Health Sector Coordinating Council
The Health Sector Coordinating Council (HSCC) is a coalition of private-sector healthcare and public health organizations that work together, and with government partners, to address cybersecurity and physical security risks facing the healthcare sector. It publishes voluntary best-practice guidance intended to help healthcare organizations improve their security posture. It is an industry collaboration body, not a government regulator, and its guidance is not itself a legal requirement under HIPAA.
The Healthcare and Public Health Sector Coordinating Council (HSCC) is a chartered coalition of private-sector industry associations and their members with equities in the Healthcare and Public Health (HPH) critical infrastructure sector. Its stated mission is to identify cyber and physical risks to the security and resiliency of the sector, develop guidance for mitigating those risks, and coordinate with government partners; much of this work is carried out through bodies such as the HSCC Cybersecurity Working Group. HSCC produces voluntary best-practice publications (referenced by federal partners such as CISA) rather than binding regulation. Practitioners should note that HSCC is distinct from HHS OCR, which enforces HIPAA, and that adopting HSCC guidance does not by itself establish or guarantee HIPAA compliance; HIPAA obligations arise from the applicable regulatory text and attach to covered entities and business associates through their defined relationships. Readers should verify the current scope and specific publications of HSCC against its official materials.
Why it matters
Healthcare organizations face persistent cyber and physical security threats, and much of the practical, sector-specific guidance available to them comes not from regulators but from industry collaboration. The HSCC fills this role by convening private-sector healthcare and public health stakeholders to identify shared risks and develop voluntary best-practice publications. For compliance and security officers, HSCC materials can be a useful reference point for benchmarking practices and understanding what peer organizations and government partners consider reasonable approaches to sector risks.
A key distinction to keep in mind is that HSCC is an industry coordinating body, not a government regulator. Its guidance is voluntary and does not carry the force of law. HIPAA obligations are enforced by HHS OCR and arise from the applicable regulatory text; they attach to covered entities and business associates through their defined relationships. Adopting HSCC guidance does not by itself establish or guarantee HIPAA compliance, and organizations should not treat HSCC publications as a substitute for meeting Security Rule, Privacy Rule, or Breach Notification Rule requirements.
That said, the fact that federal partners such as CISA reference HSCC best-practice publications gives them practical weight. Aligning with recognized sector guidance can support an organization's broader security program and may help demonstrate that reasonable and appropriate measures are being considered. Readers should verify the current scope and specific publications of HSCC against its official materials, and remain aware that state law, the HITECH Act, and other frameworks may impose requirements beyond anything addressed in HSCC guidance.
Who it's relevant to
Inside HSCC
Common questions
Answers to the questions practitioners most commonly ask about HSCC.