Skip to content
Now accepting new projects — limited slots available. Get started →

Your Patient Portal Just Failed Its Security Rule Audit

If you're a healthcare CTO holding a 60-day remediation notice, you need penetration testing that maps to 45 CFR § 164.312 controls -- not generic security theater.

We test your healthcare applications against every technical safeguard in the HIPAA Security Rule -- then fix what we find.

HIPAA Penetration Testing

HIPAA penetration testing is a structured adversarial assessment of your healthcare systems -- patient portals, EHR integrations, API endpoints, and internal networks -- evaluated against the technical safeguards enumerated in the HIPAA Security Rule at 45 CFR § 164.312. Unlike generic vulnerability scanning, every finding is mapped to a specific regulatory control and rated by its potential to expose, alter, or destroy ePHI. The deliverable is a remediation-ready report your security officer, legal counsel, and OCR reviewer can all use.

What is holding your current website back?

Common gaps we find in nearly every audit.

Your remediation notice cites specific § 164.312 controls but your last pen test report uses CVSS scores and OWASP categories with no regulatory mapping.
Risk: Auditors reviewing your corrective action plan will see a gap between the finding and the fix, which extends your remediation window and increases the likelihood of a second review.
Your patient portal authenticates through a third-party IdP, but no one has tested whether session tokens, audit logs, and access control configurations on that integration actually satisfy the addressable implementation specifications.
Risk: A misconfigured federation point is one of the most common vectors for unauthorized ePHI access, and it almost never shows up in a standard web application scan.
Your internal team patched the critical findings from last year's scan, but has no evidence that the patches held or that new attack paths introduced by the EHR upgrade cycle were evaluated.
Risk: OCR expects covered entities to conduct periodic technical and nontechnical evaluations after environmental changes -- a gap here is a documented § 164.308(a)(8) violation waiting to be cited.

How We Build This Right

Every safeguard, built in from Day 1.

45 CFR § 164.312 Control Mapping

Every finding in our report is tagged to the specific technical safeguard subpart it violates -- access control, audit control, integrity, person or entity authentication, or transmission security -- so your corrective action plan addresses the regulation directly, not just the symptom.

OCR-Defensible Evidence Package

We produce signed test methodology documentation, scoped asset inventories, and timestamped evidence artifacts that demonstrate due diligence under the Security Rule's evaluation standard at § 164.308(a)(8), usable in a corrective action plan or breach investigation.

ePHI Data Flow Verification

Before testing begins we map every path where ePHI is transmitted, stored, or processed -- including third-party integrations and API connections -- so the assessment scope matches what OCR would consider in scope, not just what your network diagram shows.

What We Build

Purpose-built features for your industry.

Patient Portal and EHR Interface Testing

We test authentication flows, session management, role-based access controls, and audit logging behavior on the interfaces your clinicians and patients actually use -- including federated identity configurations and single sign-on integrations with your EHR vendor.

Transmission Security Assessment

We evaluate TLS configurations, certificate management, API transport encryption, and any legacy protocols still active on your network against the transmission security requirements at § 164.312(e)(1), including testing for downgrade attacks and improper cipher suites.

Internal Network Segmentation Review

We test whether systems that store or process ePHI are properly isolated from general corporate infrastructure, verify that audit log pipelines cannot be tampered with by a compromised workstation, and check whether a lateral movement path from the staff network reaches clinical systems.

Findings Remediation and Retest

Once your team closes findings, we retest each affected control and issue a remediation attestation letter confirming the vulnerability is resolved. That letter is what your compliance officer presents as evidence of corrective action during a follow-up OCR inquiry.

Built on a Modern, Secure Stack

Burp Suite ProOWASP ZAPNessusMetasploitNext.jsSupabaseVercel

Our Development Process

From discovery to launch. Quality at every step.

01

Scope Definition and ePHI Asset Mapping

1 week

We work with your CISO or compliance officer to document every system in scope -- patient portals, APIs, EHR integrations, internal clinical networks -- and confirm which assets store, transmit, or process ePHI. This becomes the authoritative scope document attached to your final report.

02

Technical Safeguard Testing

1-2 weeks

Our testers execute a structured assessment across the five control categories in § 164.312: access controls, audit controls, integrity controls, person or entity authentication, and transmission security. Testing is conducted in a defined window agreed with your operations team to avoid disrupting clinical workflows.

03

Findings Report and Regulatory Mapping

1 week

We deliver a written report with every finding mapped to its corresponding § 164.312 citation, a plain-language description of the attack path, a severity rating calibrated to ePHI exposure risk, and a prioritized remediation recommendation your engineering team can act on immediately.

04

Remediation Retest and Attestation

1 week

After your team implements fixes, we retest each finding against its original exploit path and issue a signed remediation attestation letter. The letter documents test date, tester credentials, and confirmed resolution status -- structured for inclusion in your OCR corrective action plan.

Social Animal

Ready to discuss your your patient portal just failed its security rule audit project?

Get a free quote
Related Resources

Frequently Asked Questions

The Security Rule requires a risk analysis under §164.308(a)(1) and a technical evaluation under §164.308(a)(8). The phrase "penetration test" never appears in the regulation, but OCR guidance and NIST SP 800-66 make clear that simulated attacks against technical safeguards are the expected way to demonstrate compliance. Most auditors expect it, and the ones who don't will still want proof you've done something equivalent.
Yes -- any engagement where we might encounter ePHI requires a BAA, and we execute one before testing begins. Our methodology is designed to minimize ePHI exposure. Wherever feasible, we validate that access is possible without actually exfiltrating real patient data.
A vulnerability scan runs automated tools to find known weaknesses. A penetration test goes further. We manually exploit vulnerabilities, chain them together, and show you real-world impact. Scanners miss logic flaws, broken access controls, and authentication bypasses -- which happen to be exactly the issues that matter most for ePHI protection under §164.312.
At minimum, test annually and after any significant change to your ePHI environment -- a new patient portal, cloud migration, major code release, or infrastructure overhaul. Had a breach or a close call? Test immediately. OCR expects your risk analysis to be ongoing, not something you did once in 2019.
We design rules of engagement specifically to prevent disruption. Denial-of-service testing stays out of scope unless you explicitly request it against a staging environment. High-risk tests get scheduled during maintenance windows, and we stay in constant contact with your team throughout. In 12+ years, we've never caused unplanned downtime.
You get an executive summary, a full technical report with every finding mapped to §164.312 provisions, CVSS scores, proof-of-concept screenshots, step-by-step reproduction instructions, and prioritized remediation guidance. Once you've remediated, we retest and issue an updated attestation letter you can actually hand to an OCR investigator.
More solutions

Explore related industries

Need enterprise scale?

200+ employee company? Complex multi-tenant, auction, or multi-location requirement? We have a dedicated enterprise capability track.

View Enterprise Hub

Get Your Quote

Most quotes delivered within 24 hours.

Or book a 30-minute call
Get in touch

Let's build
something together.

Whether it's a migration, a new build, or an SEO challenge — the Social Animal team would love to hear from you.

Get in touch →