Lexology December 12, 2023
The U.S. Department of Health and Human Services (HHS) released a concept paper on December 6, 2023 outlining its action plan to enhance cyber resiliency in the health care sector by proposing certain voluntary cybersecurity actions and standards that may ultimately become requirements.
For health care organizations such as hospitals, “cyber resiliency” generally means how organizations anticipate, operate during, respond to, and recover from cyber attacks such as ransomware attacks, cloud exploitations, phishing or spear-phishing attacks, software and zero-day vulnerability exploitations, or distributed denial of service attacks.
The HHS concept paper is the agency’s latest activity within the cybersecurity risk landscape in health care this year. In April 2023, HHS released a Hospital Cyber Resiliency Landscape Analysis that focused on...