Healthcare and Public Health Cybersecurity Performance Goals
HHS's sector-specific list of essential and enhanced cybersecurity goals for healthcare, derived from HICP and the NIST CSF.
Definition
The Healthcare and Public Health Cybersecurity Performance Goals are a voluntary set of cybersecurity goals published by HHS (in coordination with CISA) for the Healthcare and Public Health (HPH) critical infrastructure sector. They are organized into Essential Goals (baseline practices every HPH organization should meet) and Enhanced Goals (advanced practices for mature organizations). The CPGs are aligned to the NIST Cybersecurity Framework and derived from HICP 2023, so they form a layered model: NIST CSF → HICP → HPH-CPG, with the CPGs being the most prescriptive and outcome-oriented.What this means in practice
HPH-CPGs are quickly becoming the primary measuring stick for healthcare cybersecurity maturity. HHS has signaled that future rulemaking under the HIPAA Security Rule and conditions of participation for Medicare may incorporate CPG-style requirements. Medical device manufacturers should expect hospital RFPs and procurement reviews to ask explicitly which CPGs your product helps the hospital achieve, particularly around asset inventory, vulnerability management, MFA, and incident response.- •Treating Essential CPGs as the ceiling, they are the floor. Enhanced Goals reflect what mature health systems are already doing.
- •Mapping device features to CPGs in marketing without evidence, hospitals will ask for technical artifacts (MDS2, SBOM, configuration guides) tied to specific CPGs.
- •Ignoring the supply-chain CPGs that flow down to device manufacturers via Business Associate Agreements.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsConsensus cybersecurity practices for healthcare published under HHS Section 405(d), the recognized 'reasonable practices' safe-harbor reference.
Member-driven nonprofit that operates the trusted sharing community for cyber and physical threat intelligence across the healthcare sector.
U.S. federal law governing the privacy and security of protected health information.
An industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.
More in Cybersecurity
· Same categoryA risk-based framework of cybersecurity functions and outcomes published by NIST and widely used to organize MedTech security programs.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Primary references
3 sources- 1
Cross-Sector Cybersecurity Performance GoalsVerifiedCISAcisa.gov
- 2
MDCG Cybersecurity GuidanceVerifiedMDCGhealth.ec.europa.eu
- 3
HSCC - Health Sector Coordinating CouncilVerifiedHSCChealthsectorcouncil.org
Inline markers like [1] jump to the matching reference above.