What Are Health Industry Cybersecurity Practices (HICP)?
Continuum GRC, Inc.
Your Roadmap to Risk Reduction is just 2 clicks away with Continuum GRC!
Any organization in the healthcare industry knows that cybersecurity is a critical component of doing business. So much so, in fact, that any enterprise handling protected health information (PHI) must implement and maintain strict cybersecurity and privacy controls to protect patient data from unauthorized disclosure.?
However, understanding that HIPAA is a requirement for operation doesn't necessarily make compliance or effective cybersecurity much easier to implement. That's why an initiative conceived by government agencies, known as the Health Industry Cybersecurity Practices (HICP), was put into action to align security along with government and industry best practices.?
What is HICP?
In 2015, Congress passed the Cybersecurity Act as a way to align federal, state and local agencies concerning how they share and store information. This legislation was massive in scope and attempted to draw together laws regulating a significant number of agencies and businesses in several industries to promote best practices.?
Part of this law, Section 405(d), "Aligning Health Care Industry Security Approaches," mandates the creation of a 405(d) Task Group to create a set of voluntary and consensus-based cybersecurity guidelines and processes that support enterprises in the healthcare industry. The three core goals of this Task Group are:
This group came together for the first time in 2017 with a steering committee comprised of members from:
And others.?
Furthermore, several representatives from other agencies and private companies make up the remaining group membership, including members from organizations like:
The guidelines published by this Task Group, free of charge, are called the Health Industry Cybersecurity Practices.
领英推荐
What Are the HICP Standards?
At the heart of HICP is the understanding that a standard set of basic and effective cybersecurity practices can serve the greater good of protecting patient information and supporting the three primary goals listed above.?
To outline these standards, the 405(d) publishes two separate documents, titled "Technical Volume 1" and "Technical Volume 2". These two documents, by and large, outline the same practices, with slight differences for mid-sized to enterprise organizations ("Volume 1") and for small practices ("Volume 2").?
Across both documents, ten distinct practices are defined. These are:
Protecting PHI and Meeting Security and Risk in Healthcare with Continuum GRC
HIPC isn't about compliance or mandatory regulations–it's a set of best practices that you should be following if you're in the healthcare industry
Continuum GRC provides critical security assessments, compliance support and risk management tools to support your organization's healthcare cybersecurity efforts. This can apply to your approach to HICP suggestions and even HIPAA requirements.?
Continuum GRC is cloud-based, always available and plugged into our team of experts. We provide risk management and compliance support for every major regulation and compliance framework on the market, including:
And more. We are also the only FedRAMP and StateRAMP authorized compliance and risk management solution in the world.
Looking to Get Started with HICP and HIPAA?
Continuum GRC is proactive cyber security?, and the only FedRAMP ans StateRAMP Authorized cybersecurity audit platform in the world. Call 1-888-896-6207 to discuss your organization’s cybersecurity needs and find out how we can help your organization protect its systems and ensure compliance.