Critical Infrastructure Security

New HHS toolkit helps healthcare sector gauge cyber preparedness

Digital security heart lock with heartbeat graph, representing cybersecurity in healthcare. Futuristic, technology, protection and health concept.

Cybersecurity Dive reports that the Department of Health and Human Services has released an updated Risk Identification and Site Criticality toolkit to help healthcare organizations assess cybersecurity practices and identify potential risks.

The RISC 2.0 allows healthcare organizations to "compare multiple facilities across systems, coalitions, and regions to identify dependencies and interdependencies in a consistent, repeatable way." The toolkit is available through a portal on the departments website, where organizations can input facility information and complete self-assessments. Those assessments generate reports evaluating preparedness for potential crises, including natural disasters and cyberattacks.

According to RISC's user manual, the new module "supports identification and assessment of cyber risks that may impact facility operations, safety, continuity of care, and mission performance by mapping the questions to the 206 NIST Cybersecurity Framework Subcategories and 20 HHS Cybersecurity Performance Goals."

In a statement, John Knox, HHS's principal deputy assistant secretary for preparedness and response, added that the module "will help our partners understand what is needed to strengthen their resilience and we strongly encourage them to take advantage of it."

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds