Cybersecurity: What Every NP Must Know Part 5: Pen-Testing

For many Nurse Practitioners, along with other small practice owners,  the phrase “pen-testing”, or penetration testing, sounds intimidating, expensive, and technical.

And that reaction is understandable.

Because the proposed updates to the HIPAA Security Rule and broader healthcare cybersecurity initiatives increasingly point toward annual penetration testing as part of an ongoing cybersecurity program.

Relax…

No law has been passed, and nothing is set in stone… yet.

But regardless, there are a few problems with the proposed rules, a major one being the added expense for small practices.

Because most Nurse Practitioners and other independent practice owners do not have:

  • IT departments
  • Cybersecurity experts on staff
  • Large cybersecurity or compliance budgets
  • Enterprise-level infrastructure in place

But not all is lost…

The good news is that small practices can still implement effective penetration testing and improve cybersecurity without spending enormous amounts of money.

The key is understanding what the government is actually expecting and taking a practical, risk-based approach.

Under the proposed HIPAA Security Rule updates, all healthcare organizations may eventually be required to conduct:

  • vulnerability scanning at least every six months
  • and penetration testing at least once every 12 months

The government also increasingly emphasizes the importance of:

  • ongoing risk management
  • vulnerability identification
  • up-to-date documentation
  • and reasonable security practices

For small practices, this is important because the expectation is not perfection.

The expectation is that small healthcare organizations make a reasonable, ongoing effort to identify and reduce cybersecurity risks.

Penetration testing, often called “pen testing,” is a controlled cybersecurity exercise where authorized professionals attempt to identify weaknesses in systems before criminals do.

A penetration test may evaluate components like:

  • Internet-facing systems
  • Firewall configurations
  • Password security
  • Wi-Fi security
  • Remote access
  • Access to patient information
  • Email vulnerabilities
  • Employee phishing susceptibility
  • Weaknesses inside the office network

Again, the goal is not perfection, but to identify major risks and reduce them before hackers find them first.

Under the proposed HIPAA Security Rule updates, penetration testing would likely be required at least once every 12 months.

While no requirements are in place at this time, it’s important to take steps now to make your office as safe as possible from cyberattacks.

Before investing in penetration testing, practices should first implement the core protections the government is already emphasizing:

These are weaknesses a pen-test will uncover. So, fixing obvious issues will reduce both risk and testing costs.

There’s no need to pay for advanced cybersecurity services before addressing basic security problems.

The proposed rules also emphasize routine vulnerability scanning in addition to penetration testing.

These are two different things.

Pen-Testing involves evaluation by a professional, whereas a vulnerability scan is a piece of software that searches a system for known weaknesses.

There are numerous options on the market; some are standalone software, while others are subscription-based for vulnerability scanning.

When selecting vulnerability scanning software, be sure it is HIPAA-compliant and has a proven track record in healthcare.

With respect to pen-testing, don’t assume you must hire a large cybersecurity company to perform penetration testing for your practice.

A smaller independent practice may be well served by:

  • a qualified cybersecurity freelancer
  • a cybersecurity consultant
  • or a smaller healthcare-focused security company

The key issues are qualifications and documentation.

The proposed HIPAA guidance refers to testing by “qualified persons” with appropriate cybersecurity knowledge and experience.

As always, do your due diligence and ask questions:

  • What healthcare experience do you have?
  • What type of penetration testing do you perform?
  • What systems are included?
  • Will you provide a written remediation report?
  • Do you retest after vulnerabilities are corrected?
  • Can you scale services for small practices?

Avoid vendors that immediately push expensive, long-term contracts before understanding the practice’s actual size and complexity.

At this time, May 2026, no scans or pen testing are mandated.

However, it is recommended that you get a head start on what’s coming down the pike.

Why not start by using the federal government’s resources?

Many practices overlook the fact that the federal government already provides substantial free cybersecurity guidance.

The Cybersecurity and Infrastructure Security Agency (CISA) offers:

  • healthcare cybersecurity guidance
  • ransomware prevention resources
  • vulnerability advisories
  • phishing education
  • incident response materials
  • and security checklists

Similarly, HHS HIPAA Security Rule Guidance provides security guidance specifically for healthcare organizations.

Small practices should not underestimate the value of these free resources.

And finally…

One of the clearest themes emerging is the importance of up-to-date documentation.

Because even basic documentation can demonstrate good-faith compliance efforts.

Increasingly, regulators likely will ask:

  • Did the practice identify risks?
  • Did it conduct testing?
  • Were vulnerabilities addressed?
  • Was corrective action documented?

This means your practice should maintain things like:

  • Penetration test reports
  • Remediation records
  • Vulnerability scan results
  • Software update logs
  • Employee training records
  • Cybersecurity policies

Perhaps the most important takeaway is this…

Cybersecurity is no longer a one-time project.

In the future, all healthcare organizations will be expected to demonstrate continuous security efforts rather than an occasional activity.

But don’t let that intimidate you.

We all need to implement stronger cybersecurity practices at the personal, business, and government levels.

That doesn’t mean your small practice has to turn into a cybersecurity company.

However, it means implementing manageable, yet simple routines, including regular:

  • Testing
  • Software updates
  • Employee training
  • Backups
  • Ongoing documentation

Small, consistent improvements are often far more effective than expensive one-time security projects.

The practice that begins implementing these habits now will likely be in a much stronger position as healthcare cybersecurity requirements continue to evolve.


Join the conversation by leaving a comment or question below.

Let us know if you have any questions or would like more information on specific topics.


By Johanna Hofmann, MBA, MAc., regular contributor to the NPBusiness blog.

Leave a Reply


Your email address will not be published. Required fields are marked

This site uses Akismet to reduce spam. Learn how your comment data is processed.

{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}