---
title: "HICP Definition &amp; Meaning | MedTech Terms"
description: "Consensus cybersecurity practices for healthcare published under HHS Section 405(d), the recognized 'reasonable practices' safe-harbor reference."
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/hicp#term",
        "name": "Health Industry Cybersecurity Practices",
        "alternateName": [
          "HICP",
          "HHS 405(d) HICP"
        ],
        "description": "Health Industry Cybersecurity Practices (HICP) is a publication series produced by the HHS 405(d) Task Group, a public-private collaboration of the Department of Health and Human Services and more than 200 healthcare and cybersecurity organizations. HICP defines voluntary, consensus-based cybersecurity practices scoped to small, medium, and large healthcare organizations. The 2023 edition (HICP 2023) updated the original 10 practice areas and aligned them to the NIST Cybersecurity Framework.",
        "url": "https://medtechterms.com/terms/hicp",
        "termCode": "hicp",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/hicp#article",
        "headline": "HICP, Health Industry Cybersecurity Practices",
        "description": "Consensus cybersecurity practices for healthcare published under HHS Section 405(d), the recognized 'reasonable practices' safe-harbor reference.",
        "url": "https://medtechterms.com/terms/hicp",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/hicp"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/hicp#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "Health Industry Cybersecurity Practices, HICP, HHS 405(d) HICP, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-06-20",
        "dateModified": "2026-06-20",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "405(d) Program, HICP 2023",
            "url": "https://405d.hhs.gov/Documents/HICP-Main-508.pdf",
            "publisher": {
              "@type": "Organization",
              "name": "HHS"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "HHS 405(d) Program",
            "url": "https://405d.hhs.gov/",
            "publisher": {
              "@type": "Organization",
              "name": "HHS"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "HSCC - Health Sector Coordinating Council",
            "url": "https://healthsectorcouncil.org/",
            "publisher": {
              "@type": "Organization",
              "name": "HSCC"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hph-cpg#term",
            "name": "Healthcare and Public Health Cybersecurity Performance Goals",
            "alternateName": "HPH-CPG",
            "url": "https://medtechterms.com/terms/hph-cpg"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hipaa#term",
            "name": "HIPAA",
            "alternateName": "HIPAA",
            "url": "https://medtechterms.com/terms/hipaa"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hitech-act#term",
            "name": "HITECH Act",
            "alternateName": "HITECH",
            "url": "https://medtechterms.com/terms/hitech-act"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/nist-csf#term",
            "name": "NIST Cybersecurity Framework",
            "alternateName": "NIST CSF",
            "url": "https://medtechterms.com/terms/nist-csf"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/h-isac#term",
            "name": "Health Information Sharing and Analysis Center",
            "alternateName": "H-ISAC",
            "url": "https://medtechterms.com/terms/h-isac"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hscc-jsp#term",
            "name": "HSCC Joint Security Plan",
            "alternateName": "HSCC JSP",
            "url": "https://medtechterms.com/terms/hscc-jsp"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/mds2#term",
            "name": "Manufacturer Disclosure Statement for Medical Device Security",
            "alternateName": "MDS2",
            "url": "https://medtechterms.com/terms/mds2"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "Health Industry Cybersecurity Practices",
            "item": "https://medtechterms.com/terms/hicp"
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  Health Industry Cybersecurity Practices

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)[Startup Lifecycle](/ecosystems/startup-lifecycle)HICP 

# Health Industry Cybersecurity Practices

Consensus cybersecurity practices for healthcare published under HHS Section 405(d), the recognized 'reasonable practices' safe-harbor reference.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed June 20, 2026 

## Definition

Health Industry Cybersecurity Practices (HICP) is a publication series produced by the HHS 405(d) Task Group, a public-private collaboration of the Department of Health and Human Services and more than 200 healthcare and cybersecurity organizations. HICP defines voluntary, consensus-based cybersecurity practices scoped to small, medium, and large healthcare organizations. The 2023 edition (HICP 2023) updated the original 10 practice areas and aligned them to the  [NIST Cybersecurity Framework](/terms/nist-csf). 

What the regulation says

HHS 405(d) HICP is explicitly named in HHS guidance on 'recognized security practices' for purposes of  [HIPAA](/terms/hipaa) enforcement discretion under PL 116-321. CISA's Healthcare and Public Health Sector Cybersecurity Performance Goals ( [HPH-CPG](/terms/hph-cpg)) are derived from and aligned to HICP practices. 

## What this means in practice

HICP matters legally as well as technically: under Public Law 116-321 (the  [HITECH](/terms/hitech-act) [Safe](/terms/safe-note) Harbor amendment), HHS Office for Civil Rights (OCR) is required to consider whether a covered entity or business associate has, for at least the prior 12 months, adequately demonstrated 'recognized security practices' when calculating  [HIPAA](/terms/hipaa) penalties or audit outcomes. HICP is the most commonly cited recognized-practices framework. For medical device manufacturers selling to hospitals, conformance to HICP, and the ability to provide  [MDS2](/terms/mds2) documentation that maps to it, is increasingly a procurement requirement. 

Common pitfalls

-   • Confusing HICP with the HIPAA Security Rule, HIPAA sets requirements, HICP describes how to meet them. 
-   • Manufacturers ignoring HICP because it's hospital-facing, your products must enable hospital HICP conformance, particularly around asset management, identity, and vulnerability management. 
-   • Citing HICP 2018, the current edition is HICP 2023, with updated technical volumes and a separate Cybersecurity Framework Implementation Guide. 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

Health Information Sharing and Analysis Center(H-ISAC) 

Member-driven nonprofit that operates the trusted sharing community for cyber and physical threat intelligence across the healthcare sector.





](/terms/h-isac)[

Cybersecurity

Healthcare and Public Health Cybersecurity Performance Goals(HPH-CPG) 

HHS's sector-specific list of essential and enhanced cybersecurity goals for healthcare, derived from HICP and the NIST CSF.





](/terms/hph-cpg)[

Cybersecurity

HIPAA(HIPAA) 

U.S. federal law governing the privacy and security of protected health information.





](/terms/hipaa)[

Cybersecurity

HITECH Act(HITECH) 

U.S. law that strengthened HIPAA enforcement and introduced breach-notification requirements.





](/terms/hitech-act)

### More in Cybersecurity

· Same category 

[

Cybersecurity

HSCC Joint Security Plan(HSCC JSP) 

An industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.





](/terms/hscc-jsp)[

Cybersecurity

Manufacturer Disclosure Statement for Medical Device Security(MDS2) 

A standardized form by which device manufacturers disclose security characteristics to healthcare delivery organizations.





](/terms/mds2)[

Cybersecurity

NIST Cybersecurity Framework(NIST CSF) 

A risk-based framework of cybersecurity functions and outcomes published by NIST and widely used to organize MedTech security programs.





](/terms/nist-csf)[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (2)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)
-   [Startup Lifecycle](/ecosystems/startup-lifecycle)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

HHS· 2 HSCC· 1 

1.  [1 
    
    405(d) Program, HICP 2023
    
    Verified 
    
    HHS · 405d.hhs.gov 
    
    
    
    ](https://405d.hhs.gov/Documents/HICP-Main-508.pdf)
2.  [2 
    
    HHS 405(d) Program
    
    Verified 
    
    HHS · 405d.hhs.gov 
    
    
    
    ](https://405d.hhs.gov/)
3.  [3 
    
    HSCC - Health Sector Coordinating Council
    
    Verified 
    
    HSCC · healthsectorcouncil.org 
    
    
    
    ](https://healthsectorcouncil.org/)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Acronym

HICP

Sources

3

Updated

6/20/2026

[Compare with another term](/compare?a=hicp)

Learn in 60 seconds

Card Lesson Quiz

Consensus cybersecurity practices for healthcare published under HHS Section 405(d), the recognized 'reasonable practices' safe-harbor reference.

-   · HICP is the most commonly cited recognized-practices framework. 
-   · For medical device manufacturers selling to hospitals, conformance to HICP, and the ability to provide MDS2 documentation that maps to it, is increasingly a procurement requirement. 
-   · HICP defines voluntary, consensus-based cybersecurity practices scoped to small, medium, and large healthcare organizations. 

Remember this

Watch out: Confusing HICP with the HIPAA Security Rule, HIPAA sets requirements, HICP describes how to meet them.

Related terms

-   [Healthcare and Public Health Cybersecurity Performance Goals(HPH-CPG) ](/terms/hph-cpg)
-   [HIPAA(HIPAA) ](/terms/hipaa)
-   [HITECH Act(HITECH) ](/terms/hitech-act)
-   [NIST Cybersecurity Framework(NIST CSF) ](/terms/nist-csf)
-   [Health Information Sharing and Analysis Center(H-ISAC) ](/terms/h-isac)
-   [HSCC Joint Security Plan(HSCC JSP) ](/terms/hscc-jsp)
-   [Manufacturer Disclosure Statement for Medical Device Security(MDS2) ](/terms/mds2)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [NIST IR 8473, Cybersecurity Framework Profile for HPH(NIST IR 8473) ](/terms/nist-cswp-35)
-   [IMDRF Principles and Practices for Medical Device Cybersecurity ](/terms/imdrf-cyber-principles)
-   [Secure Product Development Framework(SPDF) ](/terms/spdf)
-   [Legacy Device Cybersecurity ](/terms/legacy-device-cyber)
-   [Secure Software Development Framework(SSDF) ](/terms/ssdf)
-   [HITRUST CSF(HITRUST) ](/terms/hitrust)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)