HHS Cybersecurity Task Force Report
The HHS Cybersecurity Task Force has issued a report with six high-level imperatives, recommendations, and action steps intended to strengthen cybersecurity in the healthcare sector. The task force was created in the Cybersecurity Act of 2015 to address the challenges the healthcare industry faces when securing and protecting itself against cybersecurity incidents, whether intentional or unintentional.
The report (announcement contains link to report) says the sector experienced more cyber incidents resulting in data breaches in 2015 than any other critical infrastructure sector. In addition, it says, the growing prevalence and sophistication of ransomware attacks continues to raise the stakes for attack victims. For the health industry, it says, the harms extend beyond privacy or information loss because patient safety can be at stake.
The six high-level imperatives used by the task force to organize its recommendations and action items are:
- define and streamline leadership, governance, and expectations for healthcare industry cybersecurity;
- increase the security and resilience of medical devices and health IT;
- develop the healthcare workforce capacity necessary to prioritize and ensure cybersecurity awareness and technical capabilities;
- increase healthcare industry readiness through improved cybersecurity awareness and education;
- identify mechanisms to protect research and development efforts and intellectual property from attacks or exposure; and
- improve information sharing of industry threats, weaknesses, and mitigations.
“Each recommendation includes one or more action items for implementing the recommendation,” the report says. “Some recommendations and action items identify a single entity that the task force recommends be responsible for the recommendation and action items, while other recommendations and action items recommend multiple entities be responsible for implementation. The successful implementation of these recommendations will require adequate resources and coordination across the public and private sector. Once implemented, the recommendations will increase security for the healthcare industry’s organizations, networks, and associated medical devices.”
Four attorneys from O’Melveny & Myers write in an online blog post that although many of the recommendations are directed to federal regulators, the report suggests several practical steps that companies can take to mitigate both business and legal cyber risks. “The report provides a number of timely recommendations to help the public and private sectors work together to better manage risk prevention and more effectively respond to the broad and rapidly evolving array of cyber threats,” they write. “Overall, the report largely avoids recommending prescriptive regulation, suggesting instead, at least in the first instance, incentives, public-private partnerships, education, and awareness programs, and the sharing of best practices. However, if these voluntary and collaborative approaches fail to provide adequate security, it is likely that federal and state regulators will adopt more specific and prescriptive measures. As the cyber threat to the healthcare industry continues to grow, companies across the industry should carefully review the report and, as appropriate, implement its recommendations.”