Connect with us

Hi, what are you looking for?

Health

HHS Unveils Voluntary Cybersecurity Goals for Health Sector, Paving the Way for Future Mandates

Photo from Bit Developers

Gov Info Security recently reported about the Department of Health and Human Services (HHS) has introduced voluntary cybersecurity performance goals for the healthcare sector, establishing a roadmap for enhanced cybersecurity practices. This move follows the Biden administration’s strategy, released in December, emphasizing the need for a robust cybersecurity posture in healthcare entities. Although voluntary, these goals are expected to influence upcoming HHS rule-making, introducing potential incentives for healthcare organizations to adopt recommended practices.

Photo from BankinfoSecurity

Performance Goals Framework

HHS’ 13-page Cybersecurity Performance Goals document outlines essential and enhanced goals, drawing from industry frameworks like NIST’s Cybersecurity Framework. The “essential goals” focus on foundational practices, while the “enhanced goals” encourage advanced cybersecurity measures.

Deputy Secretary of HHS, Andrea Palm, underscores the responsibility to fortify the healthcare system against cyber threats. The performance goals, she notes, will contribute to proposed enforceable cybersecurity standards across HHS policies and programs.

While labeled “voluntary,” these goals can influence future rule-making, potentially incorporating financial programs to incentivize healthcare entities. This includes an upfront investment program for initial cybersecurity costs and an incentives program to promote advanced practices.

READ ALSO: Weight Loss For Diabetes Control Reveals Significant Heart And Kidney Health Benefits, Study Finds

Essential and Enhanced Goals

Essential goals encompass measures like email security, multifactor authentication, and incident response planning. Enhanced goals target advanced capabilities such as network segmentation and cybersecurity testing.

HHS envisions these goals as addressing common vulnerabilities, safeguarding against cyberattacks, and minimizing residual risk. The guidance aims to elevate cybersecurity as a patient safety imperative.

READ ALSO: Rising Obesity And Remote Work Causing Health Crisis: Nearly One Million Workers Hindered By Back And Neck Problems

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *