Is pentesting required for HIPAA compliance?
Pentesting, or penetration testing, is not specifically required for HIPAA compliance. However, that does not mean healthcare organizations should...
1 min read
Rick Kuwahara January 10, 2020
Penetration testing (pen testing) is designed to simulate a cyber attack to determine the effectiveness of an organization’s cybersecurity. Cybersecurity professionals hack into an organization’s computer system to pinpoint vulnerabilities that attackers could infiltrate. Pen testing is an essential part of the constant vigilance that’s needed to keep private data protected. It helps organizations identify higher- and lower-risk vulnerabilities, assess operational impacts of successful attacks, measure a network’s defense abilities, meet compliance requirements, and implement and validate new security controls.
Information gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting are the main steps involved in pen testing. Automated scans can help identify some security issues but truly effective pen testing takes into account manual attacks too.
Cybersecurity is a rapidly evolving landscape with complex policies and architectures. Pen testing analyzes the ongoing ability of an organization’s existing security tools and configurations to defend against attackers gaining access to information, installing malware, hacking networks, and disrupting services. Highly trained cybersecurity professionals are able to detect dangers an organization may not be aware of yet. These professionals are so skilled at using tactics that resemble cybercriminals that sometimes they are misconceived as attackers themselves. That’s why it’s important that all parties involved in pen testing understand the parameters of the test.
While many organizations perform automated scans of their networks, most don’t have the specialized expertise to comprehensively penetration test without potentially impacting business operations. A cybersecurity professional can efficiently determine if a potential weakness is actually exploitable and could lead to the compromise of data. When it comes to avoiding cyber attacks it’s crucial to be proactive, especially for organizations that directly manage sensitive personal information. Additional Reading: HIPAA Compliant Email: The Definitive Guide
Pentesting, or penetration testing, is not specifically required for HIPAA compliance. However, that does not mean healthcare organizations should...
The Office for Civil Rights (OCR) of the U.S. Department of Health and Human Services (HHS) announced April 9 amendments regarding HIPAA and the...
According to Healthcare Data Breaches: Insights and Implications, “E-health data is highly susceptible, as it is targeted most frequently by...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.