HHS Information Security Program Rated ‘Not Effective’ for FY 2024

The Department of Health and Human Services’ (HHS) information security program failed to meet federal effectiveness standards according to a November 14, 2024, audit report, signaling important cybersecurity lessons for healthcare entities and digital health companies. 

Specifically, the report stated that “Overall, through the evaluation of FISMA metrics, it was determined that HHS’s information security program rated ‘Not Effective’ for FY 2024, which is the same as the ‘Not Effective’ program rating from FY 2023.” 

The audit, conducted by Ernst & Young LLP and commissioned by the HHS Office of Inspector General (OIG), evaluated HHS’s compliance with the Federal Information Security Modernization Act of 2014 (FISMA). 

The assessment measured effectiveness across five key cybersecurity functions: Identify, Protect, Detect, Respond, and Recover. To achieve an “effective” rating, organizations must reach a “Managed and Measurable” maturity level, which HHS failed to achieve in any of these functions. 

The report made the following six recommendations to strengthen HHS’s information security program: 

  • Update its enterprise architecture system inventory and software/hardware asset inventories to include the information systems and components that are active on the HHS network. HHS should utilize the inventories to continuously monitor assets and identify and remediate vulnerabilities timely to better manage the risks to these assets. 
  • Complete implementation of a cybersecurity risk management strategy to assess and respond to identified risks within the agency and identified across operating divisions (OpDivs), watch for new risks, and monitor risks and confirm implementation. The strategy should define a standardized process to accept and monitor risks that cannot be adequately mitigated.  
  • Require OpDivs to incorporate analyses of security impacts of significant changes prior to implementation to measure its impacts to the organizations’ security and enterprise architecture and confirm implementation.  
  • Require OpDivs to implement an effective SCRM program that meets the defined standards across HHS and confirm implementation is consistent with established standards. This should include requiring OpDivs to assess vendors and submit said monitoring results to HHS to assist with tracking and monitoring components on the network.  
  • Require OpDivs to establish oversight of background investigations performed for employees and contractors with logical access across the agency and perform continuous monitoring for new and existing users to ensure OpDivs are aware of the investigation status of their users.  
  • Confirm that OpDivs’ policies require monitoring of privileged user accounts for both logging and activity reviews, in an automated manner. 

With the exception of the second recommendation, the report says that HHS concurred with the remaining five. 



Categories: Cybersecurity, DATA PROTECTION & PRIVACY

Tags: , ,

Leave a Reply

Discover more from Digital Healthcare Law

Subscribe now to keep reading and get access to the full archive.

Continue reading