ARTICLE
23 February 2024

HHS Releases Cybersecurity Performance Goals To Enhance Cybersecurity For Health Care And Public Health Sectors

JD
Jones Day
Contributor
Jones Day is a global law firm with more than 2,500 lawyers across five continents. The Firm is distinguished by a singular tradition of client service; the mutual commitment to, and the seamless collaboration of, a true partnership; formidable legal talent across multiple disciplines and jurisdictions; and shared professional values that focus on client needs.
The Department of Health and Human Services ("HHS") has released voluntary cybersecurity performance goals for the health care and public health sectors...
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

The Department of Health and Human Services ("HHS") has released voluntary cybersecurity performance goals for the health care and public health sectors, which outline an increasingly standardized regulatory approach and preview more intensive future enforcement efforts.

Following the HHS's 2023 concept paper outlining strategies to enhance cybersecurity for the health care and public health sectors, the HHS released its Healthcare and Public Health Sector-Specific Cybersecurity Performance Goals ("CPGs"). These CPGs are categorized into "essential" and "enhanced" goals to address common cyber-related vulnerabilities in the health sector. According to HHS, the CPGs are built from and informed by common industry cybersecurity frameworks, guidelines, and best practices. Although compliance with CPGs is currently voluntary, HHS's concept paper reported its intention to implement enforceable cybersecurity standards informed by CPGs.

Essential CPGs. The "essential" CPGs "outline minimum foundational practices for cybersecurity performance," setting a floor to facilitate better protection against cyberattacks, improve incident responsiveness, and minimize residual risk. The 10 essential CPGs direct health care organizations to:

  • Mitigate known vulnerabilities;
  • Improve email security against common threats (e.g., spoofing, phishing);
  • Implement multifactor authentication;
  • Establish basic cybersecurity training;
  • Use strong encryption in motion;
  • Revoke credentials for departing workforce members;
  • Facilitate cybersecurity incident planning and preparedness;
  • Use unique network credentials;
  • Separate common user and privileged accounts; and
  • Identify and mitigate risks associated with outside vendors.

Enhanced CPGs. The "enhanced" CPGs outline priorities to "mature [] cybersecurity capabilities" and propel organizations to "the next level of defense[.]" The 10 enhanced CPGs focus on:

  • Conducting asset inventories;
  • Processes for third-party vulnerability discovery and response;
  • Processes for third-party incident and breach reporting;
  • Cybersecurity testing;
  • Cybersecurity mitigation of vulnerabilities identified through testing;
  • Detection and response for relevant threats and tactics, techniques, and procedures;
  • Network segmentation to impede lateral movement by threat actors;
  • Centralized log collection to facilitate visibility, cost effectiveness, and efficient response;
  • Centralized cybersecurity incident planning and preparedness; and
  • Consistent baseline configuration management for devices and systems.

The CPGs are consistent with heightened scrutiny on cybersecurity practices in the health sector more generally. Whereas, historically, health data regulations allowed a flexible approach to implementation of cybersecurity practices, the CPGs presage standardized regulatory thresholds. Further, based on HHS's prior concept paper, health care entities may also expect concerted enforcement and steeper costs for noncompliance.

Industry stakeholders should consider:

  • Reviewing their cybersecurity practices relative to essential CPGs;
  • Reviewing enhanced CPGs and investments to implement advanced practices;
  • Reviewing resources across federal departments, including HHS's Cybersecurity Gateway, for additional guidance and updates; and
  • Monitoring for proposed regulations to provide comment and facilitate compliance.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

ARTICLE
23 February 2024

HHS Releases Cybersecurity Performance Goals To Enhance Cybersecurity For Health Care And Public Health Sectors

United States Technology
Contributor
Jones Day is a global law firm with more than 2,500 lawyers across five continents. The Firm is distinguished by a singular tradition of client service; the mutual commitment to, and the seamless collaboration of, a true partnership; formidable legal talent across multiple disciplines and jurisdictions; and shared professional values that focus on client needs.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More