---
title: "HPH-CPG Definition &amp; Meaning | MedTech Terms"
description: "HHS's sector-specific list of essential and enhanced cybersecurity goals for healthcare, derived from HICP and the NIST CSF."
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/hph-cpg#term",
        "name": "Healthcare and Public Health Cybersecurity Performance Goals",
        "alternateName": [
          "HPH-CPG",
          "HPH Cybersecurity Performance Goals",
          "HHS CPGs"
        ],
        "description": "The Healthcare and Public Health Cybersecurity Performance Goals are a voluntary set of cybersecurity goals published by HHS (in coordination with CISA) for the Healthcare and Public Health (HPH) critical infrastructure sector. They are organized into Essential Goals (baseline practices every HPH organization should meet) and Enhanced Goals (advanced practices for mature organizations). The CPGs are aligned to the NIST Cybersecurity Framework and derived from HICP 2023, so they form a layered model: NIST CSF → HICP → HPH-CPG, with the CPGs being the most prescriptive and outcome-oriented.",
        "url": "https://medtechterms.com/terms/hph-cpg",
        "termCode": "hph-cpg",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/hph-cpg#article",
        "headline": "HPH-CPG, Healthcare and Public Health Cybersecurity Performance Goals",
        "description": "HHS's sector-specific list of essential and enhanced cybersecurity goals for healthcare, derived from HICP and the NIST CSF.",
        "url": "https://medtechterms.com/terms/hph-cpg",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/hph-cpg"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/hph-cpg#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "Healthcare and Public Health Cybersecurity Performance Goals, HPH-CPG, HPH Cybersecurity Performance Goals, HHS CPGs, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-06-20",
        "dateModified": "2026-06-20",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "Cross-Sector Cybersecurity Performance Goals",
            "url": "https://www.cisa.gov/cross-sector-cybersecurity-performance-goals",
            "publisher": {
              "@type": "Organization",
              "name": "CISA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "MDCG Cybersecurity Guidance",
            "url": "https://health.ec.europa.eu/medical-devices-sector/new-regulations/guidance-mdcg-endorsed-documents-and-other-guidance_en",
            "publisher": {
              "@type": "Organization",
              "name": "MDCG"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "HSCC - Health Sector Coordinating Council",
            "url": "https://healthsectorcouncil.org/",
            "publisher": {
              "@type": "Organization",
              "name": "HSCC"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hicp#term",
            "name": "Health Industry Cybersecurity Practices",
            "alternateName": "HICP",
            "url": "https://medtechterms.com/terms/hicp"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/nist-csf#term",
            "name": "NIST Cybersecurity Framework",
            "alternateName": "NIST CSF",
            "url": "https://medtechterms.com/terms/nist-csf"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hipaa#term",
            "name": "HIPAA",
            "alternateName": "HIPAA",
            "url": "https://medtechterms.com/terms/hipaa"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hscc-jsp#term",
            "name": "HSCC Joint Security Plan",
            "alternateName": "HSCC JSP",
            "url": "https://medtechterms.com/terms/hscc-jsp"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/h-isac#term",
            "name": "Health Information Sharing and Analysis Center",
            "alternateName": "H-ISAC",
            "url": "https://medtechterms.com/terms/h-isac"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "Healthcare and Public Health Cybersecurity Performance Goals",
            "item": "https://medtechterms.com/terms/hph-cpg"
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  Healthcare and Public Health Cybersecurity Performance Goals

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)HPH-CPG 

# Healthcare and Public Health Cybersecurity Performance Goals

HHS's sector-specific list of essential and enhanced cybersecurity goals for healthcare, derived from HICP and the NIST CSF.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed June 20, 2026 

## Definition

The Healthcare and Public Health Cybersecurity Performance Goals are a voluntary set of cybersecurity goals published by HHS (in coordination with CISA) for the Healthcare and Public Health (HPH) critical infrastructure sector. They are organized into Essential Goals (baseline practices every HPH organization should meet) and Enhanced Goals (advanced practices for mature organizations). The CPGs are aligned to the  [NIST Cybersecurity Framework](/terms/nist-csf) and derived from  [HICP](/terms/hicp) 2023, so they form a layered model: NIST CSF → HICP → HPH-CPG, with the CPGs being the most prescriptive and outcome-oriented. 

What the regulation says

Published by HHS in January 2024 as voluntary goals, with explicit signal that they will inform future  [HIPAA](/terms/hipaa) Security Rule rulemaking. CISA includes HPH-CPGs in its Cross-Sector Cybersecurity Performance Goals program for critical infrastructure. 

## What this means in practice

HPH-CPGs are quickly becoming the primary measuring stick for healthcare cybersecurity maturity. HHS has signaled that future rulemaking under the  [HIPAA](/terms/hipaa) Security Rule and conditions of participation for Medicare may incorporate CPG-style requirements. Medical device manufacturers should expect hospital RFPs and procurement reviews to ask explicitly which CPGs your product helps the hospital achieve, particularly around asset inventory, vulnerability management, MFA, and incident response. 

Common pitfalls

-   • Treating Essential CPGs as the ceiling, they are the floor. Enhanced Goals reflect what mature health systems are already doing. 
-   • Mapping device features to CPGs in marketing without evidence, hospitals will ask for technical artifacts (MDS2, SBOM, configuration guides) tied to specific CPGs. 
-   • Ignoring the supply-chain CPGs that flow down to device manufacturers via Business Associate Agreements. 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

Health Industry Cybersecurity Practices(HICP) 

Consensus cybersecurity practices for healthcare published under HHS Section 405(d), the recognized 'reasonable practices' safe-harbor reference.





](/terms/hicp)[

Cybersecurity

Health Information Sharing and Analysis Center(H-ISAC) 

Member-driven nonprofit that operates the trusted sharing community for cyber and physical threat intelligence across the healthcare sector.





](/terms/h-isac)[

Cybersecurity

HIPAA(HIPAA) 

U.S. federal law governing the privacy and security of protected health information.





](/terms/hipaa)[

Cybersecurity

HSCC Joint Security Plan(HSCC JSP) 

An industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.





](/terms/hscc-jsp)

### More in Cybersecurity

· Same category 

[

Cybersecurity

NIST Cybersecurity Framework(NIST CSF) 

A risk-based framework of cybersecurity functions and outcomes published by NIST and widely used to organize MedTech security programs.





](/terms/nist-csf)[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)[

Cybersecurity

AAMI TIR57

AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.





](/terms/aami-tir57)[

Cybersecurity

AAMI TIR97(TIR97) 

AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.





](/terms/aami-tir97)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (1)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

CISA· 1 MDCG· 1 HSCC· 1 

1.  [1 
    
    Cross-Sector Cybersecurity Performance Goals
    
    Verified 
    
    CISA · cisa.gov 
    
    
    
    ](https://www.cisa.gov/cross-sector-cybersecurity-performance-goals)
2.  [2 
    
    MDCG Cybersecurity Guidance
    
    Verified 
    
    MDCG · health.ec.europa.eu 
    
    
    
    ](https://health.ec.europa.eu/medical-devices-sector/new-regulations/guidance-mdcg-endorsed-documents-and-other-guidance_en)
3.  [3 
    
    HSCC - Health Sector Coordinating Council
    
    Verified 
    
    HSCC · healthsectorcouncil.org 
    
    
    
    ](https://healthsectorcouncil.org/)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Acronym

HPH-CPG

Sources

3

Updated

6/20/2026

[Compare with another term](/compare?a=hph-cpg)

Learn in 60 seconds

Card Lesson Quiz

HHS's sector-specific list of essential and enhanced cybersecurity goals for healthcare, derived from HICP and the NIST CSF.

-   · HPH-CPGs are quickly becoming the primary measuring stick for healthcare cybersecurity maturity. 
-   · HHS has signaled that future rulemaking under the HIPAA Security Rule and conditions of participation for Medicare may incorporate CPG-style requirements. 
-   · They are organized into Essential Goals (baseline practices every HPH organization should meet) and Enhanced Goals (advanced practices for mature organizations). 

Remember this

Watch out: Treating Essential CPGs as the ceiling, they are the floor. Enhanced Goals reflect what mature health systems are already doing.

Related terms

-   [Health Industry Cybersecurity Practices(HICP) ](/terms/hicp)
-   [NIST Cybersecurity Framework(NIST CSF) ](/terms/nist-csf)
-   [HIPAA(HIPAA) ](/terms/hipaa)
-   [HSCC Joint Security Plan(HSCC JSP) ](/terms/hscc-jsp)
-   [Health Information Sharing and Analysis Center(H-ISAC) ](/terms/h-isac)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [NIST IR 8473, Cybersecurity Framework Profile for HPH(NIST IR 8473) ](/terms/nist-cswp-35)
-   [CISA Known Exploited Vulnerabilities Catalog(KEV) ](/terms/kev)
-   [IMDRF Principles and Practices for Medical Device Cybersecurity ](/terms/imdrf-cyber-principles)
-   [Legacy Device Cybersecurity ](/terms/legacy-device-cyber)
-   [Secure Product Development Framework(SPDF) ](/terms/spdf)
-   [Secure Software Development Framework(SSDF) ](/terms/ssdf)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)