
Healthcare cyberattacks continue to evolve, and federal regulators are responding with stronger proposed cybersecurity expectations.
The U.S. Department of Health and Human Services (HHS) has proposed major updates to the HIPAA Security Rule, with July 2027 currently listed as an estimated final-action date on the federal regulatory agenda. That date is not guaranteed and may change, but the proposal gives healthcare organizations a clear signal about where cybersecurity expectations are heading.
One area receiving greater attention is vulnerability management, including both automated vulnerability scanning and penetration testing.
Vulnerability Scans vs. Penetration Tests
While the two are related, they serve different purposes.
Vulnerability scans use automated tools to identify known technical weaknesses, outdated software, missing patches, and configuration issues across systems and devices.
Penetration tests go a step further. Qualified security professionals simulate real-world attacks to determine whether identified weaknesses can actually be exploited and how far an attacker could potentially move through the environment.
Think of a vulnerability scan as finding unlocked doors. A penetration test evaluates what could happen if someone actually tried to walk through them.
What Could Change Under the Proposed Rule?
The current HIPAA Security Rule requires organizations to identify risks to electronic protected health information (ePHI) and implement reasonable safeguards, but it does not prescribe a specific vulnerability-scanning or penetration-testing schedule.
If finalized as proposed, that would change.
Covered entities and business associates could be required to:
- Conduct automated vulnerability scans at least once every six months, or more frequently based on their risk analysis
- Perform penetration testing on relevant electronic information systems at least once every 12 months, or more frequently when warranted
- Use qualified individuals to perform penetration testing
- Continuously monitor authoritative sources for newly identified vulnerabilities
- Address identified vulnerabilities through established patch-management and risk-management processes
How Healthcare Organizations Can Prepare Now
Organizations do not need to wait for a final rule to strengthen these practices.
Start by reviewing which systems contain or interact with ePHI and determining whether they are currently included in regular vulnerability scanning. From there, work with your internal IT team or managed service provider (MSP) to establish testing schedules, assign responsibility for remediation, document findings, and verify that identified weaknesses are actually corrected.
Penetration testing may also require outside expertise, particularly for smaller organizations without dedicated security personnel.
The goal is not simply to complete another compliance task. These activities help healthcare organizations understand where weaknesses exist before an attacker finds them.
Building these processes now can strengthen patient data protection today while making future compliance requirements easier to manage if the proposed rule is finalized.

Leave a Reply