Skip to main content
Category: OCR Enforcement and Penalties

Health Industry Cybersecurity Practices

Also known as: HICP, Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients, 405(d) HICP
Simply put

HICP is a set of free, voluntary cybersecurity recommendations and best practices published through the HHS 405(d) Program to help healthcare organizations prepare for and defend against cyber threats that can affect patient safety. It is educational guidance rather than a law or regulation, so following it is not itself a HIPAA requirement. However, implementing recognized security practices such as HICP can matter during HIPAA enforcement, and readers should verify the current details against official HHS 405(d) materials.

Formal definition

HICP (Health Industry Cybersecurity Practices: Managing Threats and Protecting Patients) is voluntary cyber hygiene guidance developed under the HHS 405(d) Program to provide healthcare organizations with recommendations and best practices aimed at mitigating cybersecurity threats that can impact patient safety. HICP is generally structured to address a set of prevalent threat vectors and to present cybersecurity practices scaled to organization size through audience-specific technical volumes (small organizations versus medium/large organizations); practitioners should confirm the exact number of threat vectors, practices, and volume structure against the current published edition. HICP is not a HIPAA rule and does not carry independent enforcement authority; it is separate from the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules administered by HHS OCR. Notably, HICP is expressly identified as an example of a 'recognized security practice' under Section 13412 of the HITECH Act (added by Public Law 116-321). Under that provision, in HIPAA enforcement contexts OCR is generally required to consider whether a regulated entity had, for a specified preceding period (commonly described as the prior 12 months), adequately implemented recognized security practices when making determinations related to fines, audits, and corrective actions. This consideration mitigates but does not eliminate enforcement exposure and does not by itself establish HIPAA compliance. HICP is limited to cybersecurity practice guidance and does not address the full scope of Privacy Rule obligations, does not substitute for a Security Rule risk analysis, and may not reflect additional requirements imposed by state law or other frameworks; readers should verify statutory citations, effective dates, and the current HICP edition against authoritative sources.

Why it matters

Cyberattacks against healthcare organizations are not merely IT problems; they can disrupt clinical operations and, in the most serious cases, threaten patient safety. HICP matters because it translates the healthcare sector's most pressing cyber threats into practical, voluntary recommendations that organizations of different sizes can act on. Because the guidance is free and published through the HHS 405(d) Program, it lowers the barrier for smaller and under-resourced providers to adopt baseline cyber hygiene without purchasing a proprietary framework.

HICP also carries weight in the HIPAA enforcement context, even though it is not itself a HIPAA rule. HICP is expressly identified as an example of a 'recognized security practice' under Section 13412 of the HITECH Act (added by Public Law 116-321). Under that provision, when HHS OCR makes certain enforcement determinations, such as those related to fines, audits, and corrective actions, it is generally required to consider whether a regulated entity had adequately implemented recognized security practices for a specified preceding period (commonly described as the prior 12 months). Readers should verify the statutory citation, effective date, and the exact enforcement mechanics against authoritative HHS sources.

It is important to be precise about what this means. Implementing HICP can mitigate enforcement exposure, but it does not eliminate it, and it does not by itself establish HIPAA compliance. HICP is cybersecurity practice guidance; it does not substitute for a Security Rule risk analysis, does not address the full scope of Privacy Rule obligations, and may not reflect additional requirements imposed by state law or other frameworks. Organizations should treat HICP as a complement to, not a replacement for, their formal HIPAA compliance program.

Who it's relevant to

Security officers and IT teams
HICP offers a practical, sector-specific starting point for baseline cyber hygiene, with practices scaled to organization size. Security teams can use it to inform their defenses against common healthcare threat vectors, but should treat it as guidance that complements, rather than replaces, a required Security Rule risk analysis of ePHI.
Small healthcare providers and under-resourced organizations
Because HICP resources are free and include a volume oriented toward small organizations, they are especially useful for practices and facilities without large security budgets or dedicated staff. Adoption does not guarantee HIPAA compliance, but it can help establish reasonable cybersecurity practices.
Compliance and privacy officers
HICP is relevant to enforcement strategy because it is identified as an example of a recognized security practice under the HITECH Act, which OCR generally must consider for a specified preceding period when making certain enforcement determinations. Compliance teams should document implementation over time and verify the current enforcement mechanics against authoritative HHS sources.
Legal counsel and risk managers
Counsel should understand that implementing HICP can mitigate, but not eliminate, HIPAA enforcement exposure and does not by itself establish compliance. They should also account for additional requirements that may arise under state law or other frameworks beyond HIPAA and HICP.
Executives and boards
HICP frames cybersecurity as a patient-safety and organizational-risk issue, giving leadership a recognized reference point for investing in cyber hygiene. Leaders should confirm that adoption is tied to the organization's broader HIPAA compliance program rather than treated as a standalone assurance.

Inside HICP

HHS 405(d) Program Origin
HICP is voluntary cybersecurity guidance developed collaboratively by industry and government under the HHS 405(d) Program, established pursuant to the Cybersecurity Act of 2015. It is not a regulation, an OCR enforcement mechanism, or a mandatory standard, but rather a set of consensus-based leading practices for the healthcare sector. Practitioners should verify current program details against HHS 405(d) materials.
Five Main Threat Vectors
HICP identifies five primary threats to the healthcare industry that its practices are designed to mitigate. These commonly include email-related threats (such as phishing), ransomware, loss or theft of equipment or data, insider threats (accidental or intentional), and attacks against connected medical devices. Readers should confirm the exact framing against the current HICP publication.
Ten Cybersecurity Practices
HICP presents ten recommended cybersecurity practices mapped against the identified threats. These generally address areas such as email protection, endpoint protection, access management, data protection and loss prevention, asset management, network management, vulnerability management, incident response, medical device security, and cybersecurity governance/policies. Specific sub-recommendations vary by organization size.
Audience-Specific Technical Volumes
HICP is structured with a main document plus technical volumes tailored to organization size, typically one for small healthcare organizations and one for medium and large organizations. This tiering acknowledges that resources and complexity differ across the sector, so recommended implementations are scaled accordingly.
Recognized Security Practices and HITECH Section 13412
HICP is expressly identified as a source of 'recognized security practices' under Section 13412 of the HITECH Act, added by Public Law 116-321 (signed January 5, 2021). Under this provision, when HHS OCR makes certain determinations regarding HIPAA Security Rule enforcement, it must consider whether a regulated entity had adequately demonstrated implementation of recognized security practices for the preceding 12 months. This can mitigate fines, reduce the extent of audits, and inform corrective action, but it is not a complete safe harbor and does not itself establish HIPAA compliance.
Relationship to HIPAA and Other Frameworks
HICP is distinct from the HIPAA Security Rule itself; it is guidance that can support Security Rule compliance efforts but does not replace the required and addressable implementation specifications of the rule. Implementing HICP is voluntary. It is also separate from private frameworks such as the HITRUST CSF. State law and other authorities may impose additional requirements beyond what HICP addresses.

Common questions

Answers to the questions practitioners most commonly ask about HICP.

Does implementing HICP make an organization HIPAA compliant or carry its own enforcement authority?
No. HICP is voluntary cybersecurity guidance developed under the HHS 405(d) Program, not a regulation and not an OCR enforcement or penalty mechanism. Implementing HICP does not by itself establish HIPAA Security Rule compliance, which is a separate obligation enforced by HHS OCR. HICP can support an organization's security posture, but covered entities and business associates must still meet the applicable requirements of the Security Rule and any other relevant authorities. Organizations should verify their obligations against the current regulatory text rather than treating adoption of HICP as a compliance guarantee.
Is HICP the same as HITRUST or a certifiable control framework?
No. HICP is free, voluntary guidance published under the HHS 405(d) Program and is not a certifiable framework. HITRUST is a separate private organization, and the HITRUST CSF is a certifiable control framework offered by that organization. Neither HICP nor HITRUST certification is a legal requirement, and neither by itself demonstrates HIPAA compliance. Organizations sometimes use these resources alongside their compliance efforts, but they serve different purposes and carry no regulatory authority of their own.
How does implementing HICP interact with OCR enforcement?
HICP is expressly identified as a 'recognized security practice' under Section 13412 of the HITECH Act, added by Public Law 116-321. Under that provision, when OCR is determining fines, conducting audits, or shaping corrective-action plans, it is directed to consider whether an entity had recognized security practices in place for the preceding 12 months. This can mitigate but does not eliminate enforcement outcomes, and it does not create a defense against liability. Readers should confirm the specifics and any implementing guidance against the current regulatory text.
How is HICP structured, and which volume applies to my organization?
HICP generally identifies a set of primary threat vectors facing the health sector and a corresponding set of cybersecurity practices, presented across audience-specific technical volumes oriented toward small organizations and toward medium and large organizations. Organizations typically select the volume that matches their size and complexity. Because the precise content, threat lists, and practice sets are updated over time, readers should verify the current structure and applicable volume against the latest published version of HICP.
How can an organization document that it has implemented recognized security practices?
In most cases, an organization would maintain evidence showing which recognized security practices it adopted and that they were in place over the relevant look-back period, such as policies, configuration records, risk analyses, training documentation, and change history. Because OCR is directed to consider the preceding 12 months of implementation, contemporaneous and dated documentation is generally more useful than after-the-fact reconstruction. Organizations should confirm current expectations and any required evidence against applicable OCR guidance, since specifics may change over time.
Where does HICP fit alongside the HIPAA Security Rule risk analysis requirement?
HICP is a source of practices an organization may choose to adopt, but it does not replace the Security Rule's own requirements, including the required risk analysis. The Security Rule applies to electronic protected health information and includes administrative, physical, and technical safeguards, with implementation specifications that are either required or addressable, and addressable does not mean optional. An organization would typically use its risk analysis to determine which safeguards and, where relevant, which HICP practices are reasonable and appropriate for its environment. Verify current requirements against the applicable regulatory text.

Common misconceptions

Adopting HICP makes an organization HIPAA compliant or provides a complete legal safe harbor from OCR penalties.
HICP is voluntary guidance, not a compliance certification. Under HITECH Section 13412, OCR must consider an entity's implementation of recognized security practices over the prior 12 months when making certain enforcement determinations, which may reduce fines or audit scope. However, this is a mitigating consideration, not a guarantee against penalties, and it does not by itself establish compliance with the HIPAA Security Rule's required and addressable specifications.
HICP is an enforcement or penalty program administered as a regulatory mandate.
HICP was developed as voluntary consensus guidance under the HHS 405(d) Program and carries no independent enforcement authority. HIPAA enforcement authority rests with HHS OCR. HICP's only formal enforcement-related role is that its practices can be recognized as 'recognized security practices' that OCR must consider under HITECH Section 13412.
HICP is a one-size-fits-all document that applies uniformly to every organization.
HICP is structured with technical volumes tailored to organization size, generally one for small organizations and one for medium and large organizations, so recommended practices are meant to be scaled to an organization's resources, complexity, and risk profile.

Best practices

Map your organization's environment against HICP's five identified threat vectors and the ten recommended practices, using the technical volume that matches your organization's size (small versus medium/large).
Document your implementation of recognized security practices on an ongoing basis, since HITECH Section 13412 directs OCR to consider such practices for the preceding 12 months; maintain evidence of continuous, not point-in-time, adoption.
Treat HICP as supplementary to, not a substitute for, a HIPAA Security Rule risk analysis and the rule's required and addressable implementation specifications; verify that Security Rule obligations are independently satisfied.
Coordinate HICP adoption with your privacy, security, and legal teams so that recognized security practices are demonstrable if OCR conducts an audit or investigation, while recognizing this does not guarantee avoidance of penalties.
Confirm you are working from the current version of HICP and current HHS 405(d) materials, as threat framing and recommended practices are updated over time.
Assess whether state law, other federal authorities, or private frameworks such as the HITRUST CSF impose additional requirements beyond those addressed by HICP, and address any gaps accordingly.