Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Health Sector Coordinating Council Statement on Healthcare Cybersecurity Policy

Understanding the Health Sector Coordinating Council’s Cybersecurity Initiative

The Health Sector Coordinating Council (HSCC) Cybersecurity Working Group (CWG) is an industry-led council of more than 400 healthcare organizations advising the government and health sector on how to protect against and recover from cyber threats to health data and research, systems, manufacturing and patient care. The CWG membership collaboratively develops and publishes freely available healthcare cybersecurity best practices and policy recommendations, produces outreach and communications programs, emphasizing the imperative that Cyber Safety is Patient Safety.

TL;DR – HSCC Healthcare Cybersecurity Strategic Plan:

  • HSCC CWG: 400+ healthcare organizations advising on cybersecurity
  • Goal: Upgrade healthcare cybersecurity from “critical” to “stable” by 2029
  • Key principle: Cyber Safety is Patient Safety
  • Free resources: Best practices and policy recommendations available
  • Focus areas: Technology, governance, C-Suite accountability, workforce training
  • Vision: “911 Cyber Civil Defense” capability with early warning and response

The Health Industry Cybersecurity Strategic Plan (HIC-SP)

The Health Industry Cybersecurity Strategic Plan (HIC-SP) is a call to action for organizations throughout the healthcare ecosystem to implement foundational cybersecurity programs that address the operational, technological, and governance challenges posed by significant potential changes to the healthcare industry. HIC-SP was structured to prepare for broad industry trends over the next 5 years with high level cybersecurity goals that can be achieved through the implementation of specific measurable objectives. Success will upgrade the diagnosis of healthcare cybersecurity from “critical” to “stable condition” by 2029.

Healthcare Cybersecurity Vision for 2029

That means a healthcare cybersecurity future state in which:

  • Healthcare cybersecurity, both practiced and regulated, is reflexive, evolving, accessible, documented, and implemented
  • Secure design and implementation of technology and services across the healthcare ecosystem is a shared and collaborative responsibility
  • Leaders in the healthcare C-Suite embrace accountability for cybersecurity as an enterprise risk and a technology imperative
  • A cyber safety net promotes cyber equity among under-resourced health organizations across the ecosystem
  • Workforce cybersecurity learning and application is an infrastructure wellness continuum
  • A “911 Cyber Civil Defense” capability to provide early warning, incident response and recovery is reflexive and always on

Ongoing HIPAA Compliance Support

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.