A hospital’s most sensitive asset isn’t behind a locked door — it’s sitting on a server, in an inbox, or plugged into a heart monitor down the hall. Healthcare organizations have spent years absorbing an uncomfortable truth: cyberattacks aren’t just an IT inconvenience, they’re a patient safety issue. That reality is exactly what pushed Congress, and later the U.S. Department of Health and Human Services (HHS), to launch a public-private effort known as 405(d) — and the practical guidance it produced, the Health Industry Cybersecurity Practices (HICP).

For anyone trying to make sense of healthcare cybersecurity guidance in 2021, 405(d) and HICP are two of the most frequently referenced resources, precisely because they were built by the industry, for the industry, and are free to download. Here’s what the program is, where it came from, and how organizations of different sizes are putting it to use.

What Section 405(d) actually is

The starting point is a piece of federal legislation: the Cybersecurity Act of 2015. Tucked inside that law is Section 405(d), titled “Aligning Health Care Industry Security Approaches.” According to HHS’s own fact sheet on the provision, Congress used this section to direct HHS to align healthcare industry security practices, rather than simply issue new regulations from the top down.

HHS’s approach was to convene people who actually run cybersecurity programs in healthcare settings. In 2017, HHS formed the 405(d) Task Group, drawing on the Healthcare and Public Health (HPH) Sector Critical Infrastructure Security and Resilience Public-Private Partnership. Per HHS, the Task Group ultimately grew to more than 150 participants — information security officers, clinicians, privacy experts, health IT professionals, and other subject matter experts from across the industry.

HHS describes the Task Group’s charge around three core goals:

  1. Cost-effectively reduce cybersecurity risk for healthcare organizations of all types and sizes.
  2. Support voluntary adoption — this was never meant to be a mandate.
  3. Keep the guidance actionable, practical, and relevant to healthcare stakeholders regardless of resource level.

That third point matters. A lot of cybersecurity frameworks are written for large enterprises with dedicated security operations centers. HICP was explicitly designed to also work for a two-physician practice with no in-house IT staff.

The Task Group first convened in May 2017, and by HHS’s account met multiple times over the following months to draft the publication that would become HICP. Before finalizing it, the 405(d) team reportedly pretested the material across several U.S. cities to gather feedback from working healthcare professionals — a detail that underscores the “industry-led” framing HHS uses to describe the whole effort.

Where HICP fits into the picture

The Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients publication (commonly shortened to HICP) is the primary deliverable of the 405(d) effort. It isn’t a single document but a set of three:

  • The Main Document lays out the landscape — the five current threats facing the sector and an introduction to the ten practices used to mitigate them.
  • Technical Volume 1 goes deeper on those ten practices specifically for small healthcare organizations.
  • Technical Volume 2 covers the same ten practices, but tailored for medium and large healthcare organizations, which typically have more infrastructure, more staff, and more complex environments to secure.

HHS materials note that the recommendations draw on the National Institute of Standards and Technology (NIST) Cybersecurity Framework, which the 405(d) program describes as a widely accepted baseline for cost-effective security practices. In other words, HICP isn’t inventing a new philosophy of cybersecurity — it’s translating an existing, respected framework into language and priorities that make sense for a hospital billing department or a rural clinic, not just a bank or a defense contractor.

It’s worth being precise about what HICP is not. It is voluntary guidance, not a regulation, and it does not replace HIPAA Security Rule obligations or any other legal requirement. Following HICP is not itself a compliance certification, and organizations should treat it as one input into a broader security and risk-management program rather than a finish line.

The five threats HICP identifies

HHS’s 405(d) materials describe five threats as the most pertinent facing the healthcare and public health sector at the time of publication:

1. Email phishing attacks

Phishing is described in 405(d) materials as untargeted, mass emails sent to large numbers of people, asking for sensitive information or luring recipients to a fake website. Healthcare staff are frequent targets because a single successful phishing email can be the entry point for a much larger breach.

2. Ransomware attacks

HICP defines ransomware as a cyberattack that renders data and systems unusable until a ransom is paid. For a hospital, this isn’t an abstract IT headache — it can mean diverted ambulances, canceled procedures, and delayed care while systems are locked down.

3. Loss or theft of equipment or data

This threat covers the very physical side of cybersecurity: a stolen laptop, a misplaced USB drive, or paper records left somewhere they shouldn’t be. HHS notes that lost or stolen equipment and data can then be used to access systems or sold for profit.

4. Insider, accidental, or intentional data loss

405(d) materials distinguish between two flavors of insider threat. An accidental insider threat is unintentional — an honest mistake, a procedural error, or being tricked by an outside actor. An intentional insider threat involves an employee, contractor, or other authorized user deliberately misusing their access for personal gain or to cause harm.

5. Attacks against connected medical devices

Modern healthcare runs on networked devices — infusion pumps, imaging equipment, vital sign monitors. HHS materials note that an attack against an organization’s connected medical devices can pose a direct impact on patient safety, not just data confidentiality. This is the threat category that most clearly illustrates why HHS frames cybersecurity as a patient-safety issue rather than a purely technical one.

The ten practices HICP recommends

To mitigate those five threats, the HICP Main Document and its technical volumes lay out ten cybersecurity practices. HHS’s 405(d) program describes them as follows:

  1. Email protection systems — basic email security controls, phishing simulation training for staff, and multi-factor authentication as an added layer of defense.
  2. Endpoint protection systems — antivirus software, full-disk encryption, and consistent patching across every device connecting to the network.
  3. Access management — clearly identifying every user, maintaining audit trails, issuing unique accounts instead of shared admin logins, and tailoring access to each person’s actual job requirements.
  4. Data protection and loss prevention — data classification policies that spell out how sensitive information should be handled, encrypted, stored, and disposed of.
  5. Asset management — a full, accurate, continuously updated inventory of IT equipment, including procurement processes that track each asset’s lifecycle and rules for personal devices on the network.
  6. Network management — network segmentation to limit how far an intruder can move if they get in, alongside firewalls and defined network access profiles.
  7. Vulnerability management — regularly scheduled vulnerability scans and routine patching of servers, applications, and third-party software.
  8. Incident response — a documented incident response plan, practiced in advance, so staff know what to do the moment an attack is discovered.
  9. Medical device security — treating connected medical devices like any other IT asset: inventoried, patched, access-controlled, and monitored.
  10. Cybersecurity policies — organization-wide policies covering training, roles and responsibilities, incident reporting, and acceptable use of equipment and personal devices.

None of these practices exist in isolation — HHS material frames them as a connected set. A phishing email (threat 1) is addressed by email protection systems (practice 1) and reinforced by cybersecurity policies and staff training (practice 10). A stolen laptop (threat 3) is far less damaging to an organization that already has strong endpoint protection and data encryption in place (practices 2 and 4).

How organizations of different sizes actually use HICP

One of the more distinctive design choices behind HICP is that HHS didn’t publish one version and expect every organization to make it fit. The two technical volumes exist because a five-physician practice and a multi-hospital health system face the same five threats but have very different resources to address them.

Small organizations. HHS’s Quick Start Guide for small healthcare organizations makes a direct pitch to practices that may not have dedicated IT security staff: the guidance is meant to be practical and cost-effective, improving staff “cyber hygiene” without requiring an enterprise security budget. The framing HHS uses is candid — small practices are not exempt from being targeted. Hackers, nation-state actors, and cybercriminals alike have increasingly gone after smaller organizations, not just large health systems, in part because smaller practices may have fewer defenses in place. Technical Volume 1 breaks the ten practices down into sub-practices scaled to that reality — things a practice’s office manager or an outsourced IT contractor could realistically implement.

Medium and large organizations. HHS’s companion Quick Start Guide for medium and large organizations opens with a pointed question aimed at bigger systems that already have IT departments: is that department’s existing effort actually good enough? The guide cites data suggesting the scale of the problem — HHS materials referenced an average of one health data breach per day in 2016, with roughly 27 million patient records compromised that year, and an estimated cost to the industry of $6.2 billion annually. Technical Volume 2 goes further into practices suited to more complex environments: multiple facilities, larger user populations, more extensive networks, and dedicated security teams that need a shared framework to coordinate around. HHS frames the goal for larger organizations less as “getting started” and more as building a coordinated, enterprise-wide “culture of cybersecurity” — treating security as a leadership and governance issue, not something confined to the IT department.

Across both audiences, HHS’s messaging is consistent: cybersecurity maturity varies widely across the sector, and HICP is meant to let organizations at different maturity levels work from the same shared vocabulary and threat list, even if their implementation details differ substantially.

Where to find the source material

Because HICP is published as public, no-cost federal guidance, it’s designed to be read directly rather than taken secondhand. The Main Document, both technical volumes, the five-threat information sheets, and the Quick Start Guides for small and for medium/large organizations are all available through HHS’s dedicated 405(d) program site. The Cybersecurity and Infrastructure Security Agency (CISA) and NIST also publish complementary healthcare-sector cybersecurity resources that reference the same underlying NIST Cybersecurity Framework that HICP builds on.

This article summarizes publicly available federal guidance for informational purposes. It is not legal advice, and it does not represent affiliation with HIMSS, the World of Health IT conference, or any other organization. Healthcare organizations evaluating their own cybersecurity posture should consult the original HICP documents and their own qualified security and legal advisors.

Frequently Asked Questions

No. HICP is voluntary, consensus-based guidance developed under Section 405(d) of the Cybersecurity Act of 2015. It does not replace HIPAA Security Rule obligations or any other regulatory requirement, and adopting it is not a form of compliance certification.

Who developed the HICP publication?

HHS convened the 405(d) Task Group in 2017, drawing on the Healthcare and Public Health Sector Critical Infrastructure Security and Resilience Public-Private Partnership. HHS describes the group as including more than 150 information security officers, clinicians, privacy experts, and health IT professionals.

What are the five threats identified in HICP?

The Main Document identifies email phishing attacks, ransomware attacks, loss or theft of equipment or data, insider (accidental or intentional) data loss, and attacks against connected medical devices as the five current threats facing the healthcare sector.

Does HICP apply differently to small versus large organizations?

Yes. Technical Volume 1 tailors the ten cybersecurity practices to small healthcare organizations with limited IT resources, while Technical Volume 2 addresses the same ten practices for medium and large organizations with more complex infrastructure and dedicated security staff.

Is HICP based on an existing cybersecurity framework?

HHS materials indicate that HICP’s recommendations draw on the National Institute of Standards and Technology (NIST) Cybersecurity Framework, adapting its principles into practices specifically relevant to healthcare organizations.