Generated by All in One SEO Pro v4.9.10, this is an llms.txt file, used by LLMs to index the site. # Health Sector Council Health Sector Coordinating Council ## Sitemaps - [XML Sitemap](https://healthsectorcouncil.org/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Health Sector Publishes Framework A.I. Cybersecurity Governance](https://healthsectorcouncil.org/health-sector-publishes-framework-a-i-cybersecurity-governance/) - New resource by the sector’s primary critical infrastructure advisory council helps healthcare organizations create and manage enterprise cybersecurity governance for AI. Washington, DC – June 1, 2026 Today the Cybersecurity Working Group (CWG) of the Health Sector Coordinating Council (HSCC) published a guide to help healthcare organizations (HCOs) establish cyber governance frameworks for secure AI - [Health Industry AI Cybersecurity Governance Framework Implementation Guide](https://healthsectorcouncil.org/ai-cyber-governance/) - This guide addresses unique cybersecurity and privacy challenges as the sector adopts artificial intelligence across clinical and operational use cases, targeting the identification and mitigation of AI-specific cyber risks, including data poisoning, model drift, and adversarial attacks, while ensuring compliance with the healthcare sector’s complex regulatory environment. It addresses the full spectrum of AI technologies deployed - [AI Cyber Glossary](https://healthsectorcouncil.org/ai-cyber-glossary/) - The AI Cyber Glossary is a living reference document establishing consistent, governance-ready definitions for artificial intelligence terminology across the health sector. It was developed in direct response to a critical gap in managing healthcare AI and AI cybersecurity: the absence of shared, sector-specific language that clinical, operational, compliance, and technical stakeholders can use with confidence. - [Third-Party AI Risk and Supply Chain Transparency Guide](https://healthsectorcouncil.org/ai-cyber-thirdparty/) - This document addresses the growing gaps in discovery and disclosure processes that make AI supply chain risk so difficult to manage. Many HCOs operate with incomplete or outdated vendor inventories, while AI-specific cybersecurity risks - such as synthetic data misuse, training data leakage, and adversarial inference - go unreported by vendors. To counter this, the - [Q1 2026 Progress Report](https://healthsectorcouncil.org/q1-2026-progress-report/) - [HSCC Cybersecurity Working Group 2025](https://healthsectorcouncil.org/2025-annual-report/) - [Health Sector Publishes Guide for Third-Party A.I. Cybersecurity](https://healthsectorcouncil.org/health-sector-publishes-ai-cyber-third-party-guide/) - New resource by the sector for the sector helps healthcare organizations manage AI-enabled third-party technology and services that need cybersecurity oversight. Washington, DC – April 15, 2026 Today the Cybersecurity Working Group (CWG) of the Health Sector Coordinating Council (HSCC) is providing healthcare organizations with best practices to address the realities of AI-driven supply chains - [Health Sector Statement of Support for Improving Cyber Safety to Protect Patient Safety](https://healthsectorcouncil.org/sign-the-statement-of-support/) - The Undersigned Organizations Agree: The United States Healthcare and Public Health (Health) Sector continues to face dramatic increases in cyber-attacks, causing disruption to patient safety, the care continuum and the operation of supporting network-connected products and services; Cyber preparedness and resiliency of the Health Sector depend on a collective defense involving all Health subsectors and - [HSCC Cybersecurity Working Group 2024 Annual Report](https://healthsectorcouncil.org/2024-annual-report/) - Healthcare and Public Health Sector Coordinating Council Cybersecurity Working Group 2024 Annual Report - [Model Contract-Language for MedTech Cybersecurity - Version 2](https://healthsectorcouncil.org/model-contract-language-for-medtech-cybersecurity/) - MC2 version 2 offers an updated reference from the 2022 version 1 for shared cooperation and coordination between Healthcare Delivery Organizations (HDOs) and Medical Device Manufacturers (MDMs) regarding the security, compliance, management, operation, services, and security of MDM-managed medical devices, solutions, and connections. - [Health Sector Publishes Updated Cybersecurity Model Contract](https://healthsectorcouncil.org/health-sector-publishes-updated-cybersecurity-model-contract/) - St. Louis, MO – November 18, 2025 Today during its semi-annual All-Hands Membership meeting hosted by University of Health Sciences and Pharmacy in St. Louis, the Cybersecurity Working Group (CWG) of the Healthcare and Public Health Sector Coordinating Council (HSCC) published an updated reference for shared cooperation and coordination between Healthcare Delivery Organizations (HDOs) and - [Health Sector Publishes Previews to AI Cybersecurity Guidances](https://healthsectorcouncil.org/ai-cybersecurity-onepagers/) - This series of one-page summaries of five separate HSCC Cybersecurity workstreams on Artificial Intelligence offers a preview of best practices and white papers that the Cybersecurity Working Group will publish in 2026 about A.I.: 1) Education and Enablement; 2) Cyber Operations and Defense; 3) Governance; 4) Secure by Design; and 5) Third Party Risk and - [Health Industry Cybersecurity - Sector Mapping and Risk Toolkit (SMART)](https://healthsectorcouncil.org/smart-toolkit/) - The SMART Toolkit provides templates and a methodology to visualize, identify and measure systemic risk posed by third party technology, software and communications services essential to clinical, administrative and manufacturing workflows. This resource is intended for cybersecurity, supply chain, risk, operational and administrative executives across health industry organizations of all sizes and subsectors, including manufacturers, - [HSCC Garcia Testimony to Senate Health, Education , Labor and Pensions (HELP) Committee](https://healthsectorcouncil.org/government-partners-forward-path-2025-senate-help-testimony/) - My statement today will offer what we believe the health sector and government need to do collaboratively to get ahead of ongoing cyber incidents and reduce their likelihood and impact. - [HSCC Garcia Testifies to Senate Health, Education, Labor and Pensions (HELP) Committee](https://healthsectorcouncil.org/government-partners-forward-path-2025-senate-help-hearing-testimony-press-release/) - Washington, D.C., July 9, 2025 - Today, the Healthcare and Public Health Sector Coordinating Council (HSCC) testified on a panel to the Senate Committee on Health, Education, Labor and Pensions to make recommendations on the direction of government and industry collaboration against ongoing cybersecurity threats and incidents impacting the health sector. - [HSCC Announces Healthcare Cybersecurity Policy Recommendation at Congressional Hearing](https://healthsectorcouncil.org/government-partners-forward-path-2025-policy-statement-press-release/) - HSCC announced at a congressional hearing their recommendation for a one-year consultative process with the Trump Administration on healthcare cybersecurity. - [HSCC Garcia Testimony to House Energy and Commerce Oversight and Investigations Subcommittee](https://healthsectorcouncil.org/government-partners-forward-path-2025-april-congressional-testimony/) - HSCC Garcia's testimony to the House Energy and Commerce Oversight and Investigations Subcommittee is available for download. Learn more. - [2025 Health Industry Cybersecurity Recommendations for Government Policy and Programs](https://healthsectorcouncil.org/government-partners-forward-path-2025-cyber-program-recommendations/) - Download the Health Sector Coordinating Council's 2025 recommendations for government policy and programs to strengthen healthcare cybersecurity. - [HSCC Statement on Healthcare Cybersecurity Policy](https://healthsectorcouncil.org/government-partners-forward-path-2025-cyber-policy-statement/) - HSCC Cybersecurity Working Group's statement on healthcare cybersecurity policy is available for download. - [Healthcare Sector Coordinating Council Cybersecurity Working Group Charter](https://healthsectorcouncil.org/healthcare-sector-coordinating-council-1-cybersecurity-working-group-2-charter/) - Healthcare Sector Coordinating Council’s Cybersecurity Working Group Charter - Learn about critical healthcare cybersecurity efforts and initiatives. - [Health Industry Cybersecurity Practices 2023](https://healthsectorcouncil.org/health-industry-cybersecurity-practices-2023/) - The HICP 2023 is an update to the 2019 HICP publication developed jointly by the HSCC and HHS. It provides executives, health care practitioners, providers, and health delivery organizations, such as hospitals, with best practices for managing cyberthreats to safeguard patient safety. Click to Download Vol 1 Click to Download Vol 2 - [On the Edge: Cybersecurity Health of America’s Resource-Constrained Health Providers](https://healthsectorcouncil.org/on-the-edge-cybersecurity-health-of-americas-resource-constrained-health-providers/) - This report examines how resource-constrained health care systems - small, rural, critical access, family clinics, skilled nursing facilities, FQHCs and many more across the country - are only marginally prepared for ongoing cyber threats to clinical care and operational liquidity, and recommends forms of support they would need against stiffer cybersecurity regulatory requirements. “On the - [Health Industry Cybersecurity Recommendations for Government Policy and Programs](https://healthsectorcouncil.org/health-industry-cybersecurity-recommendations-for-government-policy-and-programs/) - Updated 03/2025 This compilation of policy and programmatic considerations is offered for the U.S. Department of Health and Human Services, the Cybersecurity and Infrastructure Security Agency, Congress and other Federal agencies to support healthcare cybersecurity. If implemented under existing or new statutory authorities, these concepts could help reduce risk across the sector through incentive- or - [Health Sector Publishes Medical Product Manufacturer Cyber Incident Response Playbook](https://healthsectorcouncil.org/health-sector-publishes-medical-product-manufacturer-cyber-incident-response-playbook/) - Health Sector Publishes Medical Product Manufacturer Cyber Incident Response Playbook on November 13th 2024. - [Medical Product Manufacturer Cyber Incident Response Playbook (MPM CIRP)](https://healthsectorcouncil.org/ot_cyber_irp/) - The Medical Product Manufacturer Cyber Incident Response Playbook (MPM CIRP) is a comprehensive guide that provides information, step-by-step recommendations, and processes for medical product manufacturers to use in responding to manufacturing cyber incidents. - [Health Sector Publishes Cyber Incident Response Executive Checklist](https://healthsectorcouncil.org/health-sector-publishes-cyber-incident-response-executive-checklist/) - This checklist aims to raise awareness about critical considerations for informed and swift executive decision-making during and after a cybersecurity incident. - [CHIME Response to ASPR’s 2023-2026 National Health Security Strategy](https://healthsectorcouncil.org/chime-response-to-asprs-2023-2026-national-health-security-strategy/) - The College of Healthcare Information Management Executives (CHIME) and the Association for Executives in Healthcare Information Security (AEHIS) welcomes the opportunity to submit comments in response to the Assistant Secretary for Preparedness and Response (ASPR) 2023-2026 National Health Security Strategy (NHSS) Request for Information (RFI) published in the Federal Register on February 14, 2022. Our - [Cyber Incident Response Executive Checklist](https://healthsectorcouncil.org/hscc-publications-execchecklist/) - This checklist aims to raise awareness about critical considerations for informed and swift executive decision-making during and after a cybersecurity incident. These considerations are categorized into Incident Response, Business Continuity, and Communication sections below. By familiarizing themselves with these strategic concerns in advance, healthcare executives can enhance their preparedness to ask the right questions and - [07/06/2022: HSCC Cyber Working Group Q2 2022 Report](https://healthsectorcouncil.org/q2-2022-report/) - HSCC Cyber Working Group Q2 2022 Report - [HSCC Cybersecurity Working Group Q1 2024 Report](https://healthsectorcouncil.org/q1-2024-report/) - Quarter 1 2024 Report by Health Sector Council - [HSCC Cyber Working Group 2023 Annual Report](https://healthsectorcouncil.org/annual-report/) - Explore the Health Sector Council’s 2023 Annual Report for insights into key initiative and advancements in healthcare cybersecurity. - [Health Industry Cybersecurity Strategic Plan 2024-2029](https://healthsectorcouncil.org/the-plan/) - The Health Industry Cybersecurity Strategic Plan (HIC-SP) is a call to action for organizations throughout the healthcare ecosystem to implement foundational cybersecurity programs that address the operational, technological, and governance challenges posed by significant healthcare industry trends over the next five years. - [HSCC Health Industry Cybersecurity Strategic Plan FAQ](https://healthsectorcouncil.org/faq/) - Browse answers to common questions about healthcare cybersecurity on the Health Sector Council’s FAQ page. Stay informed and secure. - [HSCC Health Industry Cybersecurity Strategic Plan Overview](https://healthsectorcouncil.org/overview-presentation/) - The HSCC Health Industry Cybersecurity Strategic Plan Overview offers key initiatives and advancements in the healthcare sector. - [HHS and HSCC Release Voluntary Cybersecurity Practices for the Health Industry](https://healthsectorcouncil.org/hicp/) - The Health Sector Coordinating Council (HSCC), in partnership with the U.S. Department of Health and Human Services, is pleased to announce the release of the “Health Industry Cybersecurity Practices (HICP): Managing Threats and Protecting Patients” publication. The four-volume publication seeks to raise awareness for executives, health care practitioners, providers, and health delivery organizations, such as - [JSP2 Infographic](https://healthsectorcouncil.org/jsp2-infographic/) - The HSCC’s MedTech JSP2 infographic illustrates advancements in healthcare technology standards, providing valuable insights. - [HSCC MEDTECH JSP 2.0 Overview](https://healthsectorcouncil.org/hscc-medtech-jsp-2-0-overview/) - Review the overview of HSCS’s Medtech JSP 2.0, advancing medical technology standards and collaboration in the healthcare sector. - [12/17/2020: HSCC Support for HR 7898](https://healthsectorcouncil.org/hscc-letter-supporting-hr7898/) - Review the Healthcare Sector Coordinating Council’s letter supporting HR7898, advocating for healthcare sector support. - [HSCC CWG Policy Task Group Comments on HHS ONC RFI](https://healthsectorcouncil.org/hscc-cwg-policy-task-group-comments-on-hhs-onc-rfi/) - Browse the Healthcare Sector Coordinating Council policy task group’s comments on HHS ONC RFI, shaping healthcare policy and regulations. - [HSCC Comment on HHS OCR RFI Implementing P.L. 166-321](https://healthsectorcouncil.org/hscc-comment-on-hhs-ocr-rfi-implementing-p-l-166-321/) - Discover the Healthcare Sector Coordinating Council’s comments on HHS OCR’s RFI for implementing P.L. 166-321 regarding healthcare regulations. - [HPH SCC Cybersecurity Working Group Comments on OIG and CMS Companion Proposed Rules RFI](https://healthsectorcouncil.org/hph-scc-cybersecurity-working-group-comments-on-oig-and-cms-companion-proposed-rules-rfi/) - Explore insights from the Healthcare Sector Coordinating Council’s cybersecurity working group on OIG and CMS companion proposed rules RFI. - [HPH SCC Cybersecurity Working Group Comments on HHS ONC Information Blocking RFI](https://healthsectorcouncil.org/hph-scc-cybersecurity-working-group-comments-on-hhs-onc-information-blocking-rfi/) - Browse insights from the Healthcare Sector Coordinating Council’s cybersecurity working group’s feedback on HHS ONC’s Information Blocking RFI. - [HPH SCC Cybersecurity Working Group Comments on HHS OIG Anti-Kickback Statute RFI](https://healthsectorcouncil.org/hph-scc-cybersecurity-working-group-comments-on-hhs-oig-anti-kickback-statue-rfi/) - Discover insights from the Healthcare Sector Coordinating Council’s cybersecurity working group on HHS OIG’s Anti-Kickback Statute RFI. - [Health Sector Council Letter to CMS on Stark Exception](https://healthsectorcouncil.org/health-sector-council-letter-to-cms-on-stark-exception/) - Browse the Health Sector Council’s letter to CMS on Stark Exception, focusing on healthcare cybersecurity and regulatory compliance. - [H-ISAC-HSCC Comments on Warner Report](https://healthsectorcouncil.org/h-isac-hscc-comments-on-warner-report/) - Review Health-ISAC and HSCC’s comments on the Warner Report, addressing critical issues in healthcare cybersecurity and industry responses. - [Erik Decker on Cybersecurity Best Practices](https://healthsectorcouncil.org/erik-decker-on-cybersecurity-best-practices/) - Discover cybersecurity best practices from Erik Decker to Safeguard healthcare data and systems effectively. - [12/30/2020: HSCC Comment on FDA Cybersecurity Vulnerability Communications Framework](https://healthsectorcouncil.org/12-30-2020-hscc-comment-on-fda-cybersecurity-vulnerability-communications-framework/) - Review HSCC’s comment on FDA cybersecurity vulnerability communications framework, which enhances healthcare data protection strategies. - [12/07/2020: AHA Testifies to Congress on Healthcare Cybersecurity](https://healthsectorcouncil.org/12-07-2020-aha-testifies-to-congress-on-healthcare-cybersecurity/) - AHA Testifies to Congress on Healthcare Cybersecurity - Discover insights addressing critical strategies for safeguarding data. - [06/09/2021: Health Sector Cybersecurity Letter to President Biden](https://healthsectorcouncil.org/06-09-2021-health-sector-cybersecurity-letter-to-president-biden/) - Explore the Health Sector Cybersecurity Letter to President Biden addressing key challenges and recommendations in healthcare cybersecurity. - [Healthcare Industry Cybersecurity Workforce Guide](https://healthsectorcouncil.org/workforce-guide/) - The HIC Workforce Guide is a tool kit for recruiting and retaining skilled cybersecurity workforce in the healthcare sector. - [Management Checklist for Teleworking Surge During COVID-19 Response](https://healthsectorcouncil.org/covid-checklist/) - The Teleworking Management Checklist is designed as a quick reference for healthcare enterprise management to consider important factors in a teleworking strategy that minimizes downtime and latency while supporting patient care, operational and I.T. security, and supply chain resilience. - [Health Sector Return-to-Work Guidance](https://healthsectorcouncil.org/r2w/) - This guidance compiles recommendations and considerations for managing a return-to-work (“R2W”) strategy for our healthcare institutions and companies approaching COVID phase-down, both domestically and internationally. - [Reprint Health Industry Cybersecurity – Securing Telehealth and Telemedicine (HIC-STAT)](https://healthsectorcouncil.org/health-industry-cybersecurity-securing-telehealth-and-telemedicine-hic-stat/) - Oct 2023 HIC-STAT identifies cyber risks and best practices associated with the use of telehealth and telemedicine, and summarizes the policy and regulatory underpinnings for telehealth/telemedicine cyber risk management. - [Updated Health Industry Cybersecurity Supply Chain Risk Management Guide - Version 2023 (HIC-SCRiM-v2)](https://healthsectorcouncil.org/health-industry-cybersecurity-supply-chain-risk-management-guide-hic-scrim-2023/) - The 2023 HIC-SCRiM is a toolkit for small to mid-sized healthcare institutions to better ensure the security of the products and services they procure through an enterprise supply chain cybersecurity risk management program. - [Health Sector Cybersecurity Working Group Testifies to House Energy and Commerce Committee with Recommendations for Preventing Future Catastrophic Cyber Attacks](https://healthsectorcouncil.org/health-sector-cybersecurity-working-group-testifies-to-house-energy-and-commerce-committee-with-recommendations-for-preventing-future-catastrophic-cyber-attacks/) - Washington, D.C., April 16, 2024 - Today, the Healthcare and Public Health Sector Coordinating Council (HSCC) testified on a panel to the House Energy and Commerce Subcommittee on Health about the aftermath of the Change Healthcare cyber attack on the nation’s health systems, and how to prevent future disruptions of such magnitude. HSCC Cybersecurity Working - [Examining Health Sector Cybersecurity in the Wake of the Change Healthcare Attack - Congressional Testimony](https://healthsectorcouncil.org/housetestimony/) - Testimony of Greg Garcia, Executive Director of the Healthcare and Public Health Sector Coordinating Council Cybersecurity Working Group on “Examining Health Sector Cybersecurity in the Wake of the Change Healthcare Attack” before the United States House of Representatives Committee on Energy and Commerce Health Subcommittee, on April 16, 2024. - [HHS Providers Resource for Change Healthcare Recovery](https://healthsectorcouncil.org/contactsforrecovery/) - In light of continuing concerns expressed by health providers about their difficulty getting answers from healthcare plans about the availability of prospective payments or the flexibilities while the Change Healthcare platform is unavailable, HHS asked health plans to provide specific national contact information that providers can use when they need this information. The attached letter - [The Joint Security Plan (JSP)](https://healthsectorcouncil.org/the-joint-security-plan-2018/) - [Medical Device and Health IT Joint Security Plan version 2 (JSP2)](https://healthsectorcouncil.org/jsp2/) - The JSP2 offers important updates and a major refresh of the original JSP published in 2019. JSP is a total product lifecycle reference guide to developing, deploying and supporting cyber secure technology solutions in the health care environment. The JSP utilizes “secure-by-design” and “secure-by-default" principles throughout the product lifecycle of medical devices and health IT - [Health Industry Publishes Guide for Medical Device and Health IT Security](https://healthsectorcouncil.org/health-industry-publishes-guide-for-medical-device-and-health-it-security/) - The Healthcare and Public Health Sector Coordinating Council (HSCC) Cybersecurity Working Group today published updated recommendations for manufacturing and managing the security of medical devices for clinical practice. Washington, DC – March 15, 2024 - The Healthcare and Public Health Sector Coordinating Council (HSCC) Cybersecurity Working Group today published updated recommendations for manufacturing and managing - [Health Sector Mobilizes Against Cyber Threats](https://healthsectorcouncil.org/health-sector-mobilizes-against-cyber-threats/) - June 29 Health Sector Council Meeting in Washington gathers 120 industry and government leaders to meet the threat. Washington, DC – July 17 - More than 100 healthcare providers, associations, pharmaceutical, medical device and health IT companies met with government officials in Washington DC June 29 to report and build on their collective progress toward - [Health Sector Council Pushes for Changes in Federal Cybersecurity Rules](https://healthsectorcouncil.org/health-sector-council-pushes-for-changes-in-federal-cybersecurity-rules/) - [The Fight to Secure Vulnerable Medical Devices From Hackers](https://healthsectorcouncil.org/health-sector-council-advocates-for-securing-medical-devices-from-hackers/) - [CHIME-KLAS 2018 Medical Device Security Survey](https://healthsectorcouncil.org/chime-klas-2018-medical-device-security-survey/) - [HPH-SCC Set To Issue Cybersecurity Best Practices for Healthcare](https://healthsectorcouncil.org/hph-scc-set-to-issue-cybersecurity-best-practices-for-healthcare/) - [Preventing a 'Doomsday' Healthcare Cyber Event](https://healthsectorcouncil.org/preventing-a-doomsday-healthcare-cyber-event/) - [HPH SCC Blog – During NCSAM, HSCC CWG Advocates for Patient Safety at HHS](https://healthsectorcouncil.org/hscc-cwg-blog-during-ncsam-cwg-policy-task-group-advocates-for-patient-safety-at-hhs/) - As National Cyber Security Awareness Month (NCSAM) passes its halfway point this October, it is important to note that the healthcare sector – both industry and government – is stepping up to address accelerating cybersecurity threats affecting healthcare operations, data, and patient safety. In the late summer of 2018, the HHS Office of the National - [HPH SCC Blog – Building a Stronger Healthcare Workforce for Cybersecurity](https://healthsectorcouncil.org/hph-scc-blog-building-a-stronger-healthcare-workforce-for-cybersecurity/) - The healthcare sector is working hard to get ahead of the threats facing the sector and its parent population in participation with government and critical healthcare subsectors. - [HPH SCC Blog – Patient Safety Would Benefit from Cybersecurity Exception to Anti-Kickback Statute](https://healthsectorcouncil.org/hph-scc-blog-patient-safety-would-benefit-from-cybersecurity-exception-to-anti-kickback-statute/) - Patient Safety Would Benefit from Cybersecurity Exception to Anti-Kickback Statute - [HSCC Wants Healthcare Cybersecurity Waiver to Anti-kickback Rules](https://healthsectorcouncil.org/hscc-wants-healthcare-cybersecurity-waiver-to-anti-kickback-rules/) - [HSCC Releases the Medical Device and Health IT Joint Security Plan](https://healthsectorcouncil.org/hscc-releases-the-medical-device-and-health-it-joint-security-plan/) - The JSP is a total product lifecycle reference guide to developing, deploying and supporting cyber secure technology solutions in the health care environment. - [HSCC Cybersecurity Working Group releases the 2018 Annual Report](https://healthsectorcouncil.org/hscc-cybersecurity-working-group-releases-the-2018-annual-report/) - We are pleased to bring you our 2018 Annual Report highlighting our many accomplishments over the past year. In 2018 we released a resource guide titled “Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients” which is a scalable toolkit of the top ten cybersecurity best practices for hospital systems and developed the Medical Device & - [Join the HICP Five Threat Presentation Series in March and April 2019](https://healthsectorcouncil.org/join-the-hicp-five-threat-presentation-series-in-march-and-april-2019/) - HICP Five Threat Presentation Series -- March & April 2019 - [HICP's 5 Threat Weekly Webinar Series](https://healthsectorcouncil.org/hicps-5-threat-weekly-webinar-series/) - With the recent release of the Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients publication, the 405(d) initiative is happy to announce the: HICP’s 5 Threat Weekly Series! The Series kicks off this week with Threat 1 – Email Phishing Five Threats Series Details: Dates of Engagement All at 2 PM EST Week 1/Threat - [HSCC Releases the Healthcare Industry Cybersecurity Workforce Guide](https://healthsectorcouncil.org/hscc-releases-workforce-guide/) - [HSCC JCWG 2019 Mid-Year Report](https://healthsectorcouncil.org/hscc-jcwg-2019-mid-year-report/) - [Health Industry Publishes Matrix of Cybersecurity Information Sharing Organizations](https://healthsectorcouncil.org/health-industry-publishes-matrix-of-cybersecurity-information-sharing-organizations/) - [The 405(d) Post: Healthcare Industry Cybersecurity News and Emerging Issues](https://healthsectorcouncil.org/the405dpost/) - The 405(d) Post aims to align health care industry security approaches by discussing cybersecurity news and emerging issues facing the healthcare industry. Each issue will include an article from our industry partners discussing cybersecurity topics affecting their organizations, emerging threats, innovative technologies and preparedness techniques. This newsletter also highlights the 405(d) HICP Publication, current cybersecurity - [09/01/2019: The 405(d) Post Volume One](https://healthsectorcouncil.org/11-20-2020-the-405d-post-volume-one/) - [Patient Safety Depends on Cyber Safety - HSCC JCWG Blog Celebrates NCSAM](https://healthsectorcouncil.org/2019-ncsam-hscc-jcwg-blog-1/) - [Clinical Cybersecurity: Beating the Cyber Virus Like the Human Virus - NCSAM Blog](https://healthsectorcouncil.org/2019-ncsam-hscc-jcwg-blog-2/) - [Leadership and Cybersecurity Infographic](https://healthsectorcouncil.org/leadership-and-cybersecurity-infographic/) - [HSCC Applauds Stark Waiver and HHS for Cybersecurity Assistance to Health Systems](https://healthsectorcouncil.org/hscc-applauds-stark-waiver-and-hhs-for-cybersecurity-assistance-to-health-systems/) - [Health Sector Publishes Guidance on Supply Chain Cybersecurity Risk Management](https://healthsectorcouncil.org/health-sector-publishes-guidance-on-supply-chain-cybersecurity-risk-management/) - [The Healthcare Cyber Circulatory System: Supply Chain Security - NCSAM Blog](https://healthsectorcouncil.org/2019-ncsam-hscc-jcwg-blog-3/) - [Connected Health and Cybersecurity: Advice for the Device – NCSAM Blog](https://healthsectorcouncil.org/2019-ncsam-hscc-jcwg-blog-4/) - [Protecting Critical Healthcare Innovation Capital From Cyber Theft - NCSAM Blog](https://healthsectorcouncil.org/2019-ncsam-hscc-jcwg-blog-4-2/) - [The 405(d) Post Volume Two](https://healthsectorcouncil.org/the405dpost-vol-2/) - The 405(d) Post aims to align health care industry security approaches by discussing cybersecurity news and emerging issues facing the healthcare industry. This issue includes an article from one of our industry partners discussing the differences between Base HIPAA Compliance and Cybersecurity Best Practices. Due to recent uptick in Ransomware attacks, the rest of this - [Cyber Working Group Vice Chair Theresa Meadows on Why Medical Device Security Is So Challenging](https://healthsectorcouncil.org/cyber-working-group-vice-chair-theresa-meadows-on-why-medical-device-security-is-so-challenging/) - Theresa Meadows Discusses Medical Device Security on Healthcare Info Security. - [Health IT Security - "HSCC Tells HHS: Include Patching in Stark Law Cybersecurity Donations"](https://healthsectorcouncil.org/health-it-security-hscc-tells-hhs-include-patching-in-stark-law-cybersecurity-donations/) - HSCC advises HHS to include patching in Stark Law cybersecurity donations in a policy comment letter to HHS. The policy comment letter was submitted on December 31st, 2019 and available on our website. - [Healthcare Info Security - "Nation-State Attacks: Why Healthcare Must Prepare"](https://healthsectorcouncil.org/healthcare-info-security-nation-state-attacks-why-healthcare-must-prepare/) - Errol Weiss, Chief Security Officer of H-ISAC, Outlines Critical Steps in Wake of Iran Tensions. - [The 405(d) Post Volume Three](https://healthsectorcouncil.org/the-405d-post-vol-3/) - [CHiME - CMS’ Stark and OIG’s Anti-Kickback Proposed Rules: Cybersecurity Donation Exception / Safe Harbor](https://healthsectorcouncil.org/chime-cms-stark-and-oigs-anti-kickback-proposed-rules-cybersecurity-donation-exception-safe-harbor/) - CHiME released an overview of CMS’ Stark and OIG’s Anti-Kickback Proposed Rules. The document is a cheat sheet for regulatory ease of reference on the proposed cybersecurity donation exception / safe harbor. - [2019 Annual Report - HSCC Cybersecurity Working Group](https://healthsectorcouncil.org/hscc-cwg-2019-annual-report/) - [Health Industry Publishes Management Checklist for Teleworking Surge During COVID-19 Response](https://healthsectorcouncil.org/covid-19-response-checklist-pressrelease/) - [Health Industry Publishes Cybersecurity Information Sharing Best Practices](https://healthsectorcouncil.org/info-sharing-guide-press-release/) - [The Hill - "Health Groups Vulnerable to Cyberattacks as Coronavirus Crisis Ramps Up"](https://healthsectorcouncil.org/the-hill-health-groups-vulnerable-to-cyberattacks-as-coronavirus-crisis-ramps-up/) - [The 405(d) Post Volume Four](https://healthsectorcouncil.org/the-405d-post-vol-four/) - [New 405(d) Cybersecurity Awareness Resource](https://healthsectorcouncil.org/new-405d-cybersecurity-awareness-resource/) - Just as keeping a balanced diet is important to your overall health, having a balanced cybersecurity approach is essential to protecting your patients and organization from cyber threats! Download the 405(d) Program's newest cybersecurity awareness resource that you can use in your organizations! - [AMA and AHA Joint Resource - Working From Home During the COVID-19 Pandemic](https://healthsectorcouncil.org/ama-aha-wfh-covid-19-resource/) - Responding to a spike in cyber threats that exploit telework technologies during the COVID-19 pandemic, the American Medical Association (AMA) and the American Hospital Association (AHA) have teamed to provide physicians and hospitals with guidance on protecting a remote work environment from cyber criminals. The two leading associations have created a joint cybersecurity resource, Working - [05/11/2020: The 405(d) Post Volume Five](https://healthsectorcouncil.org/05-11-2020-the-405d-post-volume-five/) - [12 Tips for Safe Teleworking from HICP](https://healthsectorcouncil.org/12-tips-teleworking-hicp/) - The healthcare workforce is always evolving and becoming more and more flexible. This flexibility includes the workforce becoming more remote, which in turn means there are more cyber threats to consider. Check out the poster below that details 12 tips you can implement from your organization and from your home to help fight cyberattacks while - [Health Industry Publishes Cybersecurity Best Practices for Protecting Innovation Capital](https://healthsectorcouncil.org/health-industry-publishes-cybersecurity-best-practices-for-protecting-innovation-capital/) - [05/18/2020: Health Industry Publishes Health Industry Cybersecurity Tactical Crisis Response Guide (HIC-TCR)](https://healthsectorcouncil.org/health-industry-publishes-health-industry-cybersecurity-tactical-crisis-response-guide-hic-tcr/) - [05/19/2020: Health IT Security - "HSCC Shares Guide to Protecting Healthcare Trade Secrets, Research"](https://healthsectorcouncil.org/health-it-security-hscc-shares-guide-to-protecting-healthcare-trade-secrets-research/) - The latest Healthcare and Public Health Sector Coordinating Council (HSCC) insights detail ways healthcare entities can better secure its trade secrets and medical research from cyber theft. Health Industry Cybersecurity Protection of Innovation Capital (HIC-PIC) was released on May 14, 20209 and available on our website. - [05/28/2020: Healthcare Info Security Podcast - Russell Koste, CSO of Alexion Pharmaceuticals, on the Protection of Innovation Capital and COVID-19 Research](https://healthsectorcouncil.org/healthcare-info-security-podcast-russell-koste-cso-of-alexion-pharmaceuticals-on-the-protection-of-innovation-capital-and-covid-19-research/) - As cyberthreats to medical research on COVID-19 - and other intellectual property - grow, organizations must take critical steps to prevent the theft of their "innovation capital," says Russell Koste, Chief Security Officer at Alexion Pharmaceuticals, and one of the HSCC CWG Leaders on the Health Industry Cybersecurity Protection of Innovation Capital (HIC-PIC) - [07/16/2020: HSCC Cyber Working Group Q2 2020 Report](https://healthsectorcouncil.org/q2-2020-report/) - [07/21/2020: The 405(d) Post Volume Six](https://healthsectorcouncil.org/the-405d-post-volume-six/) - [09/18/2020: The 405(d) Post Volume Seven](https://healthsectorcouncil.org/the-405d-post-volume-seven/) - [09/22/2020: Health Sector Publishes Guidance on Supply Chain Cybersecurity Risk Management](https://healthsectorcouncil.org/09-20-2020-health-sector-publishes-guidance-on-supply-chain-cybersecurity-risk-management/) - [10/05/2020 Natitional Cybersecurity Awareness Month: If You Connect It, Protect It!](https://healthsectorcouncil.org/10-05-2020-natitional-cybersecurity-awareness-month-if-you-connect-it-protect-it/) - [10/06/2020: HSCC Cyber Working Group Q3 2020 Report](https://healthsectorcouncil.org/q3-2020-report/) - [11/16/2020: Healthcare Supply Chain Security: Updated Guidance](https://healthsectorcouncil.org/11-16-2020-healthcare-supply-chain-security-updated-guidance/) - Vishwas Gadgil of Merck and Ed Gaudet of Censinet Discuss Key Issues, Risk Mitigation. - [11/20/2020: The 405(d) Post Volume Eight](https://healthsectorcouncil.org/11-20-2020-the-405d-post-volume-eight/) - [01/22/2021: National COVID Response and Preparedness Strategy](https://healthsectorcouncil.org/01-22-2021-national-covid-response-and-preparedness-strategy/) - The Health Sector Coordinating Council (HSCC) and Health Information Sharing Analysis Center (H-ISAC) were quoted in response to the recently released National COVID Response Strategy. - [2020 Annual Report](https://healthsectorcouncil.org/2020-annual-report/) - [03/18/2021: The 405(d) Post Volume Eight](https://healthsectorcouncil.org/03-18-2021-the-405d-post-volume-eight/) - [04/06/2021: HSCC Cyber Working Group Q1 2021 Report](https://healthsectorcouncil.org/q1-2021-report/) - [4/19/2021: Health Sector Publishes Telehealth Cybersecurity Recommendations](https://healthsectorcouncil.org/4-19-2021-health-sector-publishes-telehealth-cybersecurity-recommendations/) - [05/20/2021: The 405(d) Post Volume Ten](https://healthsectorcouncil.org/05-20-2021-the-405d-post-volume-ten/) - [07/09/2021: HSCC Cyber Working Group Q2 2021 Report](https://healthsectorcouncil.org/q2-2021-report/) - [07/20/2021: Testimony before HHS' NCVHS Subcommittee Addressing Healthcare Security Challenges](https://healthsectorcouncil.org/07-20-2021-testimony-before-hhs-ncvhs-subcommittee-addressing-healthcare-security-challenges/) - [10/06/2021: HSCC Cyber Working Group Q3 2021 Report](https://healthsectorcouncil.org/q3-2021-report/) - [12/6/2021: HHS 405(d) TG Posts New Website](https://healthsectorcouncil.org/hhs-405d-tg-posts-new-website/) - The 405(d) Program and Task Group is a collaborative effort between industry and the federal government, which aims to raise awareness, provide vetted cybersecurity practices, and move organizations towards consistency in mitigating the current most pertinent cybersecurity threats to the sector. Please explore their website to learn more about our effort and all products and - [2021 Annual Report](https://healthsectorcouncil.org/2021-annual-report/) - [Record Number of Major Health Data Breaches in 2021](https://healthsectorcouncil.org/01-18-2022-record-number-of-major-health-data-breaches-in-2021/) - In the midst of the global COVID-19 pandemic, the federal tally shows that a record number of major health data breaches were reported in the U.S. in 2021, and the overwhelming majority of them involved hacking/IT incidents. - [03/03/2022: Health Industry Publishes Model Contract Language for Medical Technology Cybersecurity](https://healthsectorcouncil.org/03-03-2023-health-industry-publishes-model-contract-language-for-medical-technology-cybersecurity/) - Medical technology companies and health delivery organizations have a new template published March 3 for agreeing on cybersecurity contractual terms and conditions to reduce cost, complexity and time in the contracting process and improve patient safety. - [04/04/2022: HSCC Cyber Working Group Q1 2022 Report](https://healthsectorcouncil.org/q1-2022-report/) - [04-13-2022: HSCC’s Model Contract Language Template Represents a Win-Win Cybersecurity Solution for HDOs and MDMs](https://healthsectorcouncil.org/04-13-2022-hsccs-model-contract-language-template-represents-a-win-win-cybersecurity-solution-for-hdos-and-mdms/) - "This freely available guidance allows HDOs of all sizes to include cybersecurity expectations in a legally binding document. As this template is utilized in agreements between HDOs and MDMs, it will improve the clarity, reduce the time burden, and improve the implemented level of security mitigations, as well as generally remove the confusion associated - [04/29/2022: Health Industry Publishes “Operational Continuity-Cyber Incident (OCCI)” Checklist](https://healthsectorcouncil.org/04-29-2022-occi-checklist-published/) - Today the Health Sector Coordinating Council’s (HSCC) Cybersecurity Working Group (CWG) published the “Operational Continuity-Cyber Incident (OCCI)” checklist. This toolkit is intended to provide a flexible template for operational staff and executive management of healthcare organizations to respond to and recover from an extended enterprise outage due to a serious cyber-attack. Its suggested operational structures and - [05/13/2022: Tips to Improve Medical Device Vulnerability Communications](https://healthsectorcouncil.org/05-13-2022-tips-to-improve-medical-device-vulnerability-communications/) - New Health Sector Coordinating Council guidance aims to help medical device makers improve their communications regarding security vulnerabilities in their products, says Matt Russo, a security leader at Medtronic and a member of the task group that developed the document. The mission of HSCC's recently issued Medtech Vulnerability Communications Toolkit document is to assist medical - [05/18/2022: Denise Anderson testimony to United States Senate Committee on Health, Education, Labor, and Pensions](https://healthsectorcouncil.org/05-18-2022-denise-anderson-testimony-to-united-states-senate-committee-on-health-education-labor-and-pensions/) - Denise Anderson, president and CEO of the Health Information Sharing & Analysis Center, and HSCC Cyber Working Group Executive Committee Member, testifies at U.S. Senate Health, Education, Labor and Pensions Committee. - [05/23/2022: CHIME and WEDI Create “Think Before You Click” Campaign](https://healthsectorcouncil.org/05-23-2022-chime-and-wedi-create-think-before-you-click-campaign/) - CHIME and WEDI have developed the “Think Before You Click” resource to assist consumers who are looking to share their health information with third-party apps. This initiative, which includes a 5-step checklist, is designed to educate and empower consumers to take the appropriate precautions prior to the transmission of health information to third-party apps. The - [HSCC Cyber Working Group 2022 Annual Report](https://healthsectorcouncil.org/hscc-cyber-working-group2022-annual-report/) - [The State of Supply Chain Risk in Healthcare](https://healthsectorcouncil.org/the-state-of-supply-chain-risk-in-healthcare/) - Washington, DC – January 10, 2023 - A new survey shows that more than 400 healthcare organizations face critical challenges in managing supply chain cyber risk across the healthcare industry and significant opportunities to adopt foundational supply chain risk management practices. “The State of Supply Chain Risk in Healthcare” research report, which was conducted by - [Top Free Resources for Improving Healthcare Cybersecurity](https://healthsectorcouncil.org/top-free-resources-for-improving-healthcare-cybersecurity/) - Regardless of size, structure, or budget, providers can leverage free or low-cost industry resources to improve healthcare cybersecurity. December 19, 2022 - The healthcare sector continues to face unprecedented levels of cyberattacks and data breaches. From state-sponsored threat actors to known vulnerabilities and phishing campaigns, the industry is up against a variety of dynamic threats. Luckily, there is no - [National Cyber Security Awareness Month Podcast Series](https://healthsectorcouncil.org/national-cyber-security-awareness-month-podcast-series/) - Congratulations to the many HSCC CWG Task Group Leads for their participation in our series of healthcare cybersecurity podcasts produced in partnership with Outcomes Rocket and its host Saul Marquez, for winning the Power Press Podcast Award. Thanks to all who voted for this award and the additional recognition and awareness our work attracts. Each - [Q3 2022 Progress Report](https://healthsectorcouncil.org/q3-2022-progress-report/) - [Health Industry Cybersecurity-Artificial Intelligence-Machine Learning](https://healthsectorcouncil.org/health-industry-cybersecurity-artificial-intelligence-machine-learning/) - Today the Health Sector Coordinating Council published a new HSCC CWG white paper titled: “Health Industry Cybersecurity-Artificial Intelligence Machine Learning (HIC-AIM)” – an overview and discussion of 9 specific cybersecurity considerations for the implementation of A.I. in a clinical and enterprise environment. Summary Healthcare has continued to evolve from the paper-and-pen world to a digital environment. - [Healthcare Industry And HHS Partner To Align Health System Cybersecurity With NIST Framework](https://healthsectorcouncil.org/hph-sector-cybersecurity-framework-implementation-guide-health-industry-and-hhs-joint-publication/) - Today, the Health Sector Coordinating Council (HSCC) Cybersecurity Working Group and the U.S. Department of Health and Human Services (HHS) jointly released a guide to help the public and private healthcare sectors align their cybersecurity programs with the NIST Cybersecurity Framework (CSF). The Cybersecurity Framework Implementation Guide provides specific steps that health care organizations can - [Examining The Cybersecurity Risks to the Healthcare Sector](https://healthsectorcouncil.org/examining-the-cybersecurity-risks-to-the-healthcare-sector/) - Health Sector Coordinating Council's Executive Director Greg Garcia, on behalf of the HSCC Cybersecurity Working Group, gave testimony to the Senate Homeland Security and Government Affairs Committee, Thursday March 16th, 10am EDT, on the topic: “In Need of a Checkup: Examining the Cybersecurity Risks to the Healthcare Sector.” - [Supply Chain TG & Ponemon Webinar](https://healthsectorcouncil.org/supply-chain-tg-ponemon-webinar/) - "The State of Supply Chain Risk in Healthcare" research report, where Dr. Larry Ponemon (Ponemon Institute) and Ed Gaudet (Censinet & Supply Chain TG Co-Lead) discussed the research and findings. Abstract: A new survey shows that more than 400 healthcare organizations face critical challenges in managing supply chain cyber risk across the healthcare industry and - [HSCC Cybersecurity Training Video Series](https://healthsectorcouncil.org/hscc-cybersecurity-training-video-series/) - This 8-part video training series totaling 47 minutes explains in non-technical language what clinicians and students in the medical profession need to understand about how cyber attacks can affect clinical operations and patient safety, and how to help keep healthcare data, systems and patients safe from cyber threats. Health Sector Coordinating Council Releases Free Cybersecurity - [HSCC Q1 2023 Progress Report](https://healthsectorcouncil.org/hscc-q1-2023-progress-report/) - [Hospital Cyber Resiliency Landscape Analysis (Health Industry and HHS 405(d) Joint Publication)](https://healthsectorcouncil.org/4260-2/) - Health delivery organizations across the United States have faced dramatic increases in cyber-attacks intended to cause disruption to the care continuum. In response to this growing threat, the HHS 405(d) Program conducted this Landscape Analysis, which identifies the vulnerabilities and threats most frequently resulting in damaging attacks against hospitals and assesses the hospitals’ known capabilities - [Hearing on "Preparing for and Responding to Future Public Health Security Threats"](https://healthsectorcouncil.org/preparing-for-and-responding-to-future-public-health-security-threats/) - The Subcommittee on Health of the Committee on Energy and Commerce will held a hearing on Thursday, May 11, 2023 at 10:00 am in 2322 Rayburn House Office Building. The hearing was entitled, "Preparing for and Responding to Future Public Health Security Threats." Erik Decker, Chairman of the Health Sector Coordinating Council's Cyber Working Group - [Testimony - Protecting Critical Infrastructure from Cyberattacks: Examining Expertise of Sector Specific Agencies](https://healthsectorcouncil.org/testimony-protecting-critical-infrastructure-from-cyberattacks-examining-expertise-of-sector-specific-agencies/) - Chairman Griffith, Vice Chair Lesko, Ranking Member Castor, and distinguished members of the Committee, it is an honor to testify before you today on the Department of Health and Human Services’ (HHS) efforts to strengthen the Healthcare and Public Health (HPH) critical infrastructure sector’s preparedness for and response to malign cyber activity.I am grateful - [HealthCareInfoSecurity Webinar on HSCC Guide for Managing Legacy Technology Security](https://healthsectorcouncil.org/healthcareinfosecurity-webinar-on-hscc-guide-for-managing-legacy-technology-security/) - [Health Sector Publishes Privacy and Security Coordination Guide](https://healthsectorcouncil.org/privacy-security-coordination-guide/) - Washington, DC – February 16, 2024 - The Healthcare and Public Health Sector Coordinating Council (HSCC) Cybersecurity Working Group today published a guide for health providers and companies to coordinate privacy and cybersecurity functions for improved overall compliance and operational efficiencies and effectiveness. It is found here: https://healthsectorcouncil.org/privacy-security-coordination/ As cyberattacks and data breaches of private - [Statement about HHS Cyber Performance Goals](https://healthsectorcouncil.org/statement-about-hhs-cyber-performance-goals/) - The Health Sector Coordinating Council (HSCC) Cybersecurity Working Group (CWG) has worked with HHS, CISA and other federal agencies over the past several years to develop leading cybersecurity practices that are provided to all health organizations in the ecosystem. Today’s release of the HPH Cyber Performance Goals (CPGs) is the next iteration of that partnership. - [Reprint Medtech Vulnerability Communications Toolkit (MVCT)](https://healthsectorcouncil.org/reprint-medtech-vulnerability-communications-toolkit-mvct/) - MVCT is a toolkit written to provide specific tools to medical device manufacturers and software developers for creating cybersecurity vulnerability communications related to their products or services. This toolkit focuses on vulnerability communications directed to non-security professionals, including clinicians, patients, users, and other readers not familiar with cybersecurity and connected technologies. It is intended to - [Reprint Health Industry Cybersecurity Protection of Innovation Capital (HIC-PIC) PR](https://healthsectorcouncil.org/reprint-health-industry-cybersecurity-protection-of-innovation-capital-hic-pic/) - The HIC-PIC is a white paper with guidance for how healthcare organizations can protect trade secrets, medical research and other innovation capital from cyber theft. - [Reprint Health Industry Cybersecurity Tactical Crisis Response Guide (HIC-TCR)](https://healthsectorcouncil.org/reprint-health-industry-cybersecurity-tactical-crisis-response-guide-hic-tcr/) - The HIC-TCR is a tactical guide to advise health providers on tactical response activities for managing the cybersecurity threats that can occur during natural or man-made emergencies. - [AHA Testifies to Congress on Healthcare Cybersecurity](https://healthsectorcouncil.org/aha-testifies-to-congress-on-healthcare-cybersecurity/) - On behalf of our nearly 5,000 member hospitals, health systems and other health care organizations, our clinician partners – including more than 270,000 affiliated physicians, 2 million nurses and other caregivers – and the 43,000 health care leaders who belong to our professional membership groups, the AHA thanks the Subcommittee for the opportunity to testify - [Health Care Cybersecurity: Is There a Role for the Anesthesia Professional?](https://healthsectorcouncil.org/health-care-cybersecurity-is-there-a-role-for-the-anesthesia-professional/) - Keeping patients safe during anesthesia care is a multifaceted challenge. The skills and vigilance of the anesthesia professional are necessary, but not sufficient. The ergonomics of the care environment, systems of care, communication between teams and many other factors ultimately impact patient safety. Now, it seems we need to add cybersecurity threats as another dimension - [Authentication: A Health-ISAC Guide for CISOs](https://healthsectorcouncil.org/authentication-a-health-isac-guide-for-cisos/) - MFA. OTP. FIDO. SMS. PKI. All of these acronyms might have you saying OMG, but they are each important to understand when it comes to managing authentication. It’s an anomaly these days when a major breach happens and compromised authentication systems don’t play a role. Multi Factor Authentication (MFA) is critical to stopping attacks — - [EHI Response to ASPR’s 2023-2026 National Health Security Strategy](https://healthsectorcouncil.org/ehi-response-to-asprs-2023-2026-national-health-security-strategy/) - Thank you for the opportunity to respond to the request for information (RFI) to help shape the 2023 – 2026 National Health Security Strategy. The healthcare and public health sector is considered a critical infrastructure sector. As such, it is essential that the industry maintain robust cybersecurity protections. While the majority of the industry - [The Future of Secure Healthcare Systems Podcast](https://healthsectorcouncil.org/outcome/) - The intersection between cybersecurity and healthcare can sometimes be a complicated gray area for people that don’t know much about this topic. In this episode, we talk with Erik Decker, the Chief Information Security Officer at Intermountain Healthcare, a mastermind leader in cybersecurity in the healthcare field. When it comes to the healthcare sector, Erik - [HPH-SCC Blog–National Cyber Security Awareness Month](https://healthsectorcouncil.org/hscc-blog-national-cyber-security-awareness-month/) - [HSCC Cybersecurity Working Group Q3 2023 Progress Report](https://healthsectorcouncil.org/hscc-cybersecurity-working-group-q3-2023-progress-report/) - To: HSCC Joint Cybersecurity Working GroupFrom: Erik Decker, Industry Chair Please see attached the Third Quarter 2023 Report of the HSCC Cybersecurity Working Group. As we head into the 4th quarter of 2023 we begin looking to 2024 on a number of fronts:-Complete and publish in February our Health Industry Cybersecurity Five-Year Strategic Plan and - [HSCC Cybersecurity Working Group Q2 2023 Progress Report](https://healthsectorcouncil.org/hscc-cybersecurity-working-group-q2-2023-progress-report/) - Star-date Q2-2023, Chairman’s Log: Let us reflect on the fact that the HSCC Cybersecurity Working Group published fully 6 resources in the second quarter, and we are on track to have published over 5 years at least 27 cybersecurity best practices and recommendations for the health sector by the end of 2023. That is an - [Cybersecurity for the Clinician Video Training Series](https://healthsectorcouncil.org/clinician-video-confirmation/) - Thank you for your interest in the Cybersecurity for the Clinician Video series. For any questions or comments, we will reply shortly to your requests. If you have requested MP4 files, a staff member will reach out to you via email to provide the download links. - [Updated Health Industry Cybersecurity Information Sharing Best Practices (HIC-ISBP)](https://healthsectorcouncil.org/updated-health-industry-cybersecurity-information-sharing-best-practices-hic-isbp/) - The HIC-ISBP is a best practice guide for how healthcare organizations can set up and manage cyber threat information sharing programs for their enterprise. View and Download - [Health Industry Cybersecurity - Matrix of Information Sharing Organizations (HIC-MISO)](https://healthsectorcouncil.org/hic-miso/) - The HIC-MISO identifies many of the cybersecurity information sharing organizations and their key services, as health organizations are beginning to understand the importance of cybersecurity information sharing and implementing information sharing systems. Footnotes ∗ The HPH-SCC is recognized by the Secretary of Health and Human Services as the critical infrastructure industry partner with the government - [HSCC Cybersecurity Working Group Charter](https://healthsectorcouncil.org/hscc-cybersecurity-working-group-charter/) - Healthcare Sector Coordinating Council Cybersecurity Working Group Charter revised January 2021 - [Health Care Industry Cybersecurity Task Force](https://healthsectorcouncil.org/health-care-industry-cybersecurity-task-force/) - Members of the Task Force The following 21 individuals constitute the membership of the Health Care Industry Cybersecurity Task Force established in March 2016. Task Force Co-Chair Emery Csulak, MS, CISSP, PMP, Chief Information Security Officer, Centers for Medicare and Medicaid Services, U.S. Department of Health and Human Services Task Force Co-Chair Theresa Meadows, MS, - [Health Industry Cybersecurity - Securing Telehealth and Telemedicine (HIC-STAT)](https://healthsectorcouncil.org/securingtelehealth/) - HIC-STAT identifies cyber risks and best practices associated with the use of telehealth and telemedicine, and summarizes the policy and regulatory underpinnings for telehealth/telemedicine cyber risk management. It is targeted for senior executives in healthcare and IT, telehealth service and product companies, and regulators. - [Health Industry Cybersecurity Supply Chain Risk Management Guide (HIC-SCRiM-2023)](https://healthsectorcouncil.org/hic-scrim-v2/) - The HIC-SCRiM is a toolkit for small to mid-sized healthcare institutions to better ensure the security of the products and services they procure through an enterprise supply chain cybersecurity risk management program. - [Health Industry Cybersecurity Tactical Crisis Response Guide (HIC-TCR)](https://healthsectorcouncil.org/hic-tcr/) - The HIC-TCR is a tactical guide to advise health providers on tactical response activities for managing the cybersecurity threats that can occur during an emergency, such as the COVID-19 Pandemic. - [Health Industry Cybersecurity Protection of Innovation Capital (HIC-PIC)](https://healthsectorcouncil.org/hic-pic/) - The HIC-PIC is a white paper with guidance for how healthcare organizations can protect trade secrets, medical research and other innovation capital from cyber theft. - [Health Industry Cybersecurity Information Sharing Best Practices (HIC-ISBP)](https://healthsectorcouncil.org/info-sharing-guide/) - The HIC-ISBP is a best practice guide for how healthcare organizations can set up and manage cyber threat information sharing programs for their enterprise. - [Health-ISAC HSCC Response to CIRCIA RFI Final](https://healthsectorcouncil.org/health-isac-hscc-response-to-circia-rfi-final/) - The Health Information Sharing and Analysis Center (Health-ISAC) and the Healthcare and Public Health Sector Coordinating Council (HSCC) Cybersecurity Working Group appreciate the opportunity to submit comments related to the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). Health-ISAC is a trusted community of critical infrastructure owners and operators within the Healthcare and - [HSCC CWG Comments of NIST SP800](https://healthsectorcouncil.org/hscc-cwg-comments-of-nist-sp800/) - HSCC Cybersecurity letter in response to NIST request for comments on NIST SP 800-66r2 initial public draft, Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide. - [HSCC Comment Letter on CISA Cross-Sector Cybersecurity Performance Goals](https://healthsectorcouncil.org/hscc-comment-letter-on-cisa-cross-sector-cybersecurity-performance-goals-v-2/) - The HSCC Cybersecurity Working Group advises CISA to recognize the many cybersecurity tools and resources developed specifically for the health sector, and that any CISA Common Baseline Cybersecurity Performance Goals should align closely to these health sector resources to minimize confusion in the sector about the preferred frameworks to implement. The letter was developed by - [Operational Continuity - Cyber Incident (OCCI)](https://healthsectorcouncil.org/occi/) - This Operational Continuity Cyber Incident (OCCI) checklist is intended to provide a flexible template for operational staff and executive management to respond to and recover from an extended enterprise outage due to a serious cyber-attack. Its suggested operational structures and tasks can be modified or refined according to an organization’s size, resources, complexity and capabilities. - [Medtech Vulnerability Communications Toolkit (MVCT)](https://healthsectorcouncil.org/medtechvulncomms/) - MVCT is a toolkit written to provide specific tools to medical device manufacturers and software developers for creating cybersecurity vulnerability communications related to their products or services. This toolkit focuses on vulnerability communications directed to non-security professionals, including clinicians, patients, users and other readers not familiar with cybersecurity and connected technologies. It is intended to - [Model Contract-Language for Medtech Cybersecurity (MC2)](https://healthsectorcouncil.org/model-contract-language-for-medtech-cybersecurity-mc2/) - MC2 offers a reference for shared cooperation and coordination between Healthcare Delivery Organizations (HDOs) and Medical Device Manufacturers (MDMs) regarding the security, compliance, management, operation, services, and security of MDM-managed medical devices, solutions, and connections. It is strongly encouraged that all medical device manufacturers, health delivery organizations, and group purchasing organizations closely review this contract - [Health Industry Cybersecurity - Coordinated Privacy Security Partnerships (HIC-CPSP)](https://healthsectorcouncil.org/privacy-security-coordination/) - This resource highlights the ways that enterprise Privacy and Security functions can proactively and cohesively work together through the use of shared executive sponsorship, combined governance, and tabletop exercises, among other coordination techniques. The HIC-CPSP is supplemented with an Executive Summary and Frequently Asked Questions, and the Press Release. - [Artificial Intelligence Machine Learning](https://healthsectorcouncil.org/artificial-intelligence-machine-learning/) - An overview and discussion of 9 specific cybersecurity considerations for the implementation of A.I. in a clinical and enterprise environment. - [Health Industry NIST CSF Implementation Guide](https://healthsectorcouncil.org/health-industry-nist-csf-implementation-guide/) - The HSCC JCWG developed this document in consultation with the SCC and GCC to help Health Care and Public Health sector organizations understand and leverage the NIST Cybersecurity Framework's Informative References in their implementation of sound cybersecurity and cyber risk management programs, address the five Core Function areas of the NIST Cybersecurity Framework to ensure - [Hospital Cyber Landscape Analysis (Joint HSCC/HHS)](https://healthsectorcouncil.org/hospital-cyber-landscape-analysis-joint-hscc-hhs/) - Health delivery organizations across the United States have faced dramatic increases in cyber-attacks intended to cause disruption to the care continuum. In response to this growing threat, the HHS 405(d) Program conducted this Landscape Analysis, which identifies the vulnerabilities and threats most frequently resulting in damaging attacks against hospitals and assesses the hospitals’ known capabilities - [Coordinated Healthcare Incident Response Plan (CHIRP)](https://healthsectorcouncil.org/coordinated-healthcare-incident-response-plan/) - Coordinated Healthcare Incident Response Plan: A preparedness and response template for disruptive cyber incidents involving health systems, hospitals and clinics. Provides guidance for maintaining clinical and business operations as the effects of a cyber attack threaten not only revenue but patient safety. - [Prioritized Recognized Cybersecurity Practices](https://healthsectorcouncil.org/prioritized-recognized-cybersecurity-practices/) - As a component of the four-part health sector cybersecurity initiative including the joint HHS-HSCC Hospital Cyber Resiliency Landscape Analysis, the recently updated publication of the Health Industry Cybersecurity Practices 2023 (HICP 2023), and the Health Industry Cybersecurity Recommendations for Government Policy and Programs this resource recommends to industry and government partners the HICP practices judged - [Managing Legacy Technology Security](https://healthsectorcouncil.org/legacy-tech-security/) - A comprehensive guide to address the management of cyber risk caused by legacy technologies used in healthcare environments. It recommends cybersecurity strategies that both manufacturers and health providers can implement for legacy medical technology as a shared responsibility in the clinical environment and provides insights for designing future devices that are more secure. A brief - [The Healthcare Sector Coordinating Council and the NH-ISAC: Two Sides of the Same Critical Infrastructure Coin](https://healthsectorcouncil.org/the-healthcare-sector-coordinating-council-and-the-nh-isac-two-sides-of-the-same-critical-infrastructure-coin/) - Every stakeholder of the healthcare system and the subsector they represent, including direct patient care, pharmaceuticals, device manufacturers, health IT and supplies, plans and payers, and mass fatality management, is part of an interdependent ecosystem that is facing sophisticated and targeted cybersecurity threats and vulnerabilities that can cascade across the value chain of the healthcare - [Next HSCC Joint Cybersecurity Working Group meeting: April 3-4, 2019, San Diego.](https://healthsectorcouncil.org/next-hscc-joint-cybersecurity-working-group-meeting-april-3-4-2019-san-diego/) - More details to come in 2019. - [Health Sector Coordinating Council publishes Five-Year Health Industry Cybersecurity Strategic Plan (HIC-SP) – 2024-29](https://healthsectorcouncil.org/health-sector-coordinating-council-publishes-five-year-health-industry-cybersecurity-strategic-plan-hic-sp-2024-29/) - Wellness plan recommends implementing enterprise and industry-wide goals by 2029 on the imperative that Cyber Safety is Patient Safety. Los Angeles, February 27, 2024 - The Healthcare and Public Health (HPH) Sector Coordinating Council (HSCC) Cybersecurity Working Group (CWG) today published at the ViVE 2024 Conference the “Health Industry Cybersecurity Strategic Plan” (HIC-SP) – a ## Pages - [HSCC Home](https://healthsectorcouncil.org/) - Join HSCC to collaborate on best practices & resources to safeguard patient data & healthcare systems from cyberattacks. - [Healthcare Sector Coordinating Council Cybersecurity Working Group](https://healthsectorcouncil.org/about/) - Learn about the Healthcare and Public Health Sector Coordinating Council (HSCC) and its Cybersecurity Working Group (CWG) in the healthcare industry. - [Health Sector Coordinating Council Cybersecurity Working Group](https://healthsectorcouncil.org/health-sector-council-cyber-working-group-introduction-2/) - Discover the composition, mission, and priorities of the industry-led advisory council in healthcare cybersecurity. - [Private Sector Voting Members (423)](https://healthsectorcouncil.org/organizational-members/private-sector-voting-members/) - HSCC voting members are leading healthcare organizations shaping the future of healthcare cybersecurity. - [Government (23)](https://healthsectorcouncil.org/organizational-members/government/) - HSCC government members partner with HSCC to improve healthcare cybersecurity across the industry. - [Private Sector Non-Voting Advisors (50)](https://healthsectorcouncil.org/organizational-members/private-sector-non-voting-advisors/) - HSCC non-voting advisors contribute their expertise to HSCC's mission of improving healthcare cybersecurity. - [HSCC Cybersecurity Working Group Executive Committee](https://healthsectorcouncil.org/executive-committee/) - Meet the HSCC Executive Committee members leading the fight for a more secure healthcare industry. - [2025 HSCC Cybersecurity Working Group](https://healthsectorcouncil.org/task-groups/) - HSCC task groups address critical issues in healthcare cybersecurity through collaboration and expertise sharing. - [Sector Mapping and Risk Toolkit (SMART)](https://healthsectorcouncil.org/workflow-maps-request/) - Work-Flow Map Request Form Request Form Requirements Please use the following request form to access the systemic work-flow maps with function identifiers that are otherwise redacted from the examples contained in Appendix A of the SMART toolkit. Due to the sensitive nature of these maps, specific organization names are not included in the maps - [Membership In The Healthcare Sector Coordinating Council Cybersecurity Working Group](https://healthsectorcouncil.org/join/) - Join HSCC to collaborate on best practices, resources, & solutions to address evolving cybersecurity threats in healthcare. - [Cybersecurity Working Group Organizational Members](https://healthsectorcouncil.org/organizational-members/) - HSCC members are committed to protecting healthcare data and systems from cyberattacks. - [Registration Cancelled](https://healthsectorcouncil.org/registration-cancelled/) - [ESPRESSO_CANCELLED] - [Registration Checkout](https://healthsectorcouncil.org/registration-checkout/) - [ESPRESSO_CHECKOUT] - [Transactions](https://healthsectorcouncil.org/transactions/) - [ESPRESSO_TXN_PAGE] - [Thank You](https://healthsectorcouncil.org/thank-you/) - [ESPRESSO_THANK_YOU] - [Forward Path 2025](https://healthsectorcouncil.org/government-partners/forward-path-2025/) - HSCC GARCIA TESTIMONY TO SENATE HEALTH, EDUCATION , LABOR AND PENSIONS (HELP) COMMITTEE: https://healthsectorcouncil.org/government-partners-forward-path-2025-senate-help-testimony/ HSCC STATEMENT ON HEALTHCARE CYBERSECURITY POLICY: https://healthsectorcouncil.org/government-partners-forward-path-2025-cyber-policy-statement 2025 HEALTH INDUSTRY CYBERSECURITY RECOMMENDATIONS FOR GOVERNMENT POLICY AND PROGRAMS: https://healthsectorcouncil.org/government-partners-forward-path-2025-cyber-program-recommendations/ - [Healthcare Cybersecurity Academic Partnership (HCAP) Program](https://healthsectorcouncil.org/academic-partnership/) - View the Healthcare Cybersecurity Academic Partnership Charter. Complete the form to tell us which part(s) of the Program you are interested in: - [Cyber Practices](https://healthsectorcouncil.org/hscc-publications/) - Access free HSCC publications & resources to stay informed and improve your healthcare cybersecurity posture. - [CISA Guidance](https://healthsectorcouncil.org/government-partners/cisa-guidance/) - CISA cybersecurity resources for healthcare: Stopransomware.gov, Healthcare Landing Page, Cyber Security Evaluation Tool, and more. - [Contact Health Sector Council](https://healthsectorcouncil.org/contact/) - Contact HSCC for inquiries, membership, or to join the fight for a more secure healthcare industry. - [Cybersecurity Strategic Plan](https://healthsectorcouncil.org/cyber-strategic-plan/) - The HIC-SP is a call to action for healthcare organizations to implement cybersecurity programs to address cyberattacks. - [“Cybersecurity for the Clinician” Video Training Series](https://healthsectorcouncil.org/cyberclinicianvideos/) - Presented by the Health Sector Coordinating Council Cybersecurity Working Group Video on Demand! For an introductory preview of the first of 8 training videos, go to our HSCC YouTube Channel https://youtu.be/rS0gT6bIiYw. For institutions and companies wanting to download the eLearning-compatible file for use in your enterprise training program, we would appreciate your registering below. With - [Government Partners](https://healthsectorcouncil.org/government-partners/) - HHS CYBER HHS ASPR TRACIE HC3 FDA Breach Portal CISA-HHS Healthcare Cybersecurity Toolkit CISA Alerts & Bulletins Healthcare Landing Page on Stopransomware Cyber Hygiene Services - [Case Studies](https://healthsectorcouncil.org/cyber-strategic-plan/case-studies/) ## Categories - [Press & Releases](https://healthsectorcouncil.org/category/press-releases/) - Press & Releases - Stay updated with HSCC press releases on critical healthcare cybersecurity initiatives, innovations, and industry developments. - [HPH Blog](https://healthsectorcouncil.org/category/hph-blog/) - [Community Contributions](https://healthsectorcouncil.org/category/memberscorner/) - The posts here are only for the members. - [Progress Report](https://healthsectorcouncil.org/category/progress-report/) - HSCC Cyber Working Group Progress reports - [Publication Downloads](https://healthsectorcouncil.org/category/publication-downloads/) - Browse essential healthcare cybersecurity publications and downloads from the Health Sector Council for industry insights and best practices. - [HSCC Publications](https://healthsectorcouncil.org/category/hscc-publications/) ## Tags - [Monitor Threats](https://healthsectorcouncil.org/tag/monitor-threats/) - Discover how to monitor threats in the healthcare sector with insights from the Health Sector Coordinating Council (HSCC). - [Manage Risks](https://healthsectorcouncil.org/tag/manage-risks/) - Discover strategies to manage risks effectively in the healthcare sector with insights from the Health Sector Cooridnating Council (HSCC). - [Secure Medtech](https://healthsectorcouncil.org/tag/secure-medtech/) - Cyber Practices - Secure Medtech - [Respond & Recover](https://healthsectorcouncil.org/tag/respond-recover/) - Explore strategies to respond and recover in healthcare scenarios with insights from the Health Sector Coordinating Council (HSCC). - [Measure Effectiveness](https://healthsectorcouncil.org/tag/measure-effectiveness/) - Learn methods to measure effectiveness in healthcare initiatives with insights from the Health Sector Coordinating Council (HSCC). - [Policy Comments](https://healthsectorcouncil.org/tag/policy-comments/)