---
title: "NIST IR 8473 Definition &amp; Meaning | MedTech Terms"
description: "NIST's Cybersecurity Framework profile tailored to the Healthcare and Public Health sector, translates NIST CSF outcomes into HPH-specific subcategories and…"
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/nist-cswp-35#term",
        "name": "NIST IR 8473, Cybersecurity Framework Profile for HPH",
        "alternateName": [
          "NIST IR 8473",
          "HPH CSF Profile",
          "Healthcare CSF Profile"
        ],
        "description": "NIST Interagency Report 8473 is a Cybersecurity Framework (CSF) Profile for the Healthcare and Public Health Sector, developed by NIST in coordination with the HHS 405(d) Task Group and HSCC. The profile takes the NIST CSF's Functions (Govern, Identify, Protect, Detect, Respond, Recover) and tailors the subcategories and informative references to the HPH sector, explicitly mapping each subcategory to HIPAA Security Rule citations, HICP practices, IEC 80001-1, and the HPH Cybersecurity Performance Goals. It is the authoritative bridge between generic NIST CSF guidance and healthcare-specific implementation expectations.",
        "url": "https://medtechterms.com/terms/nist-cswp-35",
        "termCode": "nist-cswp-35",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/nist-cswp-35#article",
        "headline": "NIST IR 8473, NIST IR 8473, Cybersecurity Framework Profile for HPH",
        "description": "NIST's Cybersecurity Framework profile tailored to the Healthcare and Public Health sector, translates NIST CSF outcomes into HPH-specific subcategories and references.",
        "url": "https://medtechterms.com/terms/nist-cswp-35",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/nist-cswp-35"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/nist-cswp-35#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "NIST IR 8473, Cybersecurity Framework Profile for HPH, NIST IR 8473, HPH CSF Profile, Healthcare CSF Profile, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-06-20",
        "dateModified": "2026-06-20",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "NIST Cybersecurity Framework 2.0",
            "url": "https://www.nist.gov/cyberframework",
            "publisher": {
              "@type": "Organization",
              "name": "NIST"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "MDCG Cybersecurity Guidance",
            "url": "https://health.ec.europa.eu/medical-devices-sector/new-regulations/guidance-mdcg-endorsed-documents-and-other-guidance_en",
            "publisher": {
              "@type": "Organization",
              "name": "MDCG"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "HSCC - Health Sector Coordinating Council",
            "url": "https://healthsectorcouncil.org/",
            "publisher": {
              "@type": "Organization",
              "name": "HSCC"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/nist-csf#term",
            "name": "NIST Cybersecurity Framework",
            "alternateName": "NIST CSF",
            "url": "https://medtechterms.com/terms/nist-csf"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hicp#term",
            "name": "Health Industry Cybersecurity Practices",
            "alternateName": "HICP",
            "url": "https://medtechterms.com/terms/hicp"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hph-cpg#term",
            "name": "Healthcare and Public Health Cybersecurity Performance Goals",
            "alternateName": "HPH-CPG",
            "url": "https://medtechterms.com/terms/hph-cpg"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hipaa#term",
            "name": "HIPAA",
            "alternateName": "HIPAA",
            "url": "https://medtechterms.com/terms/hipaa"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/iec-80001#term",
            "name": "IEC 80001-1",
            "url": "https://medtechterms.com/terms/iec-80001"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hscc-jsp#term",
            "name": "HSCC Joint Security Plan",
            "alternateName": "HSCC JSP",
            "url": "https://medtechterms.com/terms/hscc-jsp"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "NIST IR 8473, Cybersecurity Framework Profile for HPH",
            "item": "https://medtechterms.com/terms/nist-cswp-35"
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  NIST IR 8473, Cybersecurity Framework Profile for HPH

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)NIST IR 8473 

# NIST IR 8473, Cybersecurity Framework Profile for HPH

NIST's Cybersecurity Framework profile tailored to the Healthcare and Public Health sector, translates NIST CSF outcomes into HPH-specific subcategories and references.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed June 20, 2026 

## Definition

NIST Interagency Report 8473 is a Cybersecurity Framework (CSF) Profile for the Healthcare and Public Health Sector, developed by NIST in coordination with the HHS 405(d) Task Group and HSCC. The profile takes the  [NIST CSF](/terms/nist-csf)'s Functions (Govern, Identify, Protect, Detect, Respond, Recover) and tailors the subcategories and informative references to the HPH sector, explicitly mapping each subcategory to  [HIPAA](/terms/hipaa) Security Rule citations,  [HICP](/terms/hicp) practices,  [IEC 80001-1](/terms/iec-80001), and the  [HPH Cybersecurity Performance Goals](/terms/hph-cpg). It is the authoritative bridge between generic NIST CSF guidance and healthcare-specific implementation expectations. 

What the regulation says

Published by NIST in coordination with HHS. Not itself binding but referenced by HHS as the recommended approach for HPH organizations to operationalize the  [NIST CSF](/terms/nist-csf) and connect it to  [HIPAA](/terms/hipaa) and  [HICP](/terms/hicp). 

## What this means in practice

For medical device manufacturers, IR 8473 is the document that maps your security architecture to the language hospitals and HHS use. Procurement teams increasingly ask which  [NIST CSF](/terms/nist-csf) subcategories your product supports; IR 8473's HPH-tailored profile is the right reference to answer. It also makes the relationship between  [HIPAA](/terms/hipaa),  [HICP](/terms/hicp), and CPGs explicit, which removes a lot of duplicate evidence work. 

Common pitfalls

-   • Using the generic NIST CSF instead of the HPH profile, you miss the HIPAA, HICP, and IEC 80001-1 mappings. 
-   • Treating the profile as static, NIST updates CSF profiles as CSF itself evolves (CSF 2.0 introduced the Govern function in 2024). 
-   • Mapping product features to high-level Functions only; procurement maturity demands subcategory-level evidence. 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

Health Industry Cybersecurity Practices(HICP) 

Consensus cybersecurity practices for healthcare published under HHS Section 405(d), the recognized 'reasonable practices' safe-harbor reference.





](/terms/hicp)[

Cybersecurity

Healthcare and Public Health Cybersecurity Performance Goals(HPH-CPG) 

HHS's sector-specific list of essential and enhanced cybersecurity goals for healthcare, derived from HICP and the NIST CSF.





](/terms/hph-cpg)[

Cybersecurity

HIPAA(HIPAA) 

U.S. federal law governing the privacy and security of protected health information.





](/terms/hipaa)[

Cybersecurity

HSCC Joint Security Plan(HSCC JSP) 

An industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.





](/terms/hscc-jsp)

### More in Cybersecurity

· Same category 

[

Cybersecurity

IEC 80001-1

International standard for risk management of IT networks that incorporate medical devices.





](/terms/iec-80001)[

Cybersecurity

NIST Cybersecurity Framework(NIST CSF) 

A risk-based framework of cybersecurity functions and outcomes published by NIST and widely used to organize MedTech security programs.





](/terms/nist-csf)[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)[

Cybersecurity

AAMI TIR57

AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.





](/terms/aami-tir57)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (1)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

NIST· 1 MDCG· 1 HSCC· 1 

1.  [1 
    
    NIST Cybersecurity Framework 2.0
    
    Verified 
    
    NIST · nist.gov 
    
    
    
    ](https://www.nist.gov/cyberframework)
2.  [2 
    
    MDCG Cybersecurity Guidance
    
    Verified 
    
    MDCG · health.ec.europa.eu 
    
    
    
    ](https://health.ec.europa.eu/medical-devices-sector/new-regulations/guidance-mdcg-endorsed-documents-and-other-guidance_en)
3.  [3 
    
    HSCC - Health Sector Coordinating Council
    
    Verified 
    
    HSCC · healthsectorcouncil.org 
    
    
    
    ](https://healthsectorcouncil.org/)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Acronym

NIST IR 8473

Sources

3

Updated

6/20/2026

[Compare with another term](/compare?a=nist-cswp-35)

Learn in 60 seconds

Card Lesson Quiz

NIST's Cybersecurity Framework profile tailored to the Healthcare and Public Health sector, translates NIST CSF outcomes into HPH-specific subcategories and references.

-   · For medical device manufacturers, IR 8473 is the document that maps your security architecture to the language hospitals and HHS use. 
-   · Procurement teams increasingly ask which NIST CSF subcategories your product supports; IR 8473's HPH-tailored profile is the right reference to answer. 
-   · It also makes the relationship between HIPAA, HICP, and CPGs explicit, which removes a lot of duplicate evidence work. 

Remember this

Watch out: Using the generic NIST CSF instead of the HPH profile, you miss the HIPAA, HICP, and IEC 80001-1 mappings.

Related terms

-   [NIST Cybersecurity Framework(NIST CSF) ](/terms/nist-csf)
-   [Health Industry Cybersecurity Practices(HICP) ](/terms/hicp)
-   [Healthcare and Public Health Cybersecurity Performance Goals(HPH-CPG) ](/terms/hph-cpg)
-   [HIPAA(HIPAA) ](/terms/hipaa)
-   [IEC 80001-1 ](/terms/iec-80001)
-   [HSCC Joint Security Plan(HSCC JSP) ](/terms/hscc-jsp)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [Secure Software Development Framework(SSDF) ](/terms/ssdf)
-   [Health Information Sharing and Analysis Center(H-ISAC) ](/terms/h-isac)
-   [HITRUST CSF(HITRUST) ](/terms/hitrust)
-   [IMDRF Principles and Practices for Medical Device Cybersecurity ](/terms/imdrf-cyber-principles)
-   [MITRE D3FEND(D3FEND) ](/terms/mitre-d3fend)
-   [Secure Product Development Framework(SPDF) ](/terms/spdf)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)