Skip to main content
Category: Governance and Workforce

Health Sector Coordinating Council

Also known as: HSCC, Healthcare and Public Health Sector Coordinating Council, HPH Sector Coordinating Council, HPH SCC
Simply put

The Health Sector Coordinating Council (HSCC) is a coalition of private-sector healthcare and public health organizations that work together, and with government partners, to address cybersecurity and physical security risks facing the healthcare sector. It publishes voluntary best-practice guidance intended to help healthcare organizations improve their security posture. It is an industry collaboration body, not a government regulator, and its guidance is not itself a legal requirement under HIPAA.

Formal definition

The Healthcare and Public Health Sector Coordinating Council (HSCC) is a chartered coalition of private-sector industry associations and their members with equities in the Healthcare and Public Health (HPH) critical infrastructure sector. Its stated mission is to identify cyber and physical risks to the security and resiliency of the sector, develop guidance for mitigating those risks, and coordinate with government partners; much of this work is carried out through bodies such as the HSCC Cybersecurity Working Group. HSCC produces voluntary best-practice publications (referenced by federal partners such as CISA) rather than binding regulation. Practitioners should note that HSCC is distinct from HHS OCR, which enforces HIPAA, and that adopting HSCC guidance does not by itself establish or guarantee HIPAA compliance; HIPAA obligations arise from the applicable regulatory text and attach to covered entities and business associates through their defined relationships. Readers should verify the current scope and specific publications of HSCC against its official materials.

Why it matters

Healthcare organizations face persistent cyber and physical security threats, and much of the practical, sector-specific guidance available to them comes not from regulators but from industry collaboration. The HSCC fills this role by convening private-sector healthcare and public health stakeholders to identify shared risks and develop voluntary best-practice publications. For compliance and security officers, HSCC materials can be a useful reference point for benchmarking practices and understanding what peer organizations and government partners consider reasonable approaches to sector risks.

A key distinction to keep in mind is that HSCC is an industry coordinating body, not a government regulator. Its guidance is voluntary and does not carry the force of law. HIPAA obligations are enforced by HHS OCR and arise from the applicable regulatory text; they attach to covered entities and business associates through their defined relationships. Adopting HSCC guidance does not by itself establish or guarantee HIPAA compliance, and organizations should not treat HSCC publications as a substitute for meeting Security Rule, Privacy Rule, or Breach Notification Rule requirements.

That said, the fact that federal partners such as CISA reference HSCC best-practice publications gives them practical weight. Aligning with recognized sector guidance can support an organization's broader security program and may help demonstrate that reasonable and appropriate measures are being considered. Readers should verify the current scope and specific publications of HSCC against its official materials, and remain aware that state law, the HITECH Act, and other frameworks may impose requirements beyond anything addressed in HSCC guidance.

Who it's relevant to

Healthcare Security and Compliance Officers
Security and privacy officers can use HSCC best-practice publications as a reference when designing or benchmarking their security programs. These materials can inform decisions about reasonable and appropriate safeguards, but they do not replace the organization's own risk analysis or its obligations under the HIPAA Security and Privacy Rules, which are enforced by HHS OCR.
Industry Associations and Sector Stakeholders
The HSCC is itself composed of industry associations and their members with equities in the HPH sector. Organizations that participate in or align with the council contribute to and benefit from collaborative guidance development and coordination with government partners on cyber and physical risks.
Business Associates and Vendors
Vendors serving healthcare clients may find HSCC guidance helpful for understanding sector expectations. However, their binding HIPAA obligations flow through business associate agreements and the applicable regulatory text, not from HSCC publications. Following HSCC guidance does not by itself satisfy those contractual or regulatory duties.
IT and Cybersecurity Professionals
Technical staff can draw on HSCC and CISA-referenced publications for practical approaches to healthcare cybersecurity. These resources complement, rather than substitute for, the administrative, physical, and technical safeguards required by the HIPAA Security Rule for electronic protected health information.

Inside HSCC

Public-Private Partnership Structure
The Health Sector Coordinating Council (HSCC) is a collaborative body bringing together private-sector healthcare organizations and government partners to address critical infrastructure security and resilience within the healthcare and public health sector. It functions as a coordinating forum rather than a regulatory or enforcement authority.
Cybersecurity Working Groups
The HSCC typically organizes working groups that develop voluntary guidance, leading practices, and consensus resources aimed at improving cybersecurity posture across healthcare organizations. These outputs are advisory in nature and do not carry the force of law.
Sector Coordination Role
As a Sector Coordinating Council under the broader critical infrastructure protection model, it serves as a mechanism for information sharing and coordination between the healthcare sector and federal partners. It does not itself administer HIPAA, which remains enforced by HHS OCR.
Voluntary Guidance and Resources
The materials produced generally take the form of recommended practices, toolkits, and frameworks that organizations may adopt to strengthen security and resilience. Adoption is voluntary and supplemental to, not a substitute for, applicable regulatory obligations.

Common questions

Answers to the questions practitioners most commonly ask about HSCC.

Does participation in the Health Sector Coordinating Council make an organization HIPAA compliant?
No. The Health Sector Coordinating Council (HSCC) is a public-private partnership focused on critical infrastructure security and resilience for the healthcare and public health sector; it is not a regulatory body. HIPAA compliance is a separate matter governed by the HIPAA Rules and enforced by HHS OCR. Engaging with HSCC or using materials it develops does not, by itself, establish compliance with the Privacy Rule, Security Rule, or any other HIPAA requirement. Organizations must still meet their obligations under the applicable regulatory text independently.
Are the guidance documents and best practices produced by the Health Sector Coordinating Council legally binding requirements?
Generally, no. The HSCC develops voluntary guidance, leading practices, and consensus resources intended to help the sector improve cybersecurity and resilience. These outputs are typically advisory rather than mandatory. They do not carry the force of law in the way the HIPAA Rules do, and following them does not replace the need to comply with HIPAA or with any applicable state law, HITECH Act provisions, or other frameworks that may impose additional requirements. Readers should not treat HSCC materials as a substitute for verifying obligations against current regulation.
How does the Health Sector Coordinating Council relate to an organization's HIPAA Security Rule program?
The HSCC's focus on sector cybersecurity can inform, but does not define, a HIPAA Security Rule program. The Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards for ePHI, including required and addressable implementation specifications. HSCC voluntary resources may be a useful reference when developing or benchmarking those safeguards, but each organization remains responsible for conducting its own risk analysis and satisfying the Security Rule's specific requirements as written in the current regulatory text.
Can our organization use HSCC resources when developing internal security policies?
Organizations may choose to reference HSCC voluntary guidance and leading practices as one input when developing internal security policies. Because these materials are advisory, they should be adapted to the organization's own environment, risk profile, and regulatory obligations. Any policy work should be validated against the actual requirements of the applicable HIPAA Rules and any relevant state law or other frameworks, rather than relying on HSCC materials alone to demonstrate that a requirement has been met.
Who is eligible to participate in the Health Sector Coordinating Council?
The HSCC is structured as a public-private partnership involving healthcare and public health sector stakeholders. Because participation structures, membership categories, and eligibility can change over time, organizations interested in involvement should confirm the current participation criteria and processes directly through the HSCC's official channels rather than relying on general descriptions.
Should HSCC involvement replace working with legal counsel or compliance staff on HIPAA matters?
No. HSCC involvement is not a substitute for the compliance and legal functions that support HIPAA obligations. Determining how the Privacy Rule, Security Rule, Breach Notification Rule, and Enforcement Rule apply to a specific organization, and how state law or the HITECH Act may add requirements, typically requires qualified compliance and legal review. HSCC resources can supplement that work as sector-level guidance but do not carry regulatory authority in place of it.

Common misconceptions

Following HSCC guidance means an organization is HIPAA compliant.
HSCC guidance is voluntary and advisory. It may help inform an organization's security program, but it does not establish or guarantee compliance with the HIPAA Security Rule, Privacy Rule, or Breach Notification Rule. HIPAA compliance is determined against the applicable regulatory text and is enforced by HHS OCR. Readers should verify their obligations against the current regulation.
The HSCC is a government regulator that can enforce requirements or impose penalties.
The HSCC is a coordinating council operating as a public-private partnership, not a regulatory or enforcement authority. It does not issue penalties or legally binding requirements. Enforcement of HIPAA rests with HHS OCR, and its outputs generally function as voluntary recommendations.
HSCC resources address all of a healthcare organization's compliance needs.
HSCC materials are typically focused on cybersecurity and sector resilience and are supplemental in nature. They do not cover the full scope of HIPAA's requirements, and state law, the HITECH Act, or other frameworks may impose additional obligations beyond anything the HSCC addresses.

Best practices

Treat HSCC guidance as a supplemental resource that may inform your security program, while relying on the current HIPAA regulatory text and HHS OCR guidance to determine your actual compliance obligations.
When adopting voluntary HSCC leading practices, map them against your Security Rule safeguards (administrative, physical, and technical) so you can distinguish advisory recommendations from your required and addressable implementation specifications.
Confirm that participation in or adoption of HSCC resources is not being mistaken internally for evidence of HIPAA compliance, and document how any adopted practices connect to your formal risk analysis and compliance program.
Verify the applicability of any HSCC resource to your organization's role, distinguishing obligations that attach to you as a covered entity versus as a business associate or subcontractor through your business associate agreements.
Check whether state law, the HITECH Act, or other frameworks impose requirements beyond those addressed by HSCC guidance, since HSCC materials generally do not capture the full compliance landscape.
Periodically revisit HSCC outputs against their current versions and against current regulatory guidance, since voluntary guidance and regulatory expectations both evolve over time.