OUM Chiropractor Insights

Cybersecurity Checklist for Healthcare Practices

Oct 1, 2026, 6:59:59 AM / by OUM Risk Management Specialist

cyberCybersecurity is a patient safety, operational, and risk management responsibility for every healthcare organization. Implementing strong cybersecurity practices can help healthcare organizations reduce the risk of cyberattacks, protect patient information, maintain access to critical systems, and preserve continuity of care.

All healthcare organizations, from small physician offices to large, multidisciplinary practices and medical centers, face cybersecurity threats. Although a cyberattack may create significant HIPAA privacy and security concerns, its consequences can extend well beyond the unauthorized disclosure of protected health information.

A cybersecurity incident may disrupt access to electronic health records, diagnostic information, prescription systems, network-connected medical devices, and other technologies essential to patient care. These disruptions can delay treatment, contribute to clinical errors, and place patient safety at risk.

Key Takeaways

  • Cybersecurity incidents can impact patient safety as well as data security.
  • HHS developed the 405(d) Program to help healthcare organizations reduce cybersecurity risks.
  • The HICP identifies five major cybersecurity threats facing healthcare organizations.
  • Cybersecurity requires participation from the entire workforce, not just IT personnel.
  • Regular risk assessments, workforce training, access controls, backups, and incident response planning are critical safeguards.

What is the HHS 405(d) Program?

In response to growing cybersecurity threats, Congress enacted the Cybersecurity Act of 2015.
Section 405(d) directed the U.S. Department of Health and Human Services (HHS) to work with healthcare industry stakeholders to develop voluntary, consensus-based cybersecurity practices. This public-private partnership became known as the 405(d) Program.

One of the program's principal resources is Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP). First published in December 2018 and updated on April 17, 2023, HICP provides practical guidance that healthcare organizations of different sizes can use to reduce cybersecurity risks and protect patient care.

The 2023 publication includes a main document and separate technical volumes for small organizations and medium-to-large organizations.

What are the biggest cybersecurity threats facing healthcare organizations?

The 2023 HICP identifies five primary threats facing the healthcare and public health sector.

  1. Social Engineering: The use of deceptive communications, such as phishing emails, fraudulent text messages, or impersonation, to persuade someone to disclose information, transfer money, reveal login credentials, or open a malicious attachment or link.
  2. Ransomware: Malicious software or unauthorized activity that encrypts data, disables systems, or otherwise prevents an organization from accessing its information until a ransom is demanded. Paying a ransom does not guarantee that data or systems will be restored.
  3. Loss or Theft of Equipment or Data: The loss or theft of laptops, smartphones, portable drives, paper records, or other equipment containing sensitive information may expose patient data and provide unauthorized access to organizational systems.
  4. Insider, Accidental, or Malicious Data Loss: Employees, contractors, vendors, or other authorized users may unintentionally disclose information or deliberately steal, alter, destroy, or misuse data.
  5. Attacks Against Network-Connected Medical Devices: Attackers may exploit vulnerabilities in connected medical devices or the systems supporting them. A compromised device or network can disrupt clinical operations, impair device availability, and threaten patient safety.

Why is cybersecurity a patient safety responsibility?

Cybersecurity is an organization-wide responsibility, not one limited to information technology or security personnel. Just as safe patient care depends on collaboration among a multidisciplinary team, protecting healthcare's digital environment requires the participation of the entire workforce. Patient safety now extends beyond clinical care to safeguarding the technologies, networks, and databases essential to the accurate and uninterrupted delivery of healthcare.

Cybersecurity Checklist for Healthcare Practices

Healthcare practices should tailor their safeguards to their size, resources, systems, and level of risk. The following checklist is based on the ten cybersecurity practice areas presented in HICP.

Leadership and Planning

  • Assign responsibility for cybersecurity oversight to a specific individual or team.
  • Conduct and document a cybersecurity risk assessment regularly and whenever systems or operations materially change.
  • Maintain written cybersecurity policies and review them at least annually.
  • Include cybersecurity risks in the practice's patient-safety and emergency-preparedness programs.
  • Require vendors and business associates to meet appropriate security requirements.
  • Confirm that cyber-liability insurance provides coverage appropriate to the practice's risks.

Workforce and Email Security

  • Train employees upon hire and periodically thereafter to recognize phishing, social engineering, suspicious links, and fraudulent requests.
  • Conduct simulated phishing exercises when appropriate.
  • Establish a simple process for reporting suspicious messages and cybersecurity incidents.
  • Verify unusual requests for payments, patient records, passwords, or account changes through a separate communication method.
  • Prohibit sharing passwords or login credentials.

Access Management

  • Require multifactor authentication for email, remote access, administrative accounts, electronic health records, and other critical systems whenever available.
  • Provide each workforce member with a unique user account.
  • Apply the principle of least privilege so users receive only the access necessary for their work.
  • Disable accounts promptly when employees or contractors leave the organization.
  • Review user access periodically and remove unnecessary permissions.
  • Require strong passwords and prohibit reuse of organizational passwords on personal accounts.

Devices, Software, and Networks

  • Maintain a current inventory of computers, mobile devices, servers, software, and network-connected medical devices.
  • Install security updates and patches promptly.
  • Use supported operating systems and replace unsupported software and equipment.
  • Install and maintain endpoint protection on computers and servers.
  • Secure wireless networks and provide a separate network for patients and visitors.
  • Encrypt laptops, mobile devices, portable media, and sensitive data where appropriate.
  • Restrict or prohibit the use of unauthorized USB drives, software, and personal devices.

Backups and Incident Response

  • Back up electronic health records and other critical information regularly.
  • Maintain protected backups that are separate from the primary network.
  • Test backup restoration periodically rather than assuming backups will work.
  • Develop a written incident-response plan identifying whom to contact and what actions to take.
  • Maintain current contact information for leadership, IT support, legal counsel, insurance carriers, vendors, law enforcement, and regulatory authorities.
  • Develop procedures for continuing patient care when electronic systems are unavailable.
  • Conduct periodic downtime and cybersecurity-response exercises.
  • Preserve logs and other evidence following a suspected incident.
  • Review and update safeguards after an incident or near miss.

What cybersecurity resources are available for healthcare practices?

Helpful resources include:

What is the risk management takeaway for healthcare practices?

Cybersecurity cannot be treated as a one-time compliance project. Healthcare practices should regularly assess their risks, educate their workforce, maintain secure and recoverable backups, control access to sensitive systems, and prepare to continue caring for patients during a cyber incident. By incorporating cybersecurity into everyday patient-safety and practice-management activities, healthcare organizations can reduce the likelihood that a digital threat will become a clinical emergency.

 

FAQs

What is the biggest cybersecurity threat facing healthcare organizations?

The HICP identifies five major threats: social engineering, ransomware, loss or theft of equipment or data, insider-related data loss, and attacks against network-connected medical devices.

Why is cybersecurity considered a patient safety issue?

Cyber incidents can disrupt access to electronic health records, prescription systems, diagnostic information, and medical devices, potentially affecting patient care and safety.

How often should healthcare organizations conduct cybersecurity risk assessments?

Healthcare organizations should conduct and document cybersecurity risk assessments regularly and whenever systems or operations materially change.

What is multifactor authentication and why is it important?

Multifactor authentication requires users to provide more than one form of verification before gaining access to a system, helping reduce the risk of unauthorized access.

Should small healthcare practices be concerned about cybersecurity?

Yes. Healthcare organizations of all sizes face cybersecurity threats and should implement safeguards appropriate to their size, resources, systems, and level of risk.

 

Looking for more guidance? Explore our risk management resources. If you're not currently insured with OUM, fill out our online form to receive a free, no-obligation quote.  

 


References
1.    U.S. Department of Health and Human Services. (n.d.). HHS Cyber Gateway resource library. https://hhscyber.hhs.gov/resources.html

2.    U.S. Department of Health and Human Services, 405(d) Program. (2023). Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP 2023 Edition). https://405d.hhs.gov/Documents/HICP-Main-508.pdf

3.    U.S. Department of Health and Human Services. (2023, April 17). Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP 2023 Edition). https://hhscyber.hhs.gov/cornerstone-hicp.html

4.    U.S. Department of Health and Human Services, 405(d) Program. (2023). Technical Volume 1: Cybersecurity Practices for Small Healthcare Organizations. https://405d.hhs.gov/Documents/tech-vol1-508.pdf

5.    U.S. Department of Health and Human Services, 405(d) Program. (2023). Technical Volume 2: Cybersecurity Practices for Medium and Large Healthcare Organizations. https://405d.hhs.gov/Documents/tech-vol2-508.pdf

6.    U.S. Department of Health and Human Services. (n.d.). HHS Cyber Gateway. https://hhscyber.hhs.gov/

7.    U.S. Department of Health and Human Services, Office for Civil Rights. (2026, August 12). Guidance on risk analysis requirements under the HIPAA Security Rule. https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html

8.    U.S. Department of Health and Human Services, Office for Civil Rights. (2022, October 25). October 2022 OCR cybersecurity newsletter: Incident response. https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity-newsletter-october-2022/index.html

9.    U.S. Department of Health and Human Services, Office for Civil Rights. (2021, September 20). Fact sheet: Ransomware and HIPAA. https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity/ransomware-fact-sheet/index.html

10.    U.S. Food and Drug Administration. (2026, July 06). Cybersecurity. https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity

11.    Cybersecurity and Infrastructure Security Agency. (n.d.). #StopRansomware guide. U.S. Department of Homeland Security. https://www.cisa.gov/stopransomware/ransomware-guide

12.    Cybersecurity and Infrastructure Security Agency. (n.d.). Cybersecurity performance goals. U.S. Department of Homeland Security. https://www.cisa.gov/cybersecurity-performance-goals-cpgs

 


 

Disclaimer: “OUM” and “OUM Chiropractor Program” do not refer to a legal entity or insurance company but to a program or symbol of a program underwritten, insured, and administered by ProAssurance Insurance Company of America. The information contained on the OUM Chiropractor Blog does not establish a standard of care, nor does it constitute legal advice. The information is for general informational purposes only. We encourage all blog visitors to consult with their personal attorneys for legal advice, as specific legal requirements may vary from state to state. Links or references to organizations, websites, or other information is for reference use only and do not constitute the rendering of legal, financial, or other professional advice or recommendations. In the event any of the information presented conflicts with the terms and conditions of any policy of insurance offered by ProAssurance Insurance Company of America, the terms and conditions of the actual policy will apply. All information contained on the blog is subject to change.

Tags: Practice Management