• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

InFront on the Workforce

Long-term and post-acute care publication

Subscribe | Events | Advertise | Contact Us

  • Facebook
  • LinkedIn
  • Twitter

  • HOME
  • ABOUT
    • Who We Are & What We Do
    • The Vision
    • Readership
  • RESOURCES
    • Important Links
  • Retention & Engagement
  • Culture & Leadership
  • Regulatory
  • Technology
  • Industry Trends

HHS Releases Voluntary Cybersecurity Practices for Health Industry

By Joanne Kaldy / January 2, 2019

New guidelines developed by leading experts offer practical ways to cost-effectively reduce cybersecurity risks.

Cybersecurity is on every healthcare organization’s list of top priorities for 2019; and last week, the U.S. Department of Health and Human Services (HHS) released “Health Industry Cybersecurity Practices (HICP): Managing Threats and Protecting Patients.” This four-volume publication provides guidance on voluntary cybersecurity practices for healthcare organizations of all types and sizes, ranging from local clinics to large hospital systems.

The industry-led effort was in response to a mandate set forth by the Cybersecurity Act of 2015 Section 405(d) to develop practical guidelines to cost-effectively reduce cybersecurity risks for the healthcare industry. The publication is the result of a two-year effort that brought together over 150 cybersecurity and healthcare experts from industry and the government under the Healthcare and Public Health (HPH) Sector Critical Infrastructure Security and Resilience Public-Private Partnership.

“Cybersecurity is everyone’s responsibility.  It is the responsibility of every organization working in healthcare and public health.  In all of our efforts, we must recognize and leverage the value of partnerships among government and industry stakeholders to tackle the shared problems collaboratively,” said Janet Vogel, HHS Acting Chief Information Security Officer.

Technology such as Electronic Health Records (EHRs) and computerized physician order entry software are essential to the healthcare industry and help improve patient care and outcomes. Not only are organizations using technology to collect and track data, but it is increasingly necessary to share protected health information (PHI) between settings, practitioners, payors, and others. While the ability to collect and share information is essential to patient care, these same technologies are vulnerable to more and more sophisticated attacks from cybercriminals, hackers, and others. These technologies can be exploited to gain access to personal patient data or render entire health systems inoperable. Recent cyber-attacks against the nation’s healthcare industry continue to highlight the importance of ensuring these technologies are safe and secure.

The HICP publication aims to provide cybersecurity practices for this vast, diverse, and open sector to ultimately improve the security and safety of patients. The main document of the publication explores the five most relevant and current threats to the industry: email phishing attacks, ransomware attacks, loss or theft of equipment or data, insider, accidental, or intentional data loss, and attacks against connected medical devices that may affect patient safety. It also recommends 10 cybersecurity practices to help mitigate these threats, including email and endpoint protection systems, access management, data protection and loss prevention, and incident response. In addition, it presents real-life events and statistics that demonstrate the financial and patient care impacts of cyber incidents. There also are two technical volumes geared for IT and IT security professionals.

Related Posts

  • HSAs and Home Health Care
  • (12/27) Home Health and Hospice Admissions, Utilization Continue To Rise – Home Health Care News
  • (11/26) In Health Insurance Wastelands, Rosier Options Crop Up For 2019 – Kaiser Health News
  • (11/16) Health Organizations Look to Chief Patient Officers for Holistic Approach to Patient Care – Home Health Care News
  • Home Health Workforce: Preparing for the Boom

Categories: Regulatory / Tags: Featured, Latest Articles, More Articles

Primary Sidebar

AROUND THE WEB

Items of interest from across the web.

  • As More States Are Legalizing Marijuana, How Should Employers Respond – HR Executive
  • Giving Thanks for Senior Living Employees, Leaders — McKnights
  • 22 States Petition CMS to End Mandate As 76% of SNF Staff Behind on Vaccines – Skilled Nursing News
  • 6 Ways to Re-energize a Depleted Team – Harvard Business Review
  • 7 Ways to Lift Up the Employees’ Morale Ahead of Holiday Season — Entrepreneur
  • Workforce, Financial Relief Focus in ‘Tumultuous Period’ After Midterms: Argentum – McKnights
  • 6 Steps to Creating More Inclusive Job Descriptions – HR Morning
  • Mental Wellbeing and Resilience: Tech + Culture to the Rescue – HR Daily Advisor
  • Employers Have ‘Flexibility Fatigue.’ But That Could Put Them on the Wrong Side of the ADA. – HR Dive(11/16) Employers Must Push Preventive Care to Inflation-Worried Staff – TLNT

View All

CONTACT INFO

Publisher: CC Andrews
440.638.6990
Editor: Joanne Kaldy

PO Box 360727
Cleveland, OH 44136

CATEGORIES

  • CULTURE & LEADERSHIP
  • RETENTION & ENGAGEMENT
  • REGULATORY
  • TECHNOLOGY
  • TRENDS IN THE INDUSTRY

Copyright © 2025 - InFrontWorkforce.com. All rights reserved.