In response to the relentless wave of cyberattacks targeting the U.S. healthcare sector, the U.S. Department of Health and Human Services (HHS) is preparing to transition from voluntary guidance to regulatory enforcement. Within the coming weeks, HHS is expected to announce new regulations that establish mandatory minimum cybersecurity standards for hospitals. This initiative will codify elements of the Healthcare and Public Health (HPH) Cybersecurity Performance Goals (CPGs) that were introduced in January 2024. The move signals a significant policy shift aimed at creating a more resilient healthcare infrastructure by mandating foundational security practices. The program is expected to be supported by financial assistance but will also include penalties for non-compliance, aiming to elevate the baseline security posture across the entire hospital ecosystem.
The forthcoming regulations will be built upon the HPH CPGs, a framework developed by HHS in collaboration with industry partners. While the full scope of the mandatory rules is not yet public, officials have indicated that the initial rollout will focus on the "essential" CPGs. These are fundamental, high-impact security practices considered vital for defending against the most common cyber threats.
Essential CPGs include, but are not limited to:
The initial phase of the mandatory regulations will specifically target U.S. hospitals. However, the long-term vision of the HHS strategy suggests that these or similar requirements may eventually extend to other entities within the healthcare and public health sector. The HHS budget proposal includes provisions for financial aid, with a particular focus on assisting small, rural, and under-resourced hospitals in meeting these new standards.
Hospitals will be required to attest to their implementation of the mandated CPGs. The specific mechanisms for attestation and verification are yet to be detailed but will likely involve integration with existing Medicare/Medicaid programs. The core requirement will be to demonstrate that the essential CPGs are not just documented in policies but are actively implemented and operationalized as technical controls within the hospital's IT environment.
The introduction of mandatory standards will have a significant operational and financial impact on U.S. hospitals.
The HHS fiscal 2025 budget proposal outlines an enforcement mechanism that ties compliance to Medicare payments. Starting in fiscal 2029, hospitals that do not meet the mandatory standards could face financial penalties, such as reductions in their Medicare reimbursements. This "stick" approach, combined with the "carrot" of financial assistance, is designed to drive widespread adoption.
Hospitals should not wait for the final rules to be published. Proactive steps can be taken now:
U.S. government issues NSM-22, mandating cybersecurity standards across all 16 critical infrastructure sectors, reinforcing the shift from voluntary guidelines.
The White House has enacted National Security Memorandum 22 (NSM-22), a landmark policy replacing voluntary critical infrastructure cybersecurity guidelines with mandatory, performance-based standards across all 16 sectors, including healthcare. This directive, effective immediately, introduces the 'Systemically Important Entity' (SIE) designation for critical organizations, subjecting them to heightened federal oversight and stricter requirements. NSM-22 provides the overarching national framework for sector-specific regulations, such as those being developed by HHS for hospitals, signaling a definitive end to self-regulation for vital national assets.
HHS released the voluntary Healthcare and Public Health (HPH) Cybersecurity Performance Goals (CPGs).
Reports indicate HHS will release mandatory cybersecurity rules for hospitals in the coming weeks.
Proposed start date for financial penalties for non-compliant hospitals.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.