Government

CISA, HHS Release Cybersecurity Healthcare Toolkit

CISA and the HHS have released resources for healthcare and public health organizations to improve their security.

CISA and the HHS have released resources for healthcare and public health organizations to improve their security.

The US cybersecurity agency CISA and the Department of Health and Human Services (HHS) on Wednesday released cybersecurity resources for healthcare and public health (HPH) organizations.

These entities heavily rely on digital technologies to store personal and medical information, perform medical procedures, and communicate with patients, which increases their attack surface, but often face challenges in finding the necessary resources to invest in cybersecurity.

The newly released cybersecurity healthcare toolkit is meant to help organizations at every level build their cybersecurity foundation and implement more advanced tools to improve their defenses.

The toolkit details cyber hygiene steps that both organizations and individuals should take, provides an overview of the threat landscape, documents cybersecurity best practices, and provides a cybersecurity framework implementation guide.

Furthermore, it provides organizations with risk assessment tools and information on recommended tools, such as vulnerability scanning services and CISA’s Known Exploited Vulnerabilities (KEV) catalog.

The toolkit also recommends resources to help organizations strengthen their security stance, prevent ransomware attacks, access free cybersecurity services and tools, and implement incident response plans.

Advertisement. Scroll to continue reading.

For organizations constrained by resources, the toolkit recommends accessing the State and Local Cybersecurity Grant Program (SLCGP), and free and low-cost services for near-term improvements, and details what organizations in the health sector should expect from technology providers.

“Because cybersecurity is one of many areas where the healthcare and public health sector is facing persistent challenges, CISA and HHS are providing this toolkit filled with remedies to give sector stakeholders a greater ability to proactively assess vulnerabilities and implement solutions,” CISA and HHS note.

The toolkit was released on the same day that CISA and HHS co-hosted a roundtable discussion on the cybersecurity challenges the health sector faces and on how collaboration between the government and the industry can help reduce risks.

“Adversaries see healthcare and public health organizations as high value yet relatively easy targets – or what we call target rich, cyber poor.  Given that healthcare organizations have a combination of personally identifiable information, financial information, health records, and countless medical devices, they are essentially a one-stop shop for an adversary,” CISA deputy director Nitin Natarajan said.

Related: Healthcare Organizations Hit by Cyberattacks Last Year Reported Big Impact, Costs

Related: Vulnerabilities in OpenEMR Healthcare Software Expose Patient Data

Related: Personal Information of 11 Million Patients Stolen in Data Breach at HCA Healthcare

Related Content

IoT Security

The guidance aims to establish product cybersecurity requirements for IoT devices integrated into federal agencies’ networks.

Artificial Intelligence

Come vulnerabilities were found within hours, but that does not mean the model was able to exploit them within that time, the official said.

Data Protection

Federal agencies are required to transition high-value assets and high-impact systems to use PQC by the end of 2030 and 2031.

Data Breaches

Threat actors gained access to personal and protected health information that Xsolis received from its clients.

Data Breaches

The digital health company said it learned of the breach on June 8 and the attackers demanded a ransom.

Government

NSPM-12 establishes a clear structure for NSS cybersecurity governance and accountability and reestablishes CNSS.

Government

The new BOD 26-04 requires agencies to review and update vulnerability management policies with a focus on KEV catalog entries.

Data Breaches

The ShinyHunters extortion group leaked roughly 234 GB of data allegedly stolen from the dental benefits administrator.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version