Health Industry Cybersecurity Practices
Consensus cybersecurity practices for healthcare published under HHS Section 405(d), the recognized 'reasonable practices' safe-harbor reference.
Definition
Health Industry Cybersecurity Practices (HICP) is a publication series produced by the HHS 405(d) Task Group, a public-private collaboration of the Department of Health and Human Services and more than 200 healthcare and cybersecurity organizations. HICP defines voluntary, consensus-based cybersecurity practices scoped to small, medium, and large healthcare organizations. The 2023 edition (HICP 2023) updated the original 10 practice areas and aligned them to the NIST Cybersecurity Framework.What this means in practice
HICP matters legally as well as technically: under Public Law 116-321 (the HITECH Safe Harbor amendment), HHS Office for Civil Rights (OCR) is required to consider whether a covered entity or business associate has, for at least the prior 12 months, adequately demonstrated 'recognized security practices' when calculating HIPAA penalties or audit outcomes. HICP is the most commonly cited recognized-practices framework. For medical device manufacturers selling to hospitals, conformance to HICP, and the ability to provide MDS2 documentation that maps to it, is increasingly a procurement requirement.- •Confusing HICP with the HIPAA Security Rule, HIPAA sets requirements, HICP describes how to meet them.
- •Manufacturers ignoring HICP because it's hospital-facing, your products must enable hospital HICP conformance, particularly around asset management, identity, and vulnerability management.
- •Citing HICP 2018, the current edition is HICP 2023, with updated technical volumes and a separate Cybersecurity Framework Implementation Guide.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsMember-driven nonprofit that operates the trusted sharing community for cyber and physical threat intelligence across the healthcare sector.
HHS's sector-specific list of essential and enhanced cybersecurity goals for healthcare, derived from HICP and the NIST CSF.
U.S. federal law governing the privacy and security of protected health information.
U.S. law that strengthened HIPAA enforcement and introduced breach-notification requirements.
More in Cybersecurity
· Same categoryAn industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.
A standardized form by which device manufacturers disclose security characteristics to healthcare delivery organizations.
A risk-based framework of cybersecurity functions and outcomes published by NIST and widely used to organize MedTech security programs.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
Primary references
3 sources- 1
405(d) Program, HICP 2023VerifiedHHS405d.hhs.gov
- 2
HHS 405(d) ProgramVerifiedHHS405d.hhs.gov
- 3
HSCC - Health Sector Coordinating CouncilVerifiedHSCChealthsectorcouncil.org
Inline markers like [1] jump to the matching reference above.