Healthcare reform, Home Health, Hospice, News, Regulations, Skilled Nursing Facility

HHS, in partnership with industry, releases voluntary cybersecurity practices for the health industry

On Friday, December 28, the Department of Health and Human Services (HHS) released the “Health Industry Cybersecurity Practices (HICP): Managing Threats and Protecting Patients” publication. The four-volume publication aims to provide voluntary cybersecurity practices to healthcare organizations of all types and sizes, ranging from local clinics to large hospital systems.

The industry-led effort was in response to a mandate set forth by the Cybersecurity Act of 2015 Section 405(d), to develop practical cybersecurity guidelines to cost-effectively reduce cybersecurity risks for the healthcare industry.

The HICP publication aims to provide cybersecurity practices for this vast, diverse, and open sector to ultimately improve the security and safety of patients. The publication:

  • Explores the five most relevant and current threats to the industry
  • Recommends ten Cybersecurity Practices to help mitigate these threats.
  • Presents real-life events and statistics that demonstrate the financial and patient care impacts of cyber incidents
  • Lays out a call to action for all industry stakeholders, from C-suite executives and healthcare practitioners to IT security professionals, that protective and preventive measures must be taken now.
  • Includes two technical volumes geared for IT and IT security professionals. Technical Volume 1 focuses on cybersecurity practices for small healthcare organizations, while Technical Volume 2 focuses on practices for medium and large healthcare organizations.
  • Provides resources and templates that organizations can leverage to assess their own cybersecurity posture as well develop policies and procedures.

“Cybersecurity is everyone’s responsibility. It is the responsibility of every organization working in healthcare and public health. In all of our efforts, we must recognize and leverage the value of partnerships among government and industry stakeholders to tackle the shared problems collaboratively,” said Janet Vogel, HHS Acting Chief Information Security Officer in an HHS press release.

Source: HHS