HHS Releases ‘Essential’ And ‘Enhanced’ Cybersecurity Performance Goals

HHS publishes a new website and releases its essential and enhanced voluntary cybersecurity performance goals.

• Source: Shutterstock

As promised, the Department of Health and Human Services has released its voluntary cybersecurity performance goals (CPGs), split into “essential” and “enhanced” goals. A related website from HHS.gov, posted 24 January, offers resources intended to connect the healthcare and public health (HPH) sector with the department.

While the CPGs are currently voluntary, the HHS is working to establish enforcement informed by the goals around cybersecurity standards for healthcare delivery organizations (HDOs), HHS Deputy Secretary Andrea Palm said in a release.

The CPGs were created to “directly address common attack vectors against U.S. domestic hospitals as identified in the 2023 Hospital Cyber Resiliency Landscape Analysis,” the release reads.

Essential goals are the bare minimum for healthcare cybersecurity and set a “floor of safeguards” to protect HDOs from cybersecurity attacks.

The essential goals are:

  • Mitigating known vulnerabilities;
  • Reducing risk from email threats;
  • Introducing multifactor authentication;
  • Conducting basic cybersecurity trainings;
  • Encrypting sensitive data;
  • Revoking credentials of departing employees in a timely manner;
  • Creating unique credentials to detect anomalous activity within systems;
  • Separating accounts based on security levels; and
  • Extending cybersecurity requirements to third-party partners.

These are considered basic, good cybersecurity practices across industries. (Also see "FDA And CISA Device Cybersecurity Agreement Needs To Be Updated, GAO Says" - Medtech Insight, 4 January, 2024.)

The HHS’s enhanced set of goals is resource-dependent and intended to help organizations “mature” their cybersecurity and reach the “next level of defense” against threats.

What is penetration testing?

“Penetration testing often includes hiring a third party to test a system’s vulnerabilities by trying to exploit the system as much as possible. After the tests are finished, the vulnerabilities are reported back to the organization for fixing.” (Also see "Vulnerabilities Up 59%: The State Of Healthcare Cybersecurity In 2023" - Medtech Insight, 10 August, 2023.)

These include:

  • Inventorying assets to identify known and unknown assets and detect vulnerabilities more quickly;
  • Establishing processes for identifying, detecting and reporting vulnerabilities in third-party partnerships;
  • Cybersecurity testing, such as penetration testing;
  • Detecting and responding to threats and common techniques used by threat actors;
  • Segmenting networks to prevent threat actors from accessing multiple assets;
  • Creating centralized log collection and incident planning and responses; and
  • Defining a baseline of secure device and system settings.

 The report’s appendices outline these goals in greater detail, including desired outcomes and implementation resources.

The HHS’s CPG website also has a comprehensive, guided tour of its CPGs in a different format that acts as a checklist for organizations.

More from Cybersecurity

Congress, Researchers Highlight Security Risks At DNA Testing Services

 
• By 

Congress has launched an inquiry into 23andMe amid privacy concerns following its bankruptcy, particularly regarding the potential sale of sensitive user data. Additionally, a Cybernews report gave 40 DNA testing firms an average cybersecurity grade of D, citing widespread vulnerabilities and data breaches, along with inadequate public information about their security practices.

Birmingham City University Develops New Defense Mechanism Against Cyberattacks On AI Systems

 

AI systems used in healthcare are vulnerable to adversarial cyberattacks, which are a growing concern, said Atif Azad, a professor of AI at Birmingham City University. Azad’s research group has developed a method that trains AI to become more resilient to cyber threats through the use of random image adjustments.

Enovis Appoints Damien McDonald CEO, Reaffirms Q1 Guidance Amid Strategic Growth Push

 
• By 

Enovis has named veteran medtech leader Damien McDonald as its new CEO effective 12 May as the orthopedic company reaffirms first-quarter 2025 revenue guidance of between $555m and $563m. Medtech Insight spoke with Tim Czartoski, Enovis’ president of US surgical and global product and enabling technologies, about the firm’s growth strategy and innovation plans.

Digital Health Roundup: Intuitive Surgical CEO Exec Chat, AI Alert System, FDA, Roche New NGS Prototype

In this week’s Digital Health Roundup, Medtech Insight’s Marion Webb highlights her conference coverage from CES, HIMSS, AAOS and LSI including Exec Chats with Gary Guthart, CEO of Intuitive Surgical, and Arcadia’s chief strategy officer Aneesh Chopra. Brian Bossetta highlights a recently FDA-cleared alert system that sends vital signs to clinicians. Elizabeth Orr discusses FDA warning letters sent to Exer Labs for exceeding marketing claims under what is allowed under the device’s 510(k) clearance. Shubham Singh discusses how Roche's unveiling of its next-generation sequencing (NGS) prototype challenges Illumina. The SBX technology is set to compete directly with Illumina’s NovaSeq and NextSeq platforms.

More from Digital Technologies

Thousands Of Cardiac Digital Twins Reveal Novel Connections With Mental Health

 

King’s College London, Imperial College London and The Alan Turing Institute constructed cardiac digital twins at scale, creating over 3,400, in a new study using UK Biobank data published in Nature Cardiovascular Research on 16 May.

Synchron And Apple Team Up To Use ‘Mind-Thought Connection’ To Control iPhones, iPads

 
• By 

Apple and Synchron are teaming up to develop technologies that will one day allow people who can’t use their hands or voice to control iPhones, iPads and other Apple devices by using only their thoughts.

Ketryx Wants Its Validated AI Agents To Accelerate Compliance Workflows

 
• By 

While the initial focus is medical devices and life sciences, Ketryx sees future opportunities in other high-regulation sectors including automotive, aerospace and defense, pharma manufacturing and nuclear systems.