, on-site work, and retests.
You'll also see general ranges on vendor blogs with no source or date. Treat those as one company's opinion. They aren't a healthcare price, and we don't repeat them here.
Before you compare totals, make sure each quote states the full amount, the currency, what's due now, any yearly commitment, what's included and what costs extra. A missing line isn't zero. It's an unknown, and the total isn't finished until it's filled in.
For how pentest pricing works in general, see penetration testing cost.
What should penetration testing for healthcare include?
It should name every in-scope system that stores patient data or can reach it, with clear rules for anything near patient care. "Our network" on a quote tells you nothing about the portal, the cloud storage or the clinical floor.
| System | Write down | Question that makes quotes comparable | The healthcare catch |
|---|---|---|---|
| Internet-facing systems | Addresses, remote access, email | "Which addresses are tested?" | Remote access set up for outside vendors is easy to forget |
| Internal network | Sites, size, how staff log in | "From what starting point do you test?" | Shared workstations in care areas |
| Clinical and device network | How it's separated from the office network | "Do you test the wall between networks without attacking the devices?" | Nothing connected to a patient |
| Patient portal, apps, APIs | Roles, and the interfaces that share data | "Do you test whether one patient can see another patient's record?" | That check needs authenticated tests with the right roles and records; a generic scanner may miss it |
| Records system | Who hosts it | "If the vendor hosts it, what can you test on our side?" | You need written authorization that covers testing of the vendor's system |
| Cloud | Accounts and storage | "Is cloud setup in or out?" | Backups and storage that hold patient files |
| Outside connections | Billing, labs, imaging, IT firms | "Which connections are tested, and who approves each one?" | Written authorization has to cover each connection you test |
If your records system is hosted by its vendor, start by asking the vendor for its latest test summary: what was tested, which version, and when. Then test what is yours. That usually means your own network, your staff accounts and how you've set the system up.
Not sure which type of test you need? See which penetration testing service fits.
How do you keep testing safe around patients and patient data?
Agree four things in writing before anyone starts: what's off limits, when testing happens, who can stop it, and how patient data is handled. No provider can guarantee zero disruption, so the limits are your protection.
What's off limits. Keep anything connected to a patient out of active scanning and testing. If a device itself needs testing, use a spare unit on a separate network and involve your clinical engineering team and the maker. A general network pentest agreement doesn't automatically cover medical devices. There's more in our guide for hospitals testing devices.
When. Set testing hours that fit care. Name a clinical contact who is reachable during them.
Who can stop it. Name the person, how to reach them, and what happens after a stop.
Patient data. Use test accounts and made-up records wherever you can. A test environment lowers the risk, but write down how it differs from the real one. Ask where the firm stores screenshots and logs, who can see them, and when they're deleted. Require testers to stop and tell you if they come across real patient data.
Does the testing firm need to sign a BAA?
It depends on whether the arrangement makes the testing firm a business associate—for example, because the work involves the use or disclosure of PHI on your behalf. A business associate agreement (BAA) is the written contract or other arrangement that requires a business associate to safeguard that information. HHS describes business associates as those providing services "that involve the use or disclosure of PHI" (HHS guidance, read October 9, 2026). PHI means protected health information.
So the question is what the testers could actually see. Your privacy officer or lawyer makes that call, not the vendor and not us. Ask every firm up front whether it will sign one. A "yes" on a website is useful, but it isn't a signed agreement.
Copy a healthcare brief that makes every quote answer the same question
Send one brief to each firm and their answers line up. Send five different emails and you get five quotes for five different jobs.
Copy this into your own document and fill in the brackets. If you don't know something, write "unknown." That's a useful answer.
Healthcare penetration testing brief
Why and for whom: We need testing because of [customer request / insurer / state rule / our risk analysis]. The report goes to [ ]. They asked for [exact wording, or attach it].
What we are: [practice / hospital / health software / health plan].
Systems in scope: [internet-facing addresses], [internal network and sites], [patient portal or app, with roles], [APIs], [cloud accounts], [wireless]. Mark each one in, out with a reason, or unknown.
Systems we don't own: [hosted records system, billing, imaging]. We will ask those vendors for their own test summaries. Do not test them without written authorization that covers the test.
Clinical safety: No active testing of anything connected to a patient. Clinical network work is limited to [ ]. Testing hours [ ]. Clinical contact [ ]. Person who can stop testing [ ].
Patient data: Use test accounts and made-up records. If you see real patient data, stop and tell us. No patient data in the report or evidence. Tell us where evidence is stored, who can see it, which sub-processors or AI tools touch it, and when it is deleted.
Agreements: Will you sign a business associate agreement if our privacy officer says one is needed? Where are your testers located?
Team and method: Who will test, and how are they independent of our own developers? How much is people and how much is automated? What healthcare work have they done?
Report: Scope and exclusions, dates, methods, findings with evidence, fix guidance, and retest results.
Retest: Which findings qualify, how many rounds, the deadline and what starts the clock, any fee, and when we get the updated report.
Dates: Earliest start, days of testing, report date.
Full cost: Itemize the test, any platform or subscription, travel, and retest. State currency, what is due now, the term and any renewal.
What we already have: [current provider, last report, internal testing]. Tell us what can be reused.
Please send back: scope by system, exclusions, team, a redacted sample report, a dated schedule and an itemized quote.
This brief is for buying. It is not permission to test. Testing needs a separate signed agreement that names the exact targets and activities.
Here is how the made-up telehealth company from earlier would fill in the hard lines. Systems in scope: one patient web app and its API in a test environment, with patient and clinician roles. Systems we don't own: the hospital's records system, out. Patient data: made-up records only. Retest: all fixed findings, requested 60 days after the report. Full cost: one project, no yearly plan.
Want the general version of these questions for any pentest? See a filled-in penetration testing scope.
How long does a healthcare penetration test take?
Count the whole path, not only the testing days: booking, testing, the report, your fixes, the retest and the updated report. A fast start date doesn't tell you when your customer gets what they asked for.
Here's a made-up example using one provider's stated timings. Software Secured states "scheduling within 3-6 weeks," a report "within 48-72 hours of pentest completion," and retests "auto-scheduled within 2 weeks" (read October 9, 2026). Say you allow 2 weeks for testing and 4 weeks for fixes. Those two numbers are ours, for illustration.
6 weeks to start + 2 weeks of testing + 4 weeks of fixes + 2 weeks to schedule the retest = 14 weeks, plus a few days for the first report. That still does not include time to perform the retest or deliver the updated report, so 14 weeks is not the complete time to proof of fixes.
Some steps can overlap, and other firms state different times. Pentest-Tools.com states 3 working days for a test without logins and a report on day 4. A stated time is not a booked slot. Ask each firm: "Can you commit in writing to our report date and our updated-report date for this exact scope?"
How often should a healthcare organization test?
Use the rule you answer to. New York hospitals: at least once a year. Card systems: every 12 months and after big changes. HIPAA today: "periodic," and in response to environmental or operational changes that affect the security of electronic patient data.
When a vendor page says "test annually for HIPAA," that's the vendor's advice. It may be good advice. It isn't what the current rule says. If the proposed update becomes final, yearly would become the federal floor.
A sensible trigger outside any rule: test again after a big change, such as a new portal, a move to a new records system, a merger or a new outside connection.
Can a vulnerability scan or an AI-run test do the job?
A scan can't stand in for a penetration test where a rule names both, and New York's hospital rule does. An AI-run test might be fine for you. Ask whoever needs the report before you buy one.
The practical difference: a scan lists possible weak spots. A penetration test tries to use them. Whether one patient can open another patient's record requires authenticated tests with the right roles and records; a generic scan may miss it.
For more, see penetration testing vs vulnerability scanning.
Do you already have what you need?
Maybe. Check these three before you buy anything.
- Your current IT or security provider. Ask for their last report. Check what it covered, when, and who did the testing. If it matches what you've been asked for, you may be done.
- A qualified internal team. New York's hospital rule and HHS's own guidance both allow internal work. HHS-published industry guidance says penetration tests "can be run internally by qualified individuals, or they can be run by external partners" (HICP Technical Volume 2, read October 9, 2026). A customer contract may still ask for an outside firm.
- A subscription that includes a test. Read what it actually includes: which systems, people or automated, and what report you get.
Put any existing report through the same check as a new one. Does it state the scope and what was left out, the dates, the methods, findings with evidence, and what happened after fixes? If a piece is missing, buy only that piece.
Holding a quote already? Run a Quote Check before you compare on price.
Questions healthcare buyers ask
Is there such a thing as a "HIPAA-certified" penetration testing company?
Not as an HHS-recognized certification. HHS says it "does not endorse or otherwise recognize private organizations' 'certifications' regarding the Security Rule," and that such certifications "do not absolve covered entities of their legal obligations." Treat the phrase as marketing.
Does a clean pentest mean we're HIPAA compliant?
No. A test is evidence for one technical part of the rule. HIPAA also covers policies, training, physical safeguards and more.
Can we test our records vendor's hosted system?
Not without written authorization that covers the test. Ask for their own test summary and test what is yours.
We make a medical device. Is this the right page?
No. Device testing is a different purchase with FDA guidance behind it. Go to medical device penetration testing.
We're outside the United States. Does this apply?
The scope and safety advice still helps. The rules on this page are U.S. rules. We did not review other countries' rules for this page.
How we checked
We compare specific offers against stated buying needs and show our sources. For this page we read the rule texts and each provider's public pages on October 9, 2026, except the PCI DSS row, which relies on our rule tracker checked October 8, 2026. We did not buy a test, talk to these providers or read a delivered report. The telehealth company and the hospital are made up. We don't perform, authorize or certify testing. Read how we check offers and how we make money.
Sources, checked October 9, 2026 unless noted
- 45 CFR 164.308, Cornell LII copy: risk analysis and evaluation text
- HHS fact sheet on the proposed Security Rule update: proposed scan and test intervals; current rule remains in effect
- Federal Register, proposed rule, January 6, 2025: "qualified person(s)" and frequency wording
- Federal regulatory agenda entry, RIN 0945-AA22: stage and projected date
- 10 NYCRR 405.46, Cornell LII copy: hospital testing, scanning and record-keeping text
- HHS FAQ on certification: internal or external evaluation; no endorsed certifications
- HHS business associate guidance: who is a business associate
- HHS Cybersecurity Performance Goals: voluntary goals
- HICP Technical Volume 2: internal or external testers
- The PenTest Index rule tracker: PCI DSS and New York financial regulation rows, checked October 8, 2026
- Astra pricing and rescan rules
- Clearwater technical testing
- Cobalt pricing and retest documentation
- NetSPI network penetration testing
- Pentest-Tools.com managed web app test
- Software Secured pricing and healthcare page