The U.S. Department of Health and Human Services (HHS) recently published Healthcare and Public Health Sector (HPH) Cybersecurity Performance Goals (CPGs) in a document entitled, “Strengthening the Cybersecurity of the Healthcare Sector and Keeping Patients Safe and Secure.”
These voluntary CPGs are a follow up to a Concept Paper released by HHS on December 6, 2023, and are part of the agency’s efforts to help healthcare entities “prepare for and respond to cyber threats, adapt to the evolving threat landscape, and build a more resilient sector.”
The CPGs were developed in coordination with the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) and adapted from CISA’s Cross-Sector CPGs.
PURPOSE OF CPGs
As the Concept Paper previously noted, the healthcare sector is “particularly vulnerable to cybersecurity risks and the stakes for patient care and safety are particularly high,” and according to HHS, the CPGs were published to “help healthcare organizations prioritize implementation of high-impact cybersecurity practices.” They are said to be designed to improve responses when events occur and minimize residual risk.
DEVELOPMENT OF CPGs
In addition to being built on the “Chassis” of CISA’s CPGs, the HPH CPGs were ‘informed’ by the following common industry cybersecurity frameworks, guidelines, best practices, and strategies:
- The Health Industry Cybersecurity Practices developed by the Healthcare & Public Health Sector Coordinating Council;
- The National Institute of Standards and Technology (NIST) Cybersecurity; Framework;
- The National Cybersecurity Strategy; and,
- The Hospital Cyber Resiliency Initiative Landscape Analysis
THE INTENDED EFFECT OF THE GOALS
The CPGs are said to be designed to allow for “layered protection at different stages of the attack chain,” or “points in the digital systems that can be exploited.” They also provide two sets of goals – essential and enhanced.
Essential goals set a ‘floor’ of safeguards and address common vulnerabilities. Specific items here include email security and multifactor authentication. The enhanced goals are said to provide “next level defense” against “additional attack vectors,” and include such things as third-party incident reporting and network segmentation.
In addition to the CPGs, HHS stated in the Concept Paper that it would be working on providing resources to incentivize and implement cybersecurity practices; implementing an HHS-wide strategy to support greater enforcement and accountability; and expanding and maturing the one-stop shop within HHS for healthcare sector cybersecurity.
Categories: Cybersecurity, DATA PROTECTION & PRIVACY, Uncategorized
Leave a Reply