Healthcare facility cyberattacks are on the rise.
Per the FBI 2023 Internet Crime report, over the past few years, healthcare organizations have seen the highest number of these costly, disruptive security incidents. That’s the highest of 16 sectors tracked. In fact, the number of reported ransomware attacks directed at U.S. hospital systems nearly doubled from 2022 to 2023. Clear indication cybercriminals increasingly target healthcare institutions.
In late January 2024, the federal Department of Health and Human Services (HHS) and the Cybersecurity Infrastructure Agency (CISA) jointly launched a website that provides information about the Healthcare and Public Health (HPH) voluntary, healthcare-specific Cybersecurity Performance Goals (CPGs).
Goals are split into 10 “essential” goals, and 10 “enhanced” goals. On the website, HHS and CISA describe that the essential performance goals are designed “To help healthcare organizations address common vulnerabilities by setting a floor of safeguards that will better protect them from cyber-attacks, improve response when events occur, and minimize residual risk.”
HHS intends the CPGs to help health care organizations prioritize implementation of high-impact cybersecurity practices. The CPGs are designed to:
- better protect the healthcare sector from cyberattacks,
- improve response when events occur, and
- minimize residual risk.
HPH CPGs include (1) essential goals to outline minimum foundational practices for cybersecurity performance and (2) enhanced goals to encourage adoption of more advanced practices.
The CPGs provide layered protection at different points of weakness in an organization’s technology environment. Layered protections provide redundancy. If one line of defense is compromised, additional layers exist as a backup to ensure that threats are stopped along the way.
Also keep in mind, there’s a lot of room between the floor and the ceiling in cybersecurity best practices. Where would you prefer that your healthcare organization position itself?
What’s the Basis of the CPGs?
Essentially, HHS and CISA pulled from common industry cybersecurity frameworks, best practices, and strategies to develop the essential and the enhanced goals. Health Industry Cybersecurity Practices, NIST Cybersecurity Framework, and the National Cybersecurity Strategy and Implementation Plan, just to name a few. Of course, the HIPAA Security Rule defines a risk management framework in and of itself.
The unifying factor is that all the CPGs tie to standards and specifications within the HIPAA Security Rule. As the Security Rule has been effective for almost 20 years without substantial amendment, the CPG implementation guidance helps move the Security Rule closer to present day norms.
Julia Huddleston, CIPP, CIPM, CCSFP, Principal Consultant, works with Apgar & Associates’ clients on certification readiness, compliance assessments, security risk analysis and policy and procedure review and implementation.