What are the HPH Cybersecurity Performance Goals?
The HPH Cybersecurity Performance Goals are voluntary, sector-specific cybersecurity goals for the Healthcare and Public Health (HPH) sector. Specifically, they were published in January 2024 by the U.S. Department of Health and Human Services (HHS) in collaboration with the Cybersecurity and Infrastructure Security Agency (CISA) and the Health Sector Coordinating Council (HSCC). In practice, they help healthcare organizations prioritize the cybersecurity practices that actually move the needle against the threats hitting the sector.
However, the HPH Cybersecurity Performance Goals are not a new regulatory framework. Instead, they are a curated subset of practices built on top of CISA’s Cross-Sector CPGs. Moreover, they are adapted specifically for healthcare realities, including legacy medical devices, 24/7 availability requirements, ransomware targeting patient care systems, and the wide maturity gap between major academic hospitals and rural clinics.
Are the HPH Cybersecurity Performance Goals mandatory for healthcare organizations?
No, the HPH CPGs are currently voluntary. Specifically, they are guidance, not regulation, and non-adoption does not trigger direct penalties under the CPGs themselves. However, treating them as purely optional would be a mistake.
In fact, HHS has publicly stated that the CPGs will inform future rulemaking. Moreover, the HIPAA Security Rule update and proposed Medicare and Medicaid cybersecurity requirements are both informed by the CPGs. As a result, organizations that start aligning now, particularly on the 10 Essential CPGs, will be in a dramatically stronger position when the enforceable requirements arrive.
How are the HPH CPGs structured?
The HPH CPGs are organized in two tiers, each containing 10 specific goals, for a total of 20. Moreover, the structure is deliberate: build the foundation first, then mature toward advanced practices.
Specifically, the two tiers are:
- Essential Goals (10 total): the floor of safeguards. They are foundational, relatively low-cost practices that address the most common attack vectors. As a result, every HPH organization is expected to reach this baseline, regardless of size or maturity
- Enhanced Goals (10 total): advanced practices that build on the Essentials. In practice, they raise the bar against more sophisticated adversaries and typically apply to larger or more mature organizations that have already achieved the Essentials
What cybersecurity practices do the HPH CPGs recommend?
The Essential Goals focus on fundamental cyber hygiene. In practice, they target the controls that deliver the biggest risk reduction for the lowest cost, which is why HHS expects every HPH organization to reach this baseline first.
Specifically, the Essential practices include:
- Mitigating known vulnerabilities on internet-facing assets, aligned with the CISA Known Exploited Vulnerabilities (KEV) catalog
- Deploying multi-factor authentication (MFA) for external access and privileged accounts
- Enforcing strong encryption for sensitive data in transit
- Providing basic cybersecurity training to all workforce members
- Strictly separating standard user accounts from privileged and administrative accounts
- Revoking credentials promptly when workforce members depart
- Establishing an actively maintained and tested incident response plan
- Identifying and managing risks from third-party products and services
How do the HPH Cybersecurity Performance Goals align with other cybersecurity frameworks?
The HPH CPGs were designed to plug into frameworks healthcare organizations already use, rather than add another parallel compliance track. Moreover, each goal is explicitly mapped in the official HHS guidance, which makes implementation far more efficient. As a result, if you already run a NIST CSF or HICP-aligned program, you are closer to the CPGs than you might think.
Specifically, the CPGs map to four established references:
- NIST Cybersecurity Framework (CSF): originally mapped to v1.1 and fully applicable to CSF 2.0, which added the Govern function and expanded supply chain coverage
- Health Industry Cybersecurity Practices (HICP): the sector-specific best-practice document jointly developed by HHS and the Health Sector Coordinating Council
- NIST SP 800-53 Rev. 5: the federal control catalog used across FedRAMP, FISMA, and many sector-specific regimes
- CISA Cross-Sector CPGs: the parent framework from which the HPH CPGs were derived