HHS Task Force Identifies Cybersecurity Threats and Provides Free Resources for Healthcare Sector

Moses Singer Client Alert
Share this page:

On April 17, 2023, the U.S. Department of Health and Human Services’ (HHS) “Cybersecurity Task Force,” led by the HHS 405(d) Program, a collaborative effort between the federal government and industry to align healthcare industry security practices, and the Health Sector Coordinating Council Cybersecurity Working Group, released new resources1 to help address cybersecurity in the Healthcare and Public Health (HPH) sector. The HHS 405(d) Program was started as a congressional mandate under the Cybersecurity Act of 2015, Section 405(d), to strengthen the cybersecurity posture of the HPH sector, with one goal being to develop a set of voluntary, industry-led cybersecurity guidelines, practices and procedures to coalesce health care organizations around a standard industry-wide approach. The Task Force announced three new resources to help address cybersecurity concerns in the HPH Sector: (1) an online educational platform; (2) the 2023 edition of the Health Industry Cybersecurity Practices (HICP), which is aimed at raising cybersecurity awareness, setting standards and providing best practices; and (3) a report on the state of US hospitals’ cybersecurity preparedness. HHS stated in its release that these resources are part of the Biden administration’s broader work to bolster the cybersecurity of all critical infrastructure.

HHS's online educational platform is known as Knowledge on Demand and offers free cybersecurity trainings to the HPH sector workforce, a first for HHS. The platform includes videos and slide decks and covers the five cybersecurity topics that correlate with what HHS considers to be the top five threats facing the HPH sector: social engineering, ransomware, loss or theft of equipment or data, insider accidental or malicious data loss, and attacks against network connected medical devices. The training can be accessed and viewed directly on the HHS 405(d) website.

Furthermore, the HHS 405(d) Program’s updated cornerstone publication, the HICP, is also available on its website. The HICP arose from the Task Force’s initial work and was first published in 2018. Now, HICP 2023 has been updated by over 150 industry and federal government professionals with a focus on keeping patients safe and mitigating current HPH sector cybersecurity threats. In the new edition, there is considerable discussion of the five threats identified above, including identifying social engineering as a current and evolving threat. HICP also explains the vocabulary of cybersecurity “threats” and “vulnerabilities” and analogizes to more familiar real-world threats. For example, in the face of an influenza “threat,” “vulnerabilities” would include a weak immune system, lack of a flu shot and lack of hand washing. Thus, the best practices for reducing those vulnerabilities in the face of an influenza threat include getting a flu shot and regular handwashing.

Finally, the Task Force released a Hospital Cyber Resiliency Initiative Landscape Analysis, which uses HICP 2023 and the National Institute of Standards and Technology (NIST) Cybersecurity Framework as benchmarks to assess how US hospitals are or are not protected from common cybersecurity threats. Data from hundreds of hospitals across type and geography contributed to the report’s identification of best practices and opportunities for improvement. HHS Deputy Secretary Andrea Palm indicated that the report’s function was two-fold. First, it gave HHS insight into current hospital cyber resiliency as measured by available benchmarks. Second, it gave HHS a baseline of data from which it can “begin working through potential policy considerations and minimum standards.” Thus, at the same time that HHS is presenting these free resources as a tool for HPH sector leaders to assess their organizations’ cybersecurity programs, HHS is also using its interdisciplinary, collaborative public-private efforts to find common ground on what might ultimately become regulatory standards for cybersecurity preparedness, cyber resiliency and patient protection and safety. These three resources and others are available at 405d.hhs.gov.

Healthcare companies and not-for-profit organizations should become familiar with these resources and should continuously evaluate their cybersecurity measures as well as cyber threat readiness.