Penetration Testing for Home Health Agencies: What It Is, What It Costs, and What to Expect
Technical Guide

Penetration Testing for Home Health Agencies: What It Is, What It Costs, and What to Expect

Annual penetration testing became a mandatory HIPAA Security Rule requirement in 2026, and many home health administrators are encountering the requirement for the first time during their current compliance review…

Annual penetration testing became a mandatory HIPAA Security Rule requirement in 2026, and many home health administrators are encountering the requirement for the first time during their current compliance review cycle. The most common questions I receive: What exactly is a penetration test? Is it the same as a vulnerability scan? How disruptive is it to clinical operations? What do I get in the report, and what am I supposed to do with it? How do I know if the firm I am considering is actually qualified? And what does the pen test result do for my cyber insurance situation?

This article provides direct, operational answers to every one of those questions — so that home health administrators can meet the requirement correctly, select the right firm, and extract maximum value from the exercise.

Penetration Testing vs. Vulnerability Scanning: The Critical Distinction

The 2026 HIPAA update requires both biannual vulnerability scanning and annual penetration testing — these are distinct requirements for distinct activities that produce different information and serve different compliance purposes. Confusing them — or substituting one for the other — creates a documented HIPAA compliance gap.

Vulnerability scanning is an automated process that identifies known software weaknesses — unpatched operating systems, misconfigured services, outdated application versions — by comparing your systems against a database of known vulnerabilities. It is comprehensive, relatively fast, and produces a list of technical weaknesses for remediation. A vulnerability scan tells you what weaknesses exist.

Penetration testing is a simulated attack conducted by a qualified security professional who actively attempts to exploit those weaknesses — and others that automated scanning may not detect — to gain unauthorised access to your systems and data. A penetration test tells you what an attacker could actually accomplish with your weaknesses. The distinction matters because some vulnerabilities that appear severe on a scan report are not exploitable in practice given your specific configuration, while some vulnerabilities that score as low-severity on a scan are easily chained together to achieve significant access. Only a penetration test reveals the real exploitability of your environment.

One substitution that is specifically not acceptable under the 2026 HIPAA mandatory standard: an internal IT staff member running an automated vulnerability scanning tool and presenting the results as a penetration test. The regulation specifies testing by a "qualified party" — which OCR guidance interprets to mean an individual or firm with verifiable penetration testing credentials and demonstrated methodology, not an internal staff member using commercial scanning software.

What a Penetration Test for a Home Health Agency Covers

External Penetration Testing

External penetration testing examines your organisation's external attack surface — the systems, services, and interfaces that are accessible from the public internet. For a home health agency, this includes: the public-facing website and any web applications; email servers and the email domain configuration (DMARC, DKIM, SPF and whether they are exploitable); remote access services (VPN endpoints, RDP services, any systems accessible from outside the agency's network); and cloud services that are accessible from the internet with the credentials of agency staff.

The external test simulates an attacker who has no inside knowledge of the agency's environment and is attempting to gain initial access from the internet. The tester uses the same publicly available information sources that a real attacker would use — the agency website, LinkedIn, job postings, the HHS breach portal, DNS records — to build a reconnaissance profile before attempting exploitation. The findings from the external test directly address the OSINT attack surface discussed in our reconnaissance article: a competent external pen test will identify the same information gaps and exploitable configurations that a criminal attacker would target.

Internal Penetration Testing

Internal penetration testing simulates an attacker who has already gained access to the agency's internal network — through a phishing credential theft, a compromised employee device, or a rogue insider. The internal test examines how far an attacker with initial access could move through the environment, what systems they could reach, and what data they could access or exfiltrate.

For home health agencies, the internal test typically focuses on: the clinical network (EHR access, patient data systems, scheduling platforms); the administrative network (billing and financial systems, Microsoft 365 or Google Workspace); and the path between them — because segregating these networks is a critical control that is frequently absent. An internal test that finds the tester can move from a compromised field nurse device credential to billing system administrator access has identified a lateral movement pathway that real ransomware groups exploit.

Social Engineering Component

Many penetration testing engagements for healthcare organisations include a social engineering component — simulated phishing campaigns and phone-based pretexting that test whether staff can be manipulated into revealing credentials or granting access. For home health agencies where phishing is the primary initial access vector, the social engineering component of a pen test provides the most operationally relevant finding: exactly how susceptible are your specific staff members to the specific phishing techniques being used against home health agencies in 2026. This component is typically optional and adds cost, but for agencies that want to know their real human vulnerability rather than just their technical vulnerability, it is worth including.

What a Penetration Test Costs — and What Drives the Price

For a home health agency in the 50–200 employee size range, a combined external and internal penetration test from a qualified firm typically costs between $8,000 and $18,000. The range reflects four factors that drive price variation:

       Scope: the number of IP addresses, systems, and applications included in the external test; the number of internal network segments and systems included in the internal test. A larger scope means more tester time and higher cost.

       Methodology depth: a box-check compliance pen test that runs automated tools and documents findings is at the low end of the price range. A manual penetration test that uses custom exploitation techniques, chains vulnerabilities together to demonstrate realistic attack paths, and provides detailed remediation guidance is at the high end.

       Firm reputation and credentials: established penetration testing firms with documented healthcare sector experience, OSCP-certified testers, and published methodology documentation command higher rates than generalist IT vendors who offer pen testing as one of many services.

       Report quality: the value of a penetration test is in the report — the documentation of findings, their exploitability, their business risk context, and the remediation guidance. Reports that provide actionable guidance specific to your environment are more expensive to produce than template reports with generic recommendations.

One important note on budget: the $8,000–$18,000 cost is a one-time annual expenditure that satisfies a mandatory HIPAA requirement, supports cyber insurance underwriting, and is an allowable cost under Medicare cost reporting. It is not a discretionary security enhancement — it is a compliance obligation with a defined and manageable cost.

How to Select a Qualified Penetration Testing Firm

The 2026 HIPAA mandatory standard specifies that penetration testing must be conducted by a "qualified party" — and this is the area where home health agencies most consistently make errors that undermine the compliance value of the exercise. A vendor who calls their service "penetration testing" is not necessarily providing what the HIPAA standard requires. Here is how to distinguish qualified firms from inadequate ones.

The Credentials That Matter

The penetration testing credentials that are most broadly recognised and most directly relevant to the HIPAA qualified party standard:

       OSCP (Offensive Security Certified Professional): the gold standard for hands-on penetration testing certification. OSCP holders have demonstrated the ability to compromise systems through manual exploitation techniques under time pressure — not just to run automated tools. This is the credential that most directly demonstrates the capability that "penetration testing" is supposed to assess.

       GPEN (GIAC Penetration Tester): a well-regarded certification from the GIAC family that demonstrates penetration testing methodology and technical capability.

       CEH (Certified Ethical Hacker): a widely recognised certification that demonstrates security knowledge relevant to penetration testing, though it is more knowledge-based than the OSCP's hands-on requirement.

When evaluating a penetration testing firm, ask specifically: "Which credentials does the tester who will conduct our engagement hold?" A firm whose testers hold OSCP or GPEN certifications is demonstrating a genuine commitment to technical capability. A firm that cannot identify the credentials of the specific tester assigned to your engagement — as opposed to general firm certifications — warrants additional scrutiny.

The Questions That Reveal Firm Quality

Before engaging a penetration testing firm, ask these specific questions in the scoping conversation:

       "Can you describe your penetration testing methodology?" — A qualified firm will describe a structured approach: reconnaissance, scanning, exploitation, post-exploitation, reporting. A firm that describes "running our security assessment tools against your network" is describing vulnerability scanning, not penetration testing.

       "Will the test include manual exploitation or only automated scanning?" — The correct answer for a genuine penetration test is that manual exploitation is the core of the engagement, with automated scanning as a preliminary information-gathering step. An engagement that is primarily automated scanning with a penetration testing label does not satisfy the HIPAA qualified party standard.

       "Can you provide a sample report from a comparable healthcare engagement?" — A qualified firm can provide a sanitised sample report. The report quality reveals the depth of analysis and the actionability of the guidance. A one-page summary with generic recommendations is not a penetration test report.

       "What is your healthcare sector experience and how does it inform your test scope?" — A firm with healthcare sector experience understands that EHR systems, billing platforms, and clinical devices require specific testing approaches. Generic IT penetration testing methodology applied to a healthcare environment misses the healthcare-specific attack vectors that matter most.

Red Flags That Indicate an Inadequate Provider

       The firm cannot identify the credentials of the specific tester assigned to your engagement

       The proposal describes only automated scanning tools with no mention of manual exploitation techniques

       The price is significantly below the $8,000 minimum — $2,000–$4,000 "penetration tests" are almost always automated vulnerability scans with a different label

       The firm offers to complete the engagement remotely in one day — a genuine penetration test of a home health agency environment requires multiple days of work

       The sample report contains only a list of CVE numbers from automated scanning without contextual analysis of exploitability or business impact

Acting on the Penetration Test Report

The penetration test report will contain findings ranked by severity (Critical, High, Medium, Low) with descriptions of how each vulnerability was exploited and recommendations for remediation. The compliance obligation is to document the findings and remediate them — not just to file the report. Create a remediation tracking document that lists each finding, the responsible party, the target remediation date, and the confirmation date when remediation is verified complete. This document, alongside the original pen test report, is the HIPAA compliance evidence that demonstrates the mandatory annual testing requirement was met and acted upon.

Remediation priority should follow severity: Critical findings require immediate action — within 15 days; High severity within 30 days; Medium within 60 days; Low within 90 days. These timelines are not OCR regulations — they are the standards that reflect responsible risk management and that OCR guidance has referenced as reasonable. Document deviations from these timelines with explanations and compensating controls when operational constraints require a longer remediation window.

Penetration Testing and Cyber Insurance: The Connection Administrators Miss

The penetration test result has direct implications for cyber insurance coverage that most home health administrators have not connected. Insurance underwriting questionnaires for healthcare organisations increasingly ask two specific questions related to penetration testing: whether the organisation conducts annual penetration testing, and whether identified vulnerabilities are remediated within defined timeframes. Both questions appear in the questionnaires of major cyber insurance carriers serving healthcare, and both affect premium calculation and ransomware sublimit determination.

An organisation that answers "yes" to annual penetration testing — and can provide the most recent test report as evidence if the insurer requests documentation — is demonstrating a proactive security investment that actuarial models associate with lower breach probability. The premium benefit from this demonstration varies by carrier but is consistently positive. More importantly, a claim denial scenario that would not arise: an insurer who sees that a critical vulnerability identified in the penetration test was not remediated within a reasonable timeframe before a breach that exploited that vulnerability has grounds to argue the organisation failed to maintain the security programme it represented in the application.

The remediation tracking document — the record that each finding was addressed within defined timelines — is therefore not just a HIPAA compliance document. It is the insurance claim protection document that demonstrates the organisation acted on the test results, fulfilling the obligation that the "yes" answer to the underwriting questionnaire implied.

 

ShieldForce coordinates annual penetration testing for every home health managed service client as a standard component of the engagement — sourcing qualified testing firms, supporting scope definition, managing the remediation tracking process, and producing the compliance evidence documentation that HIPAA and cyber insurance both require. The penetration test is scheduled, executed, documented, and remediated within the compliance calendar without requiring the agency to manage any part of the process independently. Start with a free assessment.

 

Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment

Explore Home Healthcare Cybersecurity — shieldforce.io/home-healthcare

View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

Share this post

Topics

#Technical Guide
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours — 24/7.