The standards that drive it
- Risk analysis — an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of ePHI. This is the standard OCR cites most often in enforcement.
- Risk management — implementing security measures sufficient to reduce those risks to a reasonable and appropriate level, which requires knowing whether your measures work.
- Evaluation — a periodic technical and non-technical evaluation establishing the extent to which your safeguards meet the Security Rule. Technical evaluation is where testing lives.
- Information system activity review and audit controls — testing frequently reveals whether your logging would actually have caught the activity.
The enforcement pattern is consistent
Look at published OCR settlements and the same finding recurs: the risk analysis was incomplete, out of date, or scoped to only part of the environment. Testing that never happened is rarely the headline — the inadequate risk analysis is.
What to scope in a healthcare environment
Scope follows ePHI. Anywhere it is created, received, maintained or transmitted is in scope, and in most healthcare environments that is a wider footprint than people expect.
- The EHR platform and any patient portal, including role-based access controls across clinical roles.
- Integration and interface layers — HL7 and FHIR endpoints, interface engines, and any API exchanging ePHI.
- The internal network, since most healthcare breaches involve lateral movement after an initial foothold rather than a direct external compromise.
- Remote access paths — VPN, virtual desktops, and any vendor or third-party access into clinical systems.
- Medical devices and their network segmentation, which is frequently the weakest boundary in the environment.
- Cloud services and identity providers holding or brokering access to ePHI.
- Email, given how many healthcare incidents begin with a phishing-driven account compromise.
Business associates and vendor testing
Business associates are directly liable under the Security Rule, which means the same risk analysis and evaluation standards apply to them. If you are a business associate, your covered-entity customers will increasingly ask for evidence of testing during due diligence, and a clean summary shortens sales cycles considerably.
If you are a covered entity, your business associate agreements do not transfer risk away from you in practice — a breach at a vendor is still your patients' data and your notification obligation. Asking vendors for testing evidence is reasonable and increasingly standard.
Testing safely in a clinical environment
Healthcare has a constraint most industries do not: systems that must not go down, and devices that can behave unpredictably under active testing. This is a scoping and rules-of-engagement problem, not a reason to avoid testing.
In practice that means agreed testing windows outside clinical peaks, explicit exclusion of life-critical devices from active exploitation, a named clinical contact who can halt testing instantly, and — where an environment is genuinely too fragile to touch — testing a replica instead. A signed rules-of-engagement document should record all of it before anything runs.
Want a number before you talk to anyone?
Our instant estimator prices your actual environment using the same model our quoting process uses. No email required to see the figure.