Reviewed September 30, 2026HHS Cyber Gateway current

HHS Healthcare Cybersecurity Performance Goals: turn 20 voluntary CPGs into an evidence-backed resilience program.

HHS currently organizes its Healthcare and Public Health sector Cybersecurity Performance Goals into 10 Essential Goals and 10 Enhanced Goals. The goals are voluntary, healthcare-specific practices intended to help organizations prioritize high-impact safeguards, strengthen cyber preparedness and resilience, and protect patient information and safety.

Use the HHS CPGs as a prioritization and implementation framework—not as a substitute for HIPAA, other law, contractual requirements, accreditation obligations, or organization-specific risk analysis.

Current HHS framework

Start with high-impact safeguards, then mature the operating system around them.

HHS describes the HPH CPGs as a voluntary subset of cybersecurity practices for healthcare organizations, especially healthcare delivery organizations. They are built from CISA's CPG approach and informed by Healthcare Industry Cybersecurity Practices (HICP), the NIST Cybersecurity Framework, sector implementation guidance, and observed hospital attack patterns.

The current HHS Cyber Gateway maps each goal to related HICP practices/sub-practices, NIST controls, CISA CPG identifiers, and supporting resources. Use those mappings to connect a healthcare-specific priority to the broader control and assurance systems your organization already operates.

Do not treat the list as a one-time checklist. A useful implementation records scope, owner, evidence source, coverage, exceptions, operational metric, validation method, and improvement work for each goal.

10 Essential Goals

Establish the floor of safeguards HHS prioritizes for common healthcare attack paths.

Essential CPGImplementation evidence to make it reviewable
Mitigate Known VulnerabilitiesExternal exposure inventory, vulnerability scans, KEV-aware prioritization, remediation SLAs, exception records, closure validation.
Email SecurityMail-security configuration, anti-spoofing controls, phishing telemetry, malicious-message response, user reporting and training evidence.
Multifactor AuthenticationMFA coverage by identity/system, internet-facing access inventory, privileged access coverage, technical exceptions and compensating controls.
Basic Cybersecurity TrainingRole-based training assignments, completion, exercises, phishing/reporting behaviour, remediation for repeat risk patterns.
Strong EncryptionData-flow inventory, approved cryptographic standards, TLS/service configuration, key/certificate lifecycle evidence and exceptions.
Revoke Departing Workforce CredentialsHR-to-identity workflow, termination timing, privileged/service access checks, sampled deprovisioning evidence and orphan-account detection.
Basic Incident Planning and PreparednessIncident plan, clinical downtime procedures, contact tree, tabletop evidence, recovery priorities, backups and after-action remediation.
Unique CredentialsAccount inventory, shared-account restrictions, device/service identity design, credential rotation, lateral-movement detection and exceptions.
Separate User and Privileged AccountsAdministrative account inventory, separate privileged identities, PAM/JIT where used, admin workstation controls and access reviews.
Vendor/Supplier Cybersecurity RequirementsRisk-tiering, contract requirements, supplier evidence, critical-dependency inventory, notification/escalation paths and exit contingencies.
10 Enhanced Goals

Build deeper visibility, containment, testing, and repeatable response.

Asset Inventory

Identify known, shadow, and unmanaged assets. Reconcile endpoint, server, network, medical-device, cloud, virtual, and application inventories enough to support vulnerability and incident response.

Third Party Vulnerability Disclosure

Define how suppliers disclose vulnerabilities, how the organization receives and triages them, which products are affected, and how remediation status reaches technical and clinical owners.

Third Party Incident Reporting

Require usable incident-notification paths and test how supplier incidents move into internal incident command, privacy/legal review, clinical continuity, communications, and recovery.

Cybersecurity Testing

Use penetration testing, attack simulation, and vulnerability-disclosure processes to discover realistic weaknesses and feed findings into owned remediation.

Cybersecurity Mitigation

Turn testing findings into prioritized remediation with accountable owners, timelines, risk acceptance, verification, and reporting.

Detect and Respond to Relevant Threats and TTPs

Connect endpoint/network telemetry, threat intelligence, detection logic, triage, containment, and clinical/operational context for the threats most relevant to the environment.

Network Segmentation

Separate mission-critical assets and constrain lateral movement. Validate boundaries between clinical systems, medical devices, administrative networks, guest/IoT zones, management planes, and recovery infrastructure.

Centralized Log Collection

Collect the telemetry needed for visibility and response, with source ownership, time synchronization, retention, parser health, access controls, alert dependencies, and outage monitoring.

Centralized Incident Planning and Preparedness

Maintain and exercise relevant scenarios consistently across security, IT, clinical operations, leadership, privacy, legal, communications, vendors, and recovery teams.

Configuration Management

Define secure baselines, approved deviations, change control, drift detection, validation and restoration paths for infrastructure, endpoints, network devices, applications and supported clinical technology.

Evidence model

Measure coverage and operational performance—not policy existence.

For each CPG, define the denominator before reporting a percentage. “MFA 95% complete” is weak evidence unless the organization can state which identities and systems belong in scope, what is excluded, how exceptions are approved, and how the coverage figure is generated.

Useful evidence often combines configuration exports, identity and asset inventories, vulnerability records, SIEM/EDR telemetry, ticket/change records, supplier evidence, exercise results, audit findings, restoration tests, and clinical downtime observations. Preserve enough context to reproduce the metric and explain changes over time.

Use trend measures such as vulnerable internet-facing assets, MFA exception age, termination-to-access-revocation time, patch/remediation lead time, critical supplier evidence age, restore-test success, segmentation validation findings, log-source health, and incident-exercise actions closed on time.

Implementation roadmap

Prioritize patient-impacting exposure and recovery dependencies first.

0–30 days: establish scope

Inventory internet-facing services, privileged/remote identities, critical clinical workflows, recovery dependencies, critical vendors, known vulnerabilities, incident contacts, and current evidence for all essential CPGs.

31–60 days: close high-consequence gaps

Prioritize exploitable exposure, missing MFA, stale privileged access, unsupported internet services, backup/restore weaknesses, email attack paths, and gaps that could cause patient-care disruption.

61–90 days: validate the system

Exercise ransomware and supplier-outage scenarios, test restoration, verify credential revocation, validate segmentation, sample logging coverage, and confirm findings reach owners with deadlines.

Ongoing: mature enhanced CPGs

Expand asset discovery, supplier disclosure/reporting, testing, threat detection, centralized logging, configuration management, segmentation, and recurring scenario exercises using risk and incident data to set priorities.

Clinical resilience

Cyber controls must survive healthcare's availability and patient-safety constraints.

Healthcare security cannot be implemented as a generic corporate IT checklist. MFA, segmentation, endpoint controls, patching, account changes, and incident containment can affect EHR access, imaging, laboratory, pharmacy, medical devices, nurse-call systems, identity workflows, interfaces, and downtime procedures.

Bring clinical engineering, biomedical/device owners, application teams, nursing/clinical operations, emergency management, facilities, privacy, legal, communications, and major vendors into design and exercises where their workflows are affected. Define what must continue manually, what can be isolated safely, what must be restored first, and who has authority to make those decisions during an incident.

HHS's 2026 RISC 2.0 cybersecurity module reinforces this operational use: ASPR states that it evaluates facility cyber posture against both NIST CSF 2.0 and the HHS CPGs. Treat the CPGs as a living resilience baseline tied to actual facility and health-system risk.

Regulatory boundary

Voluntary CPGs and HIPAA requirements are related, but they are not interchangeable.

The current HHS Cyber Gateway calls the CPGs voluntary. Separately, HHS OCR issued a proposed HIPAA Security Rule update in December 2024. A proposed rule is not the same thing as a final binding rule. Organizations should track the current regulatory status and continue satisfying applicable existing requirements while using the CPGs as a cybersecurity prioritization framework.

Continue learning

Related guides after HHS Healthcare Cybersecurity Performance Goals

Follow the next implementation topic without returning to search.

Put this guide to work

Turn HHS Healthcare Cybersecurity Performance Goals: 20 CPGs | Zeph Tech into a decision-ready next step.

Use the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.