HHS Cybersecurity Task Force makes 3 key resources available

CHICAGO – At the HIMSS23 Healthcare Cybersecurity Forum on Monday, a leader with the Cybersecurity and Infrastructure Security Agency cited some sobering statistics, noting an 86% increase in cyberattacks against hospitals since 2021, with healthcare reporting more such incidents than any other industry.

In response to these escalating threats, the U.S. Department of Health and Human Services on Monday made available a trio of new reports and resources to help providers and public health agencies manage the challenges posed by bad actors whose frequent exploits are only growing in sophistication and severity.

The HHS 405(d) Program, in collaboration with the Health Sector Coordinating Council Cybersecurity Working Group, announced three new tools today.

Knowledge on Demand

This online educational platform offers healthcare organizations free cybersecurity training – the first time HHS has offered such services to the health sector workforce.

This platform offers awareness trainings on five cybersecurity topics:

  • social engineering.

  • ransomware.

  • loss or theft of equipment or data.

  • insider accidental or malicious data loss.

  • attacks against network connected medical devices.

The lessons – videos, PowerPoints and more – can be accessed and launched directly from the 405(d) website.

“Cyberattacks are one of the biggest threats facing our healthcare system today, and the best defense is prevention,” said HHS Deputy Secretary Andrea Palm in a statement.

“These trainings will serve as an asset to any sized organization looking to train staff in basic cybersecurity awareness and are offered free of charge, ensuring that those hospitals and health care organizations most vulnerable to attack can take steps toward resilience. This is part of HHS’s continued commitment to working with hospitals, Congress, and industry leaders in protecting America’s patients.”

Hospital Cyber Resiliency Landscape Analysis

This new 55-page survey (PDF) of the healthcare cybersecurity landscape is meant to benchmark participating hospitals against standard cybersecurity guidelines, such as HICP 2023 and the NIST Cybersecurity Framework.

The survey uses HICP 2023 as a lens through which to give an overview of how health systems are managing common cybersecurity threats, tracking data from hundreds of hospitals of various types and geographies, to spotlight existing best practices and new opportunities for improved resilience.

“The Hospital Cyber Resiliency Initiative Landscape Analysis greatly furthers our understanding of hospital cyber resiliency and provides us with a platform to begin working through potential policy considerations and minimum standards to better support cybersecurity in U.S. hospitals,” said Palm. 

She added: “We look forward to working with hospitals, Congress, and the information security community as we look to improve cyber resiliency and protect patient safety and wellbeing.” said Deputy Secretary Andrea Palm.

Health Industry Cybersecurity Practices, 2023 Edition

Healthcare IT News has reported often on HICP, touted as a cyber preparedness “cookbook” to help cash-strapped health systems, among other imperatives, prioritize and target their cybersecurity resources and get the most bang for their infosec investments.

The new 2023 Edition of HICP has been updated by more than 150 industry and federal professionals to include the most relevant and cost-effective ways to keep patients safe and mitigate the current cybersecurity threats that the HPH sector faces. 

The new edition includes a deep dive on social engineering attacks, labeling them as one of the biggest threats facing the healthcare industry today. 

“Staying current and responsive to evolving cyber threats is critical to protecting patient safety. HICP 2023 is the updated version that our industry needs to make sure they are applying scarce resources to the highest threat,” said Erik Decker, chief information security officer of Intermountain Health and chair of the Health Sector Coordinating Council Cybersecurity Working Group, in a press statement. 

“This will give the most underserved hospitals the best return on investment for cyber investment,” he said.

At the Healthcare Cybersecurity Forum on Monday, Decker offered a bit more insight about the HICP updates, and what the Hospital Cyber Resiliency Landscape Analysis shows about the state of health information security.

The landscape analysis was meant to be “as objective of review as we possibly could do,” he said. And it was taken very much from an adversarial mindset: How are we getting beat as hospitals? And then we can understand how we’re getting beat. And what does the resiliency side of this look like?

“We used HICP as the basis of the whole framework on how we would evaluate the resiliency itself and then found certain practices to be in urgent need of assistance and some practices to be generally OK or just needing some additional research,” he added.

Among many telling observations in the survey, “we saw statistically significant correlation between ownership of the program,” said Decker.

He explained: “If the CISO actually owns the program, you get better pickup coverage, which one would hope that that would be the case. But there’s a lot of CISOs that actually don’t own the full breadth of the cybersecurity program.”

Another finding that “was great to hear and see,” he said, “is that if you have good HICP coverage, [that] has a correlation to [good] NIST cybersecurity coverage. You would think that that would be the case: As you get better at HICP you’re going to get intrinsically better at the Cybersecurity Framework itself, because the framework describes this whole program.

“With those two things,” Decker added, “effectively, what we’re seeing then is when you put more ownership with the CISO you’re going to get better resiliency, you’re going to get better outcomes.”

Mike Miliard is executive editor of Healthcare IT News
Email the writer: mi**********@********ia.com

Healthcare IT News is a HIMSS publication.

Read More
Johnathon Fetzer

Latest

Moore Park South Unveils New Park, 12-Hole Golf Course | Mirage News

NSW Gov Mums, dads and young people from across Sydney are a step closer to being able to enjoy a brand-new park with sports fields, courts, outdoor fitness equipment, a nature playground, shaded picnic spaces with barbecues and more. The Minns Labor Government has today released the final plan for the new 20-hectare park and

HDB resale prices and transactions ease slightly in April 2026, Money News

April 2026 brings a clearer view of how the HDB resale market is evolving. While headline figures show slight changes in both prices and activity, the underlying trends point to a shift in buyer behaviour and market dynamics. HDB resale prices ease slightly in April 2026 In April 2026, the HDB resale market showed signs

Big Breakthrough In Suvendu Aide Chandrakanth’s Murder Probe: Fake Number Plate, Live Rounds, Fired Cartridges Recovered; Vehicle Seized

Updated 7 May 2026 at 10:30 IST On Wednesday, Suvendu Adhikari's PA was allegedly shot at and succumbed to his injuries at a hospital near Madhyamgram. Big Breakthrough In Suvendu Aide Chandranath’s Murder Probe: Fake Number Plate, Live Rounds, Fired Cartridges Recovered; Vehicle Seized | Image: Republic Madhyamgram: West Bengal Police on Thursday seized a

Berkshire-owned distribution giant to deploy driverless big rigs across U.S. Sun Belt

Berkshire Hathaway's McLane, with autonomous trucking company Aurora Innovation, is planning new autonomous freight routes between its distribution centers and restaurants across the U.S. Sun Belt by year-end. Aurora Innovation Berkshire Hathaway subsidiary McLane is planning to deploy self-driving trucking technology from Aurora Innovation on routes in Texas and across the U.S. Sun Belt by

Newsletter

Don't miss

Moore Park South Unveils New Park, 12-Hole Golf Course | Mirage News

NSW Gov Mums, dads and young people from across Sydney are a step closer to being able to enjoy a brand-new park with sports fields, courts, outdoor fitness equipment, a nature playground, shaded picnic spaces with barbecues and more. The Minns Labor Government has today released the final plan for the new 20-hectare park and

HDB resale prices and transactions ease slightly in April 2026, Money News

April 2026 brings a clearer view of how the HDB resale market is evolving. While headline figures show slight changes in both prices and activity, the underlying trends point to a shift in buyer behaviour and market dynamics. HDB resale prices ease slightly in April 2026 In April 2026, the HDB resale market showed signs

Big Breakthrough In Suvendu Aide Chandrakanth’s Murder Probe: Fake Number Plate, Live Rounds, Fired Cartridges Recovered; Vehicle Seized

Updated 7 May 2026 at 10:30 IST On Wednesday, Suvendu Adhikari's PA was allegedly shot at and succumbed to his injuries at a hospital near Madhyamgram. Big Breakthrough In Suvendu Aide Chandranath’s Murder Probe: Fake Number Plate, Live Rounds, Fired Cartridges Recovered; Vehicle Seized | Image: Republic Madhyamgram: West Bengal Police on Thursday seized a

Berkshire-owned distribution giant to deploy driverless big rigs across U.S. Sun Belt

Berkshire Hathaway's McLane, with autonomous trucking company Aurora Innovation, is planning new autonomous freight routes between its distribution centers and restaurants across the U.S. Sun Belt by year-end. Aurora Innovation Berkshire Hathaway subsidiary McLane is planning to deploy self-driving trucking technology from Aurora Innovation on routes in Texas and across the U.S. Sun Belt by

New members for Registration Board | Local Business | trinidadexpress.com

THE Government has appointed new members to the Registration, Recognition and Certification Board (RRCB). The appointments were formalised during a ceremony hosted by the Ministry of Labour on April 10 at the ministry’s head office, International Waterfront Centre, Port of Spain. In a release from the ministry, Labour Minister Leroy Baptiste said the RRCB plays

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID

Business groups are fighting Labor’s CGT changes. Here is where SMEs stand

Labor’s most contested tax reform in a generation cleared its first formal hurdle on Thursday and immediately ran into organised resistance. Treasurer Jim Chalmers introduced the government’s tax reform legislation to the House of Representatives on 28 May, bundling together four budget measures: the capital gains tax overhaul, new limits on negative gearing, a $250

Meet the most influential business owners from Southwest Nigeria

This article spotlights the most influential business owners from Southwest Nigeria, adjudged by their dominance in their respective sectors of the economy where they operate. The post Meet the most influential business owners from Southwest Nigeria appeared first on Nairametrics...