Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

HHS.gov
  • About HHS
  • Programs & Services
  • Grants & Contracts
  • Laws & Regulations

Breadcrumb

  1. Home
  2. About
  3. News
  4. HHS Announces Next Steps in Ongoing Work to Enhance Cybersecurity for Health Care and Public Health Sectors
  • News
  • Blog
  • HHS Live
  • Podcasts
  • Media Guidelines for HHS Employees
FOR IMMEDIATE RELEASE
December 6, 2023
Contact: HHS Press Office
202-690-6343
media@hhs.gov

HHS Announces Next Steps in Ongoing Work to Enhance Cybersecurity for Health Care and Public Health Sectors

Concept paper highlights ongoing and planned steps to improve cyber resiliency and protect patient safety.

WASHINGTON – The U.S. Department of Health and Human Services (HHS) today released a concept paper that outlines the Department’s cybersecurity strategy for the health care sector. The concept paper builds on the National Cybersecurity Strategy that President Biden released last year, focusing specifically on strengthening resilience for hospitals, patients, and communities threatened by cyber-attacks. The paper details four pillars for action, including publishing new voluntary health care-specific cybersecurity performance goals, working with Congress to develop supports and incentives for domestic hospitals to improve cybersecurity, and increasing accountability and coordination within the health care sector.

According to the HHS Office for Civil Rights (OCR), cyber incidents in health care are on the rise. From 2018-2022, there has been a 93% increase in large breaches reported to OCR (369 to 712), with a 278% increase in large breaches involving ransomware. Cyber incidents affecting hospitals and health systems have led to extended care disruptions, patient diversions to other facilities, and delayed medical procedures, all putting patient safety at risk.

“Since entering office, the Biden-Harris Administration has worked to strengthen the nation’s defenses against cyberattacks. The health care sector is particularly vulnerable, and the stakes are especially high. Our commitment to this work reflects that urgency and importance,” said HHS Secretary Xavier Becerra. “HHS is working with health care and public health partners to bolster our cyber security capabilities nationwide. We are taking necessary actions that will make a big difference for the hospitals, patients, and communities who are being impacted.”

“Hospitals across the country have experienced cyberattacks, leading to cancelled medical treatments and stolen medical records. Such impacts are preventable – to keep Americans safe, the Biden-Harris Administration is establishing strong cybersecurity standards for health care organizations and enhancing resources to improve cyber resiliency across the health sector, including working with Congress to provide financial support for hospitals. Today’s announcement by HHS builds on Biden-Harris Administration’s work to operationalize smart cybersecurity practices in our nation’s most critical sectors, like pipelines, aviation, and rail systems,” said Anne Neuberger, Deputy National Security Adviser for Cyber and Emerging Technologies.

“The health care sector is experiencing a significant rise in cyberattacks, putting patient safety at risk. These attacks expose vulnerabilities in our health care system, degrade patient trust, and ultimately endanger patient safety,” said HHS Deputy Secretary Andrea Palm. “HHS takes these threats very seriously, and we are taking steps that will ensure our hospitals, patients, and communities impacted by cyberattacks are better prepared and more secure.”

The HHS concept paper outlines the following actions:

  • Publish voluntary Health care and Public Health sector Cybersecurity Performance Goals (HPH CPGs). HHS will release HPH CPGs to help health care institutions plan and prioritize implementation of high-impact cybersecurity practices.
  • Provide resources to incentivize and implement cybersecurity practices. HHS will work with Congress to obtain new authority and funding to administer financial support and incentives for domestic hospitals to implement high-impact cybersecurity practices.
  • Implement an HHS-wide strategy to support greater enforcement and accountability. HHS will propose new enforceable cybersecurity standards, informed by the HPH CPGs, that would be incorporated into existing programs, including Medicare and Medicaid and the HIPAA Security Rule.
  • Expand and mature the one-stop shop within HHS for healthcare sector cybersecurity. HHS will mature the Administration for Strategic Preparedness and Response’s (ASPR) coordination role as a “one-stop shop” for health care cybersecurity which will improve coordination within HHS and the Federal Government, deepen HHS and the Federal government’s partnership with industry, improve access and uptake of government support and services, and increase HHS’s incident response capabilities.

The full concept paper is available here.

The President’s National Cyber Security Strategy is available here.

###
Note: All HHS press releases, fact sheets and other news materials are available at https://www.hhs.gov/news.
Like HHS on Facebook, follow HHS on Twitter @HHSgov, and sign up for HHS Email Updates.
Last revised: December 6, 2023

Sign Up for Email Updates

Receive the latest updates from the Secretary, Blogs, and News Releases

Sign Up

Subscribe to RSS

Receive latest updates

Subscribe to our RSS

Related News Releases

  • HHS Expands TEFCA by Adding Two Additional QHINs

  • Health Resources and Services Administration Takes Historic New Steps to Transform the Organ Transplant System to Better Serve Patients

  • Guiding Principles Help Healthcare Community Address Potential Bias Resulting from Algorithms

Related Blog Posts

  • HHS Blog thumbnail

    Reflecting on Cybersecurity Awareness Month

  • HHS Blog thumbnail

    Navigating Section 752: Insights from Program Managers on Success, Challenges, and Tools for Change

  • HHS Blog thumbnail

    Thank you to the 2023 Civic Digital Fellows

Media Inquiries

For general media inquiries, please contact media@hhs.gov.

Content created by Assistant Secretary for Public Affairs (ASPA)
Content last reviewed December 6, 2023
Back to top
  • Contact HHS
  • Careers
  • HHS FAQs
  • Nondiscrimination Notice
  • HHS Archive
  • Accessibility
  • Privacy Policy
  • Viewers & Players
  • Budget/Performance
  • Inspector General
  • Web Site Disclaimers
  • EEO/No Fear Act
  • FOIA
  • The White House
  • USA.gov
  • Vulnerability Disclosure Policy

Sign Up for Email Updates

Receive the latest updates from the Secretary, Blogs, and News Releases.

Sign Up
HHS Logo

HHS Headquarters

200 Independence Avenue, S.W.
Washington, D.C. 20201
Toll Free Call Center: 1-877-696-6775​