HIPAA Tip: Health Sector Coordinating Council Statement on Healthcare Cybersecurity Policy
Understanding the Health Sector Coordinating Council’s Cybersecurity Initiative
The Health Sector Coordinating Council (HSCC) Cybersecurity Working Group (CWG) is an industry-led council of more than 400 healthcare organizations advising the government and health sector on how to protect against and recover from cyber threats to health data and research, systems, manufacturing and patient care. The CWG membership collaboratively develops and publishes freely available healthcare cybersecurity best practices and policy recommendations, produces outreach and communications programs, emphasizing the imperative that Cyber Safety is Patient Safety.
- HSCC CWG: 400+ healthcare organizations advising on cybersecurity
- Goal: Upgrade healthcare cybersecurity from “critical” to “stable” by 2029
- Key principle: Cyber Safety is Patient Safety
- Free resources: Best practices and policy recommendations available
- Focus areas: Technology, governance, C-Suite accountability, workforce training
- Vision: “911 Cyber Civil Defense” capability with early warning and response
The Health Industry Cybersecurity Strategic Plan (HIC-SP)
The Health Industry Cybersecurity Strategic Plan (HIC-SP) is a call to action for organizations throughout the healthcare ecosystem to implement foundational cybersecurity programs that address the operational, technological, and governance challenges posed by significant potential changes to the healthcare industry. HIC-SP was structured to prepare for broad industry trends over the next 5 years with high level cybersecurity goals that can be achieved through the implementation of specific measurable objectives. Success will upgrade the diagnosis of healthcare cybersecurity from “critical” to “stable condition” by 2029.
Healthcare Cybersecurity Vision for 2029
That means a healthcare cybersecurity future state in which:
- Healthcare cybersecurity, both practiced and regulated, is reflexive, evolving, accessible, documented, and implemented
- Secure design and implementation of technology and services across the healthcare ecosystem is a shared and collaborative responsibility
- Leaders in the healthcare C-Suite embrace accountability for cybersecurity as an enterprise risk and a technology imperative
- A cyber safety net promotes cyber equity among under-resourced health organizations across the ecosystem
- Workforce cybersecurity learning and application is an infrastructure wellness continuum
- A “911 Cyber Civil Defense” capability to provide early warning, incident response and recovery is reflexive and always on
Ongoing HIPAA Compliance Support
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.