The U.S. Department of Health and Human Services (HHS) has announced a plan to provide resources and incentives for the healthcare industry to adopt cybersecurity measures and to increase potential regulatory penalties for cybersecurity breaches amid growing data security risks to hospitals and health systems.
Quick Hits
- HHS released a concept paper outlining four key steps the department will take to improve cybersecurity across the healthcare sector and provide resources and financial support to implement best practices.
- The paper states HHSâs goals to work with Congress to increase its funding to provide financial support to hospitals to implement cybersecurity practices, expand its enforcement authority, and increase civil monetary penalties for HIPAA violations.
- The performance guidelines include âessential goalsâ to define âminimum foundational practices for cybersecurityâ and âenhanced goalsâ that serve as the best practices for data security.
On December 6, 2023, HHS released a âconcept paper,â âHealthcare Sector Cybersecurity: Introduction to the Strategy of the U.S. Department of Health and Human Services,â outlining four new and ongoing steps HHS will take to âadvance cyber resiliency in the healthcare sector,â especially with respect to high-risk targets like hospitals.
HHS noted that healthcare providers are especially vulnerable to cybersecurity attacks and hold large amounts of sensitive health data of patients, making them âattractive targets for cyber criminals.â According to the HHS Office for Civil Rights (OCR), reported large data breaches increased 93 percent from 2018 to 2022, including a 278 percent increase in reported large breaches involving ransomware.
To address these risks, HHS plans to take the following steps:
- âEstablish voluntary cybersecurity goals for the healthcare sector.â HHS will publish âHealthcare and Public Health Sector-specific Cybersecurity Performance Goalsâ (HPH CPGs) to facilitate the adoption of cybersecurity best practices.
- âProvide resources to incentivize and implement these cybersecurity practices.â HHS stated that it will seek increased funding from the U.S. Congress for hospital cybersecurity investments and expand HHS authority to âenforce new cybersecurity requirements through the imposition of financial consequences for hospitals.â Toward that end, HHS will seek to establish two new programs: (1) âan upfront investments programâ to provide financial support to low-resourced providers and hospitals to cover upfront costs of implementing âessentialâ HPH CPGs; and (2) âan incentives programâ to encourage the adoption of recommended, or âenhanced,â cybersecurity practices.
- âImplement an HHS-wide strategy to support greater enforcement and accountability.â HHS will seek to have the HPH CPGs incorporated into existing regulations to establish ânew enforceable cybersecurity standardsâ and ask Congress to increase monetary penalties for violations of the Health Insurance Portability and Accountability Act (HIPAA). Specifically, HHS will seek comment on two proposed actions: (1) a proposal by the Centers for Medicare and Medicaid Services (CMS) for new cybersecurity requirements for hospitals; and (2) OCR adding cybersecurity requirements to the HIPAA Security Rule (planned for Spring 2024).
- âExpand and mature the one-stop shop within HHS for healthcare sector cybersecurity.â HHS will seek to improve its âone-stop shopâ for cybersecurity support for the healthcare sector within the Administration of Strategic Preparedness and Response (ASPR). Although light on details, the concept paper stated that the âone-stop shopâ will enhance coordination between HHS, the federal government, and private entities and increase the availability of cybersecurity resources for the healthcare sector, such as âtechnical assistance, vulnerability scanning, and more.â
Next Steps
The HHS concept paper highlights the departmentâs and the federal governmentâs priority to protect data privacy, particularly concerning individualsâ sensitive health information. The concept paper comes after the Biden administrationâs âNational Cybersecurity Strategy,â released in March 2023, and builds on HHSâs â2023 Hospital Cyber Resiliency Initiative Landscape Analysis,â which was developed in partnership with the industry and published in April 2023.
According to the paper, HHS seeks to develop both carrots and sticks to drive healthcare providers to improve their cybersecurity. On the positive reinforcement side, HHS will release cybersecurity practices and goals for the industry to follow, and the department will work with Congress to increase its financial resources for supporting hospital cybersecurity investments. If providers violate HIPAA, however, HHS is requesting that Congress expand its enforcement toolkit, both through expansion of HHSâs enforcement authority and through increases to civil monetary penalties.
Healthcare employers might want to review their cybersecurity policies and safeguards in light of the increase in high-profile data breaches (including ransomware attacks) and federal regulatorsâ increased scrutiny. If the impending HPH CPGs ultimately become regulatory requirements at some juncture, as HHS suggests, businesses may be able to take advantage of financial incentives to implement these safeguards proactively while they remain âenhancedâ rather than âessentialâ benchmarks.