Skip to main content
Framework library
Framework module · hhs-hph-cybersecurity-performance-goals

HHS HPH Cybersecurity Performance Goals

HHS's voluntary healthcare-specific priorities for high-impact cybersecurity practices. The goals are guidance for improving sector resilience, not a regulation or certification.

Current HPH CPGs · U.S. Department of Health and Human Services

Standing today
Directory entry

00Answer

from the registry record
What is HHS HPH Cybersecurity Performance Goals?
HHS's voluntary healthcare-specific priorities for high-impact cybersecurity practices. The goals are guidance for improving sector resilience, not a regulation or certification.
Who does HHS HPH Cybersecurity Performance Goals apply to?
HHS HPH Cybersecurity Performance Goals applies to healthcare, public health, US, per U.S. Department of Health and Human Services.
What is the current version of HHS HPH Cybersecurity Performance Goals?
The current edition is Current HPH CPGs, issued by U.S. Department of Health and Human Services. Source: https://hhscyber.hhs.gov/cybersecurity-performance-goals.html.
What does an assessment under HHS HPH Cybersecurity Performance Goals require?
No control catalog has been ingested for HHS HPH Cybersecurity Performance Goals yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

HHS HPH Cybersecurity Performance Goals is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Metadata only; the voluntary goals and their HICP/NIST references have not been normalized into a guidance profile.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Essential goals · Enhanced goals · Cyber resilience · Patient safety
Applies to
healthcare · public health · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28

03Version ledger

1 edition
Current HPH CPGsCurrent editiondate not published

06Related frameworks

scored from registry facts
  1. Also applies to healthcare · HICP 2023 is voluntary healthcare-sector guidance on common cyber threats, recommended practices, and patient-safety-oriented resilience for organizations of different sizes.

  2. 42 CFR Part 22024 final rule

    Also applies to healthcare · Confidentiality rules for substance use disorder treatment records, now aligned with HIPAA on consent, notice, and enforcement.

  3. Shared Assessments SIG2026 annual release

    Also applies to healthcare · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.

  4. HIPAA Security Rule45 CFR Part 164 Subparts A and C

    Also applies to healthcare · The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.

HHS HPH Cybersecurity Performance Goals | ControlFrame