HHS HPH Cybersecurity Performance Goals
HHS's voluntary healthcare-specific priorities for high-impact cybersecurity practices. The goals are guidance for improving sector resilience, not a regulation or certification.
Current HPH CPGs · U.S. Department of Health and Human Services
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
HHS HPH Cybersecurity Performance Goals is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Metadata only; the voluntary goals and their HICP/NIST references have not been normalized into a guidance profile.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Essential goals · Enhanced goals · Cyber resilience · Patient safety
- Applies to
- healthcare · public health · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-28
03Version ledger
| Current HPH CPGs | Current edition | date not published |
06Related frameworks
- Health Industry Cybersecurity Practices2023 edition
Also applies to healthcare · HICP 2023 is voluntary healthcare-sector guidance on common cyber threats, recommended practices, and patient-safety-oriented resilience for organizations of different sizes.
- 42 CFR Part 22024 final rule
Also applies to healthcare · Confidentiality rules for substance use disorder treatment records, now aligned with HIPAA on consent, notice, and enforcement.
- Shared Assessments SIG2026 annual release
Also applies to healthcare · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.
- HIPAA Security Rule45 CFR Part 164 Subparts A and C
Also applies to healthcare · The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.