All healthcare organizations, from small physician offices to large, multidisciplinary practices and medical centers, face cybersecurity threats. Although a cyberattack may create significant HIPAA privacy and security concerns, its consequences can extend well beyond the unauthorized disclosure of protected health information.
A cybersecurity incident may disrupt access to electronic health records, diagnostic information, prescription systems, network-connected medical devices, and other technologies essential to patient care. These disruptions can delay treatment, contribute to clinical errors, and place patient safety at risk.
In response to growing cybersecurity threats, Congress enacted the Cybersecurity Act of 2015.
Section 405(d) directed the U.S. Department of Health and Human Services (HHS) to work with healthcare industry stakeholders to develop voluntary, consensus-based cybersecurity practices. This public-private partnership became known as the 405(d) Program.
One of the program's principal resources is Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP). First published in December 2018 and updated on April 17, 2023, HICP provides practical guidance that healthcare organizations of different sizes can use to reduce cybersecurity risks and protect patient care.
The 2023 publication includes a main document and separate technical volumes for small organizations and medium-to-large organizations.
The 2023 HICP identifies five primary threats facing the healthcare and public health sector.
Cybersecurity is an organization-wide responsibility, not one limited to information technology or security personnel. Just as safe patient care depends on collaboration among a multidisciplinary team, protecting healthcare's digital environment requires the participation of the entire workforce. Patient safety now extends beyond clinical care to safeguarding the technologies, networks, and databases essential to the accurate and uninterrupted delivery of healthcare.
Healthcare practices should tailor their safeguards to their size, resources, systems, and level of risk. The following checklist is based on the ten cybersecurity practice areas presented in HICP.
Helpful resources include:
Cybersecurity cannot be treated as a one-time compliance project. Healthcare practices should regularly assess their risks, educate their workforce, maintain secure and recoverable backups, control access to sensitive systems, and prepare to continue caring for patients during a cyber incident. By incorporating cybersecurity into everyday patient-safety and practice-management activities, healthcare organizations can reduce the likelihood that a digital threat will become a clinical emergency.
The HICP identifies five major threats: social engineering, ransomware, loss or theft of equipment or data, insider-related data loss, and attacks against network-connected medical devices.
Cyber incidents can disrupt access to electronic health records, prescription systems, diagnostic information, and medical devices, potentially affecting patient care and safety.
Healthcare organizations should conduct and document cybersecurity risk assessments regularly and whenever systems or operations materially change.
Multifactor authentication requires users to provide more than one form of verification before gaining access to a system, helping reduce the risk of unauthorized access.
Yes. Healthcare organizations of all sizes face cybersecurity threats and should implement safeguards appropriate to their size, resources, systems, and level of risk.
Looking for more guidance? Explore our risk management resources. If you're not currently insured with OUM, fill out our online form to receive a free, no-obligation quote.
References
1. U.S. Department of Health and Human Services. (n.d.). HHS Cyber Gateway resource library. https://hhscyber.hhs.gov/resources.html
2. U.S. Department of Health and Human Services, 405(d) Program. (2023). Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP 2023 Edition). https://405d.hhs.gov/Documents/HICP-Main-508.pdf
3. U.S. Department of Health and Human Services. (2023, April 17). Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients (HICP 2023 Edition). https://hhscyber.hhs.gov/cornerstone-hicp.html
4. U.S. Department of Health and Human Services, 405(d) Program. (2023). Technical Volume 1: Cybersecurity Practices for Small Healthcare Organizations. https://405d.hhs.gov/Documents/tech-vol1-508.pdf
5. U.S. Department of Health and Human Services, 405(d) Program. (2023). Technical Volume 2: Cybersecurity Practices for Medium and Large Healthcare Organizations. https://405d.hhs.gov/Documents/tech-vol2-508.pdf
6. U.S. Department of Health and Human Services. (n.d.). HHS Cyber Gateway. https://hhscyber.hhs.gov/
7. U.S. Department of Health and Human Services, Office for Civil Rights. (2026, August 12). Guidance on risk analysis requirements under the HIPAA Security Rule. https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html
8. U.S. Department of Health and Human Services, Office for Civil Rights. (2022, October 25). October 2022 OCR cybersecurity newsletter: Incident response. https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity-newsletter-october-2022/index.html
9. U.S. Department of Health and Human Services, Office for Civil Rights. (2021, September 20). Fact sheet: Ransomware and HIPAA. https://www.hhs.gov/hipaa/for-professionals/security/guidance/cybersecurity/ransomware-fact-sheet/index.html
10. U.S. Food and Drug Administration. (2026, July 06). Cybersecurity. https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity
11. Cybersecurity and Infrastructure Security Agency. (n.d.). #StopRansomware guide. U.S. Department of Homeland Security. https://www.cisa.gov/stopransomware/ransomware-guide
12. Cybersecurity and Infrastructure Security Agency. (n.d.). Cybersecurity performance goals. U.S. Department of Homeland Security. https://www.cisa.gov/cybersecurity-performance-goals-cpgs
Disclaimer: “OUM” and “OUM Chiropractor Program” do not refer to a legal entity or insurance company but to a program or symbol of a program underwritten, insured, and administered by ProAssurance Insurance Company of America. The information contained on the OUM Chiropractor Blog does not establish a standard of care, nor does it constitute legal advice. The information is for general informational purposes only. We encourage all blog visitors to consult with their personal attorneys for legal advice, as specific legal requirements may vary from state to state. Links or references to organizations, websites, or other information is for reference use only and do not constitute the rendering of legal, financial, or other professional advice or recommendations. In the event any of the information presented conflicts with the terms and conditions of any policy of insurance offered by ProAssurance Insurance Company of America, the terms and conditions of the actual policy will apply. All information contained on the blog is subject to change.