Asset Inventory
Identify known, shadow, and unmanaged assets. Reconcile endpoint, server, network, medical-device, cloud, virtual, and application inventories enough to support vulnerability and incident response.
HHS currently organizes its Healthcare and Public Health sector Cybersecurity Performance Goals into 10 Essential Goals and 10 Enhanced Goals. The goals are voluntary, healthcare-specific practices intended to help organizations prioritize high-impact safeguards, strengthen cyber preparedness and resilience, and protect patient information and safety.
Use the HHS CPGs as a prioritization and implementation framework—not as a substitute for HIPAA, other law, contractual requirements, accreditation obligations, or organization-specific risk analysis.
HHS describes the HPH CPGs as a voluntary subset of cybersecurity practices for healthcare organizations, especially healthcare delivery organizations. They are built from CISA's CPG approach and informed by Healthcare Industry Cybersecurity Practices (HICP), the NIST Cybersecurity Framework, sector implementation guidance, and observed hospital attack patterns.
The current HHS Cyber Gateway maps each goal to related HICP practices/sub-practices, NIST controls, CISA CPG identifiers, and supporting resources. Use those mappings to connect a healthcare-specific priority to the broader control and assurance systems your organization already operates.
Do not treat the list as a one-time checklist. A useful implementation records scope, owner, evidence source, coverage, exceptions, operational metric, validation method, and improvement work for each goal.
| Essential CPG | Implementation evidence to make it reviewable |
|---|---|
| Mitigate Known Vulnerabilities | External exposure inventory, vulnerability scans, KEV-aware prioritization, remediation SLAs, exception records, closure validation. |
| Email Security | Mail-security configuration, anti-spoofing controls, phishing telemetry, malicious-message response, user reporting and training evidence. |
| Multifactor Authentication | MFA coverage by identity/system, internet-facing access inventory, privileged access coverage, technical exceptions and compensating controls. |
| Basic Cybersecurity Training | Role-based training assignments, completion, exercises, phishing/reporting behaviour, remediation for repeat risk patterns. |
| Strong Encryption | Data-flow inventory, approved cryptographic standards, TLS/service configuration, key/certificate lifecycle evidence and exceptions. |
| Revoke Departing Workforce Credentials | HR-to-identity workflow, termination timing, privileged/service access checks, sampled deprovisioning evidence and orphan-account detection. |
| Basic Incident Planning and Preparedness | Incident plan, clinical downtime procedures, contact tree, tabletop evidence, recovery priorities, backups and after-action remediation. |
| Unique Credentials | Account inventory, shared-account restrictions, device/service identity design, credential rotation, lateral-movement detection and exceptions. |
| Separate User and Privileged Accounts | Administrative account inventory, separate privileged identities, PAM/JIT where used, admin workstation controls and access reviews. |
| Vendor/Supplier Cybersecurity Requirements | Risk-tiering, contract requirements, supplier evidence, critical-dependency inventory, notification/escalation paths and exit contingencies. |
Identify known, shadow, and unmanaged assets. Reconcile endpoint, server, network, medical-device, cloud, virtual, and application inventories enough to support vulnerability and incident response.
Define how suppliers disclose vulnerabilities, how the organization receives and triages them, which products are affected, and how remediation status reaches technical and clinical owners.
Require usable incident-notification paths and test how supplier incidents move into internal incident command, privacy/legal review, clinical continuity, communications, and recovery.
Use penetration testing, attack simulation, and vulnerability-disclosure processes to discover realistic weaknesses and feed findings into owned remediation.
Turn testing findings into prioritized remediation with accountable owners, timelines, risk acceptance, verification, and reporting.
Connect endpoint/network telemetry, threat intelligence, detection logic, triage, containment, and clinical/operational context for the threats most relevant to the environment.
Separate mission-critical assets and constrain lateral movement. Validate boundaries between clinical systems, medical devices, administrative networks, guest/IoT zones, management planes, and recovery infrastructure.
Collect the telemetry needed for visibility and response, with source ownership, time synchronization, retention, parser health, access controls, alert dependencies, and outage monitoring.
Maintain and exercise relevant scenarios consistently across security, IT, clinical operations, leadership, privacy, legal, communications, vendors, and recovery teams.
Define secure baselines, approved deviations, change control, drift detection, validation and restoration paths for infrastructure, endpoints, network devices, applications and supported clinical technology.
For each CPG, define the denominator before reporting a percentage. “MFA 95% complete” is weak evidence unless the organization can state which identities and systems belong in scope, what is excluded, how exceptions are approved, and how the coverage figure is generated.
Useful evidence often combines configuration exports, identity and asset inventories, vulnerability records, SIEM/EDR telemetry, ticket/change records, supplier evidence, exercise results, audit findings, restoration tests, and clinical downtime observations. Preserve enough context to reproduce the metric and explain changes over time.
Use trend measures such as vulnerable internet-facing assets, MFA exception age, termination-to-access-revocation time, patch/remediation lead time, critical supplier evidence age, restore-test success, segmentation validation findings, log-source health, and incident-exercise actions closed on time.
Inventory internet-facing services, privileged/remote identities, critical clinical workflows, recovery dependencies, critical vendors, known vulnerabilities, incident contacts, and current evidence for all essential CPGs.
Prioritize exploitable exposure, missing MFA, stale privileged access, unsupported internet services, backup/restore weaknesses, email attack paths, and gaps that could cause patient-care disruption.
Exercise ransomware and supplier-outage scenarios, test restoration, verify credential revocation, validate segmentation, sample logging coverage, and confirm findings reach owners with deadlines.
Expand asset discovery, supplier disclosure/reporting, testing, threat detection, centralized logging, configuration management, segmentation, and recurring scenario exercises using risk and incident data to set priorities.
Healthcare security cannot be implemented as a generic corporate IT checklist. MFA, segmentation, endpoint controls, patching, account changes, and incident containment can affect EHR access, imaging, laboratory, pharmacy, medical devices, nurse-call systems, identity workflows, interfaces, and downtime procedures.
Bring clinical engineering, biomedical/device owners, application teams, nursing/clinical operations, emergency management, facilities, privacy, legal, communications, and major vendors into design and exercises where their workflows are affected. Define what must continue manually, what can be isolated safely, what must be restored first, and who has authority to make those decisions during an incident.
HHS's 2026 RISC 2.0 cybersecurity module reinforces this operational use: ASPR states that it evaluates facility cyber posture against both NIST CSF 2.0 and the HHS CPGs. Treat the CPGs as a living resilience baseline tied to actual facility and health-system risk.
The current HHS Cyber Gateway calls the CPGs voluntary. Separately, HHS OCR issued a proposed HIPAA Security Rule update in December 2024. A proposed rule is not the same thing as a final binding rule. Organizations should track the current regulatory status and continue satisfying applicable existing requirements while using the CPGs as a cybersecurity prioritization framework.
Follow the next implementation topic without returning to search.
Build repeatable security operations and evidence practices
Continue readingPrioritize and remediate vulnerabilities using asset, exploitation, exposure, ownership, exception, and verification evidence
Continue readingGovern identity lifecycle, authentication, federation, privileged access, service identities, access review, and identity evidence
Continue readingUse the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.