HHS Prepares to Launch Mandatory Minimum Cybersecurity Standards for U.S. Hospitals

U.S. Hospitals to Face New Mandatory Cybersecurity Rules from HHS

INFORMATIONAL
June 21, 2026
5m read
Policy and ComplianceRegulatoryThreat Intelligence

Full Report

Executive Summary

In response to the relentless wave of cyberattacks targeting the U.S. healthcare sector, the U.S. Department of Health and Human Services (HHS) is preparing to transition from voluntary guidance to regulatory enforcement. Within the coming weeks, HHS is expected to announce new regulations that establish mandatory minimum cybersecurity standards for hospitals. This initiative will codify elements of the Healthcare and Public Health (HPH) Cybersecurity Performance Goals (CPGs) that were introduced in January 2024. The move signals a significant policy shift aimed at creating a more resilient healthcare infrastructure by mandating foundational security practices. The program is expected to be supported by financial assistance but will also include penalties for non-compliance, aiming to elevate the baseline security posture across the entire hospital ecosystem.


Regulatory Details

The forthcoming regulations will be built upon the HPH CPGs, a framework developed by HHS in collaboration with industry partners. While the full scope of the mandatory rules is not yet public, officials have indicated that the initial rollout will focus on the "essential" CPGs. These are fundamental, high-impact security practices considered vital for defending against the most common cyber threats.

Essential CPGs include, but are not limited to:

  • Mitigating Known Vulnerabilities: Implementing robust patch and vulnerability management programs.
  • Multi-Factor Authentication (MFA): Enforcing MFA for remote access, administrative privileges, and access to sensitive data.
  • Strong Encryption: Encrypting sensitive data both at rest and in transit.
  • Incident Response Planning: Developing and regularly testing a comprehensive incident response plan.
  • Email Security: Implementing measures to detect and block phishing attempts.

Affected Organizations

The initial phase of the mandatory regulations will specifically target U.S. hospitals. However, the long-term vision of the HHS strategy suggests that these or similar requirements may eventually extend to other entities within the healthcare and public health sector. The HHS budget proposal includes provisions for financial aid, with a particular focus on assisting small, rural, and under-resourced hospitals in meeting these new standards.

Compliance Requirements

Hospitals will be required to attest to their implementation of the mandated CPGs. The specific mechanisms for attestation and verification are yet to be detailed but will likely involve integration with existing Medicare/Medicaid programs. The core requirement will be to demonstrate that the essential CPGs are not just documented in policies but are actively implemented and operationalized as technical controls within the hospital's IT environment.

Implementation Timeline

  • January 2024: HHS released the voluntary HPH Cybersecurity Performance Goals.
  • Summer 2024 (coming weeks): HHS is expected to issue a notice of proposed rulemaking, officially unveiling the new mandatory requirements.
  • Fiscal Year 2025: The HHS budget proposal includes $1.3 billion in financial assistance to help hospitals meet the new standards.
  • Fiscal Year 2029: Proposed start date for financial penalties (e.g., reduced Medicare payments) for hospitals that fail to comply.

Impact Assessment

The introduction of mandatory standards will have a significant operational and financial impact on U.S. hospitals.

  • Resource Allocation: Hospitals will need to allocate budget and personnel to implement and manage the required security controls. This may be particularly challenging for smaller facilities with limited IT and security staff.
  • Operational Changes: The enforcement of controls like MFA may require changes to clinical workflows and will necessitate staff training.
  • Compliance Overhead: Hospitals will face new administrative burdens related to tracking, documenting, and attesting to their compliance status.
  • Positive Security Impact: If implemented successfully, these standards will significantly raise the bar for cybersecurity in the healthcare sector, reducing the frequency and impact of disruptive cyberattacks, protecting patient data, and ensuring continuity of care.

Enforcement & Penalties

The HHS fiscal 2025 budget proposal outlines an enforcement mechanism that ties compliance to Medicare payments. Starting in fiscal 2029, hospitals that do not meet the mandatory standards could face financial penalties, such as reductions in their Medicare reimbursements. This "stick" approach, combined with the "carrot" of financial assistance, is designed to drive widespread adoption.

Compliance Guidance

Hospitals should not wait for the final rules to be published. Proactive steps can be taken now:

  1. Conduct a Gap Analysis: Assess your current security posture against the published HPH CPGs, focusing on the "essential" goals. Identify where your organization falls short.
  2. Prioritize MFA: If not already in place, make the implementation of MFA across all remote access points and for all privileged users your top priority.
  3. Develop a Roadmap: Create a prioritized roadmap and budget for addressing the identified gaps. Focus on high-impact, low-cost solutions first.
  4. Review Incident Response Plans: Ensure your IR plan is up-to-date, tested, and accounts for common attack scenarios like ransomware.
  5. Engage Leadership: Brief hospital leadership on the upcoming regulations and the need for investment in cybersecurity to ensure buy-in and resource allocation.

Timeline of Events

1
January 1, 2024
HHS released the voluntary Healthcare and Public Health (HPH) Cybersecurity Performance Goals (CPGs).
2
June 20, 2024
Reports indicate HHS will release mandatory cybersecurity rules for hospitals in the coming weeks.
3
June 21, 2026
This article was published
4
January 1, 2029
Proposed start date for financial penalties for non-compliant hospitals.

MITRE ATT&CK Mitigations

A core requirement of the new regulations, MFA is critical for preventing credential-based attacks.

Mapped D3FEND Techniques:

The CPGs emphasize mitigating known vulnerabilities, which requires a robust patch management program.

Mapped D3FEND Techniques:

Encryption of patient data (PHI) at rest and in transit is a foundational HIPAA requirement and a key CPG.

Mapped D3FEND Techniques:

Part of the CPGs includes email security, which is heavily reliant on user awareness and training to be effective.

D3FEND Defensive Countermeasures

In anticipation of the HHS mandates, hospitals must prioritize the deployment of Multi-Factor Authentication (MFA) as their primary defense enhancement. The focus should be on protecting all remote access to the network (e.g., VPNs, Citrix), access to cloud services (like Microsoft 365), and all privileged accounts (domain administrators, EHR system admins). Given the high-stakes environment of patient care, implementation should favor less intrusive but secure methods, such as push notifications (e.g., Duo, Microsoft Authenticator) over SMS-based codes, which are vulnerable to SIM-swapping. A phased rollout plan is crucial, starting with IT staff and high-privilege users, then expanding to all remote users, and finally to all employees accessing critical systems. This single control directly addresses the most common attack vector—compromised credentials—and is a cornerstone of the HHS CPGs.

To meet the CPG requirement for mitigating known vulnerabilities, hospitals need a formalized and efficient patch management program. This goes beyond just patching Windows servers. It must encompass all assets on the network, including medical devices (IoMT), network infrastructure, and third-party software. Hospitals should use an asset inventory system to identify all devices and a vulnerability management tool to scan for and prioritize vulnerabilities based on severity (CVSS score) and exploitability (e.g., CISA KEV catalog). Given the 24/7 nature of hospital operations, patching windows must be carefully coordinated with clinical departments to minimize disruption to patient care. For critical vulnerabilities, a risk-based decision might be to implement compensating controls (like network segmentation) until a patch can be safely applied.

Network segmentation is a critical compensating control for hospitals, especially given the challenges of patching legacy systems and medical devices. To align with the CPGs, hospitals should create distinct network zones to isolate critical systems. For example, medical devices should be on a separate VLAN from the general corporate network. The EHR system should be in its own protected enclave. Access between these zones should be strictly controlled by internal firewalls with a default-deny policy. This 'microsegmentation' approach can prevent a ransomware attack that starts on a business workstation from spreading to critical clinical systems, thereby containing the impact and ensuring patient care can continue. This is a strategic investment that significantly enhances resilience, a key goal of the new HHS regulations.

Timeline of Events

1
January 1, 2024

HHS released the voluntary Healthcare and Public Health (HPH) Cybersecurity Performance Goals (CPGs).

2
June 20, 2024

Reports indicate HHS will release mandatory cybersecurity rules for hospitals in the coming weeks.

3
January 1, 2029

Proposed start date for financial penalties for non-compliant hospitals.

Sources & References

June, 2024
BSafesJune 21, 2024

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Tags

HHSHealthcareCybersecurityComplianceRegulationCPGMFA

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.