Skip to main content
Framework library
Framework module · hicp-2023

Health Industry Cybersecurity Practices

HICP 2023 is voluntary healthcare-sector guidance on common cyber threats, recommended practices, and patient-safety-oriented resilience for organizations of different sizes.

2023 edition · HHS 405(d) Program

Standing today
Directory entry

00Answer

from the registry record
What is Health Industry Cybersecurity Practices?
HICP 2023 is voluntary healthcare-sector guidance on common cyber threats, recommended practices, and patient-safety-oriented resilience for organizations of different sizes.
Who does Health Industry Cybersecurity Practices apply to?
Health Industry Cybersecurity Practices applies to healthcare, public health, US, per HHS 405(d) Program.
What is the current version of Health Industry Cybersecurity Practices?
The current edition is 2023 edition, issued by HHS 405(d) Program. Source: https://hhscyber.hhs.gov/cornerstone-hicp.html.
What does an assessment under Health Industry Cybersecurity Practices require?
No control catalog has been ingested for Health Industry Cybersecurity Practices yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

Health Industry Cybersecurity Practices is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Metadata only; HICP practices and sub-practices have not been normalized into a guidance profile.

02Registry record

checked 2026-08-28
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Threats · Practices for small organizations · Practices for medium and large organizations · Patient safety
Applies to
healthcare · public health · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-28

03Version ledger

1 edition
2023 editionCurrent editiondate not published

06Related frameworks

scored from registry facts
  1. Also applies to healthcare · HHS's voluntary healthcare-specific priorities for high-impact cybersecurity practices. The goals are guidance for improving sector resilience, not a regulation or certification.

  2. 42 CFR Part 22024 final rule

    Also applies to healthcare · Confidentiality rules for substance use disorder treatment records, now aligned with HIPAA on consent, notice, and enforcement.

  3. HIPAA Security Rule45 CFR Part 164 Subparts A and C

    Also applies to healthcare · The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.

  4. Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

Health Industry Cybersecurity Practices | ControlFrame