Health Industry Cybersecurity Practices
Managing Threats and Protecting Patients
Resource Topic: Health Information Technology (HIT)/Data
Resource Subtopic: Privacy and Security.
Year Developed: 2019
Resource Type: Publication
Primary Audience: Administrative Staff
Secondary Audience: C-Suite (CEOs, CFOs, CIOs, COOs, CMOs, etc)
Health and Human Services
(See other resources developed by this organization).
Resource Summary: Cyber threats to healthcare entities put patient health, business continuity, and IT systems at risk. Under the auspices of the Cybersecurity Act of 2015 (CSA), Section 405(d), HHS convened the CSA 405(d) Task Group to enhance cybersecurity and align industry approaches by developing a common set of voluntary, consensus-based, and industry-led guidelines, practices, methodologies, procedures, and processes that healthcare organizations can use to enhance cybersecurity.
Resource Details: Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP) was developed to raise awareness, provide vetted cybersecurity practices, and move organizations towards consistency in mitigating the most pertinent cybersecurity threats. The HICP provides guidance on cost-effective methods that a range of healthcare organizations at every size and resource level can use to reduce cybersecurity risks.