The Health Sector Coordinating Council public-private partnership and Department of Health and Human Services today released a guide to help health care organizations align their cybersecurity practices with the National Institute for Standards and Technology’s Cybersecurity Framework to better protect the health care sector. 

“This guide represents the collective technical cyber expertise of both the health care sector and government through HHS and NIST,” said John Riggi, AHA’s national advisor for cybersecurity and risk. “This collaborative approach is very timely, following on the heels of the White House National Cybersecurity Strategy that articulates a combined and coordinated approach between the government and private sector to help defend critical infrastructure from cyberthreats. As part of that strategy, the government also recognizes they must do more on offense to counter foreign-based cyber adversaries. I would also note that adherence to the framework might be used to demonstrate implementation of recognized cybersecurity practices to qualify for regulatory relief for cyberattack victims provided under Public Law 116-321.” 

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.

Related News Articles

Headline
The AHA Jan. 14 expressed support for the Rural Hospital Cybersecurity Enhancement Act (S. 2169), legislation that would direct the Department of Health and…
Headline
The FBI Jan. 8 released an alert on evolving threat tactics by Kimsuky, a North Korean state-sponsored cyber threat group. As of last year, the group…
Headline
The Cybersecurity and Infrastructure Security Agency Dec. 11 released an update to its voluntary Cybersecurity Performance Goals, which includes measurable…
Headline
U.S. and international agencies are warning of potential cyberattacks on health care and other critical infrastructure from state-sponsored cyber actors in…
Headline
A critical, unauthenticated remote code execution vulnerability known as React2Shell has been added to the Cybersecurity and Infrastructure Security Agency’s…
Headline
The FBI has public resources available to help prevent exploitation by cybercriminals, who use artificial intelligence for deception. An infographic by the FBI…