Using the 405(d) HICP Practices as Your Security Roadmap

Many small and mid-size healthcare organizations know they should improve cybersecurity but are unsure where to start. Frameworks can seem written for large hospital systems with security teams. One resource built with smaller organizations in mind is the Health Industry Cybersecurity Practices, known as HICP, published through the HHS 405(d) program.

The program takes its name from Section 405(d) of the Cybersecurity Act of 2015, which called for industry and government to develop practical guidance. The resulting publication, Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients, is free to download and organized by organization size.

What HICP covers

HICP focuses on the most common cyber threats facing healthcare. It identifies five major threats:

Email phishing attacks.

Ransomware attacks.

Loss or theft of equipment or data.

Insider, accidental or intentional data loss.

Attacks against connected medical devices that may affect patient safety.

It then describes ten cybersecurity practices that address them:

Email protection systems.

Endpoint protection systems.

Access management.

Data protection and loss prevention.

Asset management.

Network management.

Vulnerability management.

Security operations center and incident response.

Network-connected medical device security.

Cybersecurity oversight and governance.

The publication has a technical volume for small organizations and another for medium and large ones, along with resources such as assessment tools and templates.

Why it suits care organizations

Written for healthcare. Examples reflect clinical environments, including connected devices.

Scaled by size. A small facility is not expected to build the same program as a large health system.

Practical and prioritized. It describes sub-practices and gives an idea of where to begin.

Free. Cost is not a barrier to using it.

Recognized. The HITECH Act, as amended in 2021, directs HHS to consider whether an organization has implemented recognized security practices for the previous twelve months when making certain enforcement decisions. HICP is among the practices that may qualify, though it provides no guarantee about any outcome.

A simple way to use it

Step 1: Score yourself

Work through each practice and honestly assess how well it is in place: not started, partially in place or fully in place. Involve your IT partner, privacy officer and clinical leaders.

Step 2: Match against your risks

Compare the results with your HIPAA risk analysis. Where do gaps overlap with your highest risks? Those are your first priorities.

Step 3: Pick a few actions

Choose three to five items for the next quarter. Examples might include enabling multi-factor authentication for email, setting up an offsite immutable backup, creating an asset inventory or writing an incident response plan.

Step 4: Assign owners and dates

Each action needs an owner, a date and a budget estimate. Track progress in a simple spreadsheet.

Step 5: Review and repeat

Revisit every quarter, update your scores and adjust. Report progress to leadership.

Connecting it with other frameworks

HICP complements the HIPAA Security Rule, which sets requirements but is intentionally flexible about how to meet them. It also maps to the NIST Cybersecurity Framework, so organizations that use NIST CSF 2.0 can relate the two. You do not need to adopt several frameworks at once. Pick one as your working roadmap and cross-reference when necessary.

Governance matters

The last practice, oversight and governance, is easy to overlook. Name someone responsible for security, put cybersecurity on leadership agendas and set a budget line. Without it, technical measures drift.

What to avoid

Treating the assessment as a one-time paper exercise.

Trying to do all ten practices at once.

Ignoring connected medical devices because they feel outside IT.

Leaving out clinical leaders who understand how devices are used.

How UnityCare IT can help

UnityCare IT helps healthcare and senior living organizations assess themselves against HICP, prioritize improvements and carry out the technical work. If you would like a facilitated walkthrough, we can set that up with your leadership team.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172