HHS Issues Healthcare Cybersecurity Concept Paper
Earlier this month, the Department of Health and Human Services (HHS) released a concept paper that outlines the Department’s cybersecurity strategy for the healthcare sector. The concept paper builds on the Biden Administration’s National Cybersecurity Strategy, specifically focusing on strengthening resilience for hospitals, patients, and communities threatened by cyber-attacks. The paper arrives at a crucial time for healthcare providers since, according to the HHS Office for Civil Rights (OCR), large breach cyber incidents in the healthcare sector have increased 93% from 2018-2022, with a 278% increase in large breaches involving ransomware.
The HHS healthcare cybersecurity strategy is comprised of four concurrent components, with the overarching goal of strengthening cyber resiliency in the healthcare sector. The four components established by HHS are:
- Establish voluntary cybersecurity performance goals for the healthcare sector;