In 2023, 133 million health care records were breached, more than twice the count of 2022 and 2021 combined. At this rate, next year’s numbers could look even more grim — especially following Change healthcare’s cyberattack in February 2024 — what the American Hospital Association deemed the most significant attack on healthcare in American history. A new federal strategy hopes to achieve its intended goal of cracking down on healthcare cyber vulnerabilities.
Released in December 2023 by the U.S. Department of Health and Human Services (HHS), the strategy — titled Health Care Sector Cybersecurity — outlines a new path to reinforce cyber defenses in healthcare. With more specificity than similar guidelines have had in the past, it lays out what health systems should be doing across cybersecurity performance goals (CPG).
Those 20 goals cover a broad range of cybersecurity best practices, from basic ones like email security and multifactor authentication to more advanced activities, such as incident reporting and attack testing.
While they’re all voluntary, they could be tied to significant incentives soon, or even made mandatory in the future. As such, healthcare executives should ensure their IT teams are preparing accordingly. Is yours?
Our own Brian Conner sat down with Troy Hawes to cover what leaders should know about the new HHS cybersecurity plan.


