The Healthcare and Public Health Sector Coordinating Council’s Cybersecurity Working Group testified to the House Energy and Commerce Subcommittee on Health about sector progress in adopting strong cybersecurity practices. Greg Garcia, HSCC executive director, endorsed two pending bills—the ‘Healthcare Cybersecurity and Resiliency Act’ and the ‘Rural Hospital Cybersecurity Enhancement Act,’ while offering refinement suggestions. Garcia noted that HSCC published nearly 40 cybersecurity best practices since 2019, many developed jointly with HHS. He emphasized that scaling implementation of these tools to stakeholders requires government support alongside industry efforts.
Small, rural, and resource-constrained health providers remain the sector’s most vulnerable, requiring a ‘concerted, multi-pronged combination of government programs, assistance, and funding coupled with market-based mutual support, community defense and safe harbor dispensation.’ The Rural Hospital Cybersecurity Enhancement Act would provide targeted assistance to these vulnerable providers. These bills provide complementary guidance on structured coordination processes and objectives across HHS, CISA, and the healthcare sector, and targeted assistance to rural and resource-constrained health providers.
Garcia further observed that both bills ‘represent a welcome indication of the committee’s attention to this complex and evolving challenge,’ adding that ‘where clarifications or refinements are needed in certain provisions, we stand ready to work with the committee to consider recommendations.
The HSCC recommended that HHS and CISA formally involve the council in cybersecurity policy deliberations, threat information sharing and incident response advisories for the health care community. It also recommended clarifying Section 4 of the Cyber Resiliency Act to require that the HHS designee responsible for internal and external cybersecurity coordination be at the deputy assistant secretary level or above and have sufficient authority to influence policy and programmatic decisions.
The council recommended making grant funding available to the broadest possible community of resource-constrained health care providers. It also called for funding to support replacing older, vulnerable medical devices that can no longer be adequately protected against cyber threats.
Finally, the HSCC recommended that Congress avoid prescribing specific technical solutions, such as multifactor authentication and encryption, in legislation. The council argued that technology is continually evolving, changing the meaning, implementation, and effectiveness of specific security products and methods. It said technical guidance would be better addressed through evolving industry security frameworks that are already widely recognized and referenced.
Garcia referenced HSCC’s 2025 report ‘On the Edge: Cybersecurity Health of America’s Resource-Constrained Health Providers’ as validation of the bill’s findings and provisions.
HSCC offers several resources to strengthen healthcare organizations’ cybersecurity preparedness and resilience. The Health Industry Cybersecurity Practices (HICP) 2023 publication, a joint HHS-HSCC update to the 2019 version, provides executives, practitioners, and health delivery organizations with best practices for managing cyber threats and protecting patient safety. Building on HICP, the consolidated Healthcare Cyber Performance Goals derive from a joint HHS-HSCC Hospital Cyber Landscape Analysis that identified the vulnerabilities and threats most frequently causing damaging hospital attacks and assessed existing prevention capabilities.
The Sector Mapping and Risk Toolkit (SMART) was developed in response to the catastrophic Change Healthcare ransomware attack, which disrupted roughly one-third of the nation’s health systems and resulted in substantial daily revenue losses. SMART provides templates enabling healthcare organizations to map critical workflows and identify systemic risks posed by third-party technology, software, and communications services.
The Operational Continuity-Cyber Incident Checklist offers a flexible protocol for operational staff and executive management to respond to and recover from extended enterprise outages caused by serious cyberattacks, adaptable to each organization’s size, resources, and capabilities.
Operation Vital Signs, hosted by HSCC and the Health Information Sharing and Analysis Center, conducted the nation’s first healthcare cybersecurity tabletop exercise in July 2026, engaging over 500 participants from approximately 120 organizations. The exercise examined enterprise-level and cross-sector response and recovery, focusing on collective impacts, coordination, shared resources, and information flows among health sector organizations, government agencies, and sector partners.
The final After Action Report with lessons learned and recommendations is expected in November. The Cybersecurity Information Sharing Best Practices guide complements these efforts by explaining how healthcare organizations can establish and improve cyber threat information-sharing programs across their enterprises.
Congress should support a long-term extension of the Cybersecurity Information Sharing Act of 2015, which established the 405(d) Program enabling joint initiatives between HHS and the healthcare sector while protecting industry stakeholders from regulatory jeopardy as an incentive for voluntary threat information sharing. HHS should partner with HSCC and healthcare stakeholders in a national communications campaign positioning cybersecurity as a patient safety imperative, featuring a federated strategy that addresses five critical areas: threat monitoring, risk management, medical device security, incident response and recovery, and effectiveness measurement.
Joint HHS-HSCC security guidance demonstrates greater credibility, reach, and adoption than independent publications, warranting formalized procedures for collaborative publication development similar to those that produced resources like ‘Health Industry Cybersecurity Practices (HICP): Managing Threats and Protecting Patients’ and the ‘Hospital Resiliency Cyber Landscape Analysis.’ HHS should encourage health sector organizations to join the Health Information Sharing and Analysis Center (Health-ISAC) as part of a comprehensive resilience strategy.
CISA, HHS, and law enforcement should establish formal MOU protocols requiring consultation with Health-ISAC and HSCC when developing threat and remediation advisories, ensuring government and industry leaders align on threat intelligence accuracy, sector relevance, and appropriate remediation before public release.
Unregulated third-party technology and service providers pose both significant threat vectors and substantial third-party risk management costs. Health providers should not bear sole responsibility for vendor oversight; third-party vendors supporting critical healthcare infrastructure must be held to enforceable, elevated cybersecurity standards commensurate with the life-or-death stakes of healthcare delivery.
The February 2024 Change Healthcare attack underscores healthcare’s incident response challenges. HSCC recommends establishing a ‘Healthcare 911 Cyber Civil Defense,’ a rapid response capability to declare national cyber emergencies, activate catastrophic insurance, provide emergency funding, suspend regulatory barriers, and deploy mobile healthcare services, particularly for small, rural, and resource-constrained providers. Government and industry should exchange actionable intelligence rapidly, standardize incident reporting across federal agencies, and waive victim reporting requirements during early discovery and triage.
CISA 2015 protections for threat information sharing should extend to victim organizations implementing recognized practices and discussing public health impacts with government. Federal incident response support, expanded law enforcement disruption initiatives, and military/National Guard cyber and medical assistance with HHS/CISA reimbursement should be available for qualifying providers. Finally, government and industry research partnerships should optimize incident response and continuity to enable rapid operational recovery following severe cyberattacks.
Garcia mentioned that the HHS should administer a healthcare cybersecurity workforce development program in partnership with NIST, CISA, and the Veterans Administration, offering free cyber training, expanded Regional Extension Centers support, and student loan forgiveness programs modeled after physician loan forgiveness or the NSF’s CyberCorps Scholarship for Service program. The government should also fund civilian cyber health corps programs providing loan forgiveness in exchange for service commitments, similar to the U.S. Public Health Service Commissioned Corps model.
Existing workforce initiatives should be augmented, particularly programs like the HITECH Act’s University-Based Training Program and Community College Consortia Program, which trained 21,437 students across all 50 states and U.S. territories at 91 academic institutions. Finally, the NICE Framework’s Work Roles and Job Descriptions should be mapped to HHS-HSCC Health Industry Cybersecurity Practices to create clarity and uniformity in matching skills with healthcare cybersecurity job requirements.
On regulatory reforms, Garcia mentioned that the January 2025 HHS notice of proposed rulemaking updating the HIPAA Security Rule lacked sufficient insight into healthcare cybersecurity complexities and failed to acknowledge the sector’s six years of good-faith progress building collective cyber defense. He recommended resetting or abandoning the HIPAA Security Rule update.
Instead, HSCC, as the primary cross-sector healthcare advisory council on critical infrastructure cybersecurity, stands ready to engage government leadership in phased policy consultations and workshops to develop a modernized, practical, scalable framework combining mandatory and flexible voluntary practices. HSCC cited the NIST Cybersecurity Framework (2014) as a successful public-private model, developed through one year of industry-led collaboration convened by NIST.
HHS, CISA, and other agencies must streamline and unify incident reporting requirements across multiple agencies, which currently provide minimal security benefit while largely serving agencies’ interests in exercising authority. Agencies ostensibly collect incident reports to analyze threats and provide actionable remediation guidance, but in practice their communications to the sector arrive late, lack relevance, and are often overtaken by subsequent events.
In conclusion, Garcia reminded the Chairman and Members of the Committee of the “tremendous amount of work to do in the health sector to make the policy and programmatic investments necessary to upgrade our cybersecurity diagnosis from critical to stable condition. We have been working hard on the prescription – some of it is bitter medicine, some of it should be simple and habitual. We also know we will never be totally immune from evolving cyber infections; we will only be better.”


