The HPH Cybersecurity Performance Goals
In January 2024 HHS published the Healthcare and Public Health Sector Cybersecurity Performance Goals, a voluntary set of practices developed with CISA and aligned to the NIST Cybersecurity Framework. They exist because the Security Rule is flexible by design, and the sector asked for a concrete floor. The goals are split into ten essential goals, meant to be the minimum for every organization, and ten enhanced goals for mature programs.
The goals are voluntary, but they are not academic. HHS has stated its intent to build them into future enforcement and incentive programs, and several of the essential goals reappear as explicit requirements in the 2025 Security Rule proposal, including multi-factor authentication, encryption, and vulnerability management.
For a compliance program the practical use is as a control baseline: map each goal to the Security Rule standards it supports and to the 405(d) Health Industry Cybersecurity Practices, then treat the essential goals as the prioritized work list.
Key points
Essential: mitigate known vulnerabilities
Patch or otherwise remediate internet-facing known exploited vulnerabilities on a defined timeline. CISA's Known Exploited Vulnerabilities catalog is the reference list.
Essential: email security and MFA
Phishing-resistant multi-factor authentication for privileged and remote access, and basic email protections including DMARC, SPF and DKIM.
Essential: basic training and unique credentials
Role-based cybersecurity training for the workforce and the elimination of shared or default credentials.
Essential: separate user and privileged accounts, and revoke on departure
Administrative access separated from daily-use accounts, and access removed promptly when people leave or change roles.
Essential: encryption, incident planning and vendor incident reporting
Encrypt sensitive data in transit and at rest, maintain and exercise an incident response plan, and require vendors and suppliers to report incidents.
Enhanced goals
Asset inventory, third-party vulnerability disclosure, network segmentation, centralized logging, configuration management, cybersecurity testing, mitigation of non-internet-facing vulnerabilities, threat intelligence, and vendor cybersecurity requirements.
Common mistakes
Voluntary versus optional
The goals are voluntary in the sense that they are not yet regulation. They describe what regulators, insurers and plaintiffs will regard as reasonable, which is the Security Rule's standard.
CPGs versus HICP
The 405(d) Health Industry Cybersecurity Practices are a longer, practice-level document with small, medium and large organization tracks. The CPGs are a short prioritized list. Use HICP for how, CPGs for what first.
Sector CPGs versus CISA's cross-sector CPGs
CISA publishes cross-sector goals for all critical infrastructure. The HPH goals are the healthcare-specific adaptation and carry HHS's weight.
Sources
; ;
See it in the live data.
Watch CISA and FDA advisories