HHS and Industry Release Voluntary Cybersecurity Practices for the Health Industry


HHS, in partnership with industry, is pleased to announce the release of the “Health Industry Cybersecurity Practices (HICP): Managing Threats and Protecting Patients” publication. The four-volume publication seeks to raise awareness for executives, health care practitioners, providers, and health delivery organizations, such as hospitals. It is applicable to health organizations of all types and sizes across the industry.

This industry-led effort was in response to a mandate set forth by the Cybersecurity Act of 2015 Section 405(d), to develop practical cybersecurity guidelines to cost-effectively reduce cybersecurity risks for the healthcare industry. The publication marks the culmination of a two-year effort that brought together over 150 cybersecurity and healthcare experts from industry and the government under the Healthcare and Public Health (HPH) Sector Critical Infrastructure Security and Resilience Public-Private Partnership.

405(d) Cybersecurity Best Practices

Healthcare Industry Cybersecurity Practices (HICP
Cybersecurity Practices for Small Health Care Organizations
Cybersecurity Practices for Medium and Large Health Care Organizations
Resources & Templates

Articles by Cyber Tygr

The Danger of Being Connected: Medical Device Cybersecurity
A Wicked Problem: Medical Devices
NIST Privacy Framework: An Enterprise Risk Management Tool
The NIST Privacy Framework: 405(d) Spotlight
Aligning Governance, Risk and Compliance

Other Important Documents


Medical Device and Health IT Joint Security Plan
Health Industry Cybersecurity Supply Chain Risk Management Guide
NIST Privacy Framework 1.0
NEW LAW: Recognition of Security Practices

Resources


Resource Documents

Resources


Resource Documents