Berlin – The U.S. Department of Health and Human Services (HHS) is bolstering the nation’s healthcare cybersecurity defenses with the launch of a novel module within its Risk Identification and Site Criticality (RISC) 2.0 Toolkit. Released on March 5, 2026, by the Administration for Strategic Preparedness and Response (ASPR), this addition provides health systems with a standardized method for evaluating cyber risks alongside existing hazard assessments, a critical step in protecting patient data and ensuring continuity of care. The increasing sophistication and frequency of cyberattacks targeting healthcare organizations necessitate proactive and comprehensive security measures, and this toolkit aims to provide a crucial resource in that effort.
The healthcare sector has become a prime target for cybercriminals due to the sensitive nature of patient information and the potential for disruption of essential services. Ransomware attacks, in particular, have crippled hospitals and healthcare providers, leading to canceled appointments, diverted ambulances, and, in some cases, compromised patient safety. According to the HHS, the healthcare sector faces a growing threat landscape, requiring a coordinated and standardized approach to cybersecurity risk management. The new RISC 2.0 module is designed to address this challenge by offering a structured framework for identifying vulnerabilities and prioritizing security investments.
The new cybersecurity module functions by guiding users through a detailed questionnaire focused on organizational policies and practices. Responses are then scored against two key frameworks: the National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0 and the HHS Cybersecurity Performance Goals. This standards-based scoring system allows organizations to pinpoint critical gaps in their security posture, effectively allocate resources, and make informed decisions regarding risk mitigation strategies. The NIST Cybersecurity Framework 2.0, released in February 2024, provides a comprehensive and adaptable framework for managing and reducing cybersecurity risk, while the HHS Cybersecurity Performance Goals offer a set of prioritized actions for healthcare organizations to enhance their cybersecurity resilience.
RISC 2.0: A Widely Adopted Risk Assessment Platform
RISC 2.0, a free, web-based platform developed by ASPR, already serves as a valuable tool for over 3,500 health systems across the country. It enables organizations to conduct thorough risk assessments by identifying potential threats, evaluating vulnerabilities, determining potential consequences, and sharing findings with relevant stakeholders. The platform’s integration of the new cyber module allows facilities, health systems, and healthcare coalitions to analyze cyber risk within the same environment they currently utilize for assessing other hazards, such as natural disasters or public health emergencies. This unified approach streamlines the risk management process and facilitates a more holistic understanding of potential vulnerabilities.
Organizations have the flexibility to complete the cyber module independently or alongside other RISC 2.0 risk assessments, tailoring the process to their specific needs and priorities. This adaptability is crucial, as healthcare organizations vary significantly in size, complexity, and the types of services they provide. The module’s design acknowledges this diversity and allows organizations to focus on the areas of greatest concern. The ASPR emphasizes that the RISC 2.0 toolkit is intended to be a collaborative resource, encouraging information sharing and cooperation among healthcare providers to strengthen the overall cybersecurity posture of the sector.
The Role of HHS and ASPR in Healthcare Cybersecurity
The Department of Health and Human Services (HHS) serves as the Sector Risk Management Agency for the Healthcare and Public Health Sector, a critical role in coordinating cybersecurity efforts across the industry. Within HHS, the Administration for Strategic Preparedness and Response (ASPR) is responsible for coordinating these activities and providing guidance to both public and private sector partners. ASPR’s mission is to prepare the nation to respond to a wide range of public health emergencies, including those caused by cyberattacks. The launch of the RISC 2.0 cyber module is a direct reflection of ASPR’s commitment to enhancing the cybersecurity resilience of the healthcare sector.
The HHS has been increasingly focused on addressing cybersecurity threats in recent years, recognizing the potential for significant disruption to healthcare delivery. In 2023, the HHS released the Health Sector Cybersecurity Coordination Center (HSCC) updated cybersecurity video training series to help healthcare organizations improve their security practices. The agency has been working to address gaps in cybersecurity preparedness through various initiatives, including the development of model contract language for medical device cybersecurity and efforts to bridge the cybersecurity skills gap within the healthcare workforce. These initiatives demonstrate a comprehensive approach to cybersecurity, encompassing training, resource development, and workforce development.
Understanding the NIST Cybersecurity Framework 2.0
The NIST Cybersecurity Framework 2.0, upon which the RISC 2.0 module is partially based, provides a structured approach to managing cybersecurity risk. It is organized around five core functions: Identify, Protect, Detect, Respond, and Recover. Each function encompasses a set of categories and subcategories that provide detailed guidance on specific security measures. The framework is designed to be flexible and adaptable, allowing organizations to tailor it to their specific needs and risk profiles. More information about the NIST Cybersecurity Framework 2.0 is available on the NIST website. The framework’s emphasis on continuous improvement and ongoing risk assessment is particularly relevant in the rapidly evolving cybersecurity landscape.
The HHS Cybersecurity Performance Goals, also integrated into the RISC 2.0 module, provide a more targeted set of actions for healthcare organizations. These goals focus on essential cybersecurity practices, such as implementing multi-factor authentication, conducting regular vulnerability scans, and developing incident response plans. Details on the HHS Cybersecurity Performance Goals can be found on the HHS website. By aligning with these goals, healthcare organizations can demonstrate a commitment to cybersecurity best practices and reduce their risk of falling victim to cyberattacks.
Accessing the RISC 2.0 Cyber Module
Healthcare organizations interested in utilizing the new cybersecurity module within the RISC 2.0 Toolkit can uncover additional information and access the platform at aspr.hhs.gov/RISC. The platform is freely available to all healthcare organizations, regardless of size or location. ASPR encourages organizations to leverage this resource to proactively assess their cybersecurity risks and implement appropriate mitigation strategies. The agency also provides technical assistance and support to organizations as they navigate the risk assessment process.
The launch of this module represents a significant step forward in strengthening the cybersecurity posture of the U.S. Healthcare system. By providing a standardized and accessible tool for risk assessment, HHS and ASPR are empowering healthcare organizations to better protect themselves against the growing threat of cyberattacks. The ongoing commitment to collaboration and information sharing will be crucial in ensuring the continued resilience of the healthcare sector in the face of evolving cyber threats.
Key Takeaways
- The HHS has launched a new cybersecurity module within the RISC 2.0 Toolkit to help healthcare organizations assess cyber risks.
- The module uses the NIST Cybersecurity Framework 2.0 and HHS Cybersecurity Performance Goals as benchmarks.
- RISC 2.0 is a free, web-based platform used by over 3,500 health systems.
- The HHS serves as the Sector Risk Management Agency for the Healthcare and Public Health Sector, coordinating cybersecurity efforts.
Looking ahead, the ASPR will continue to monitor the cybersecurity landscape and provide guidance to healthcare organizations as new threats emerge. The agency is also exploring opportunities to enhance the RISC 2.0 Toolkit with additional features and capabilities. Regular updates and improvements to the toolkit will be essential to ensure its continued relevance and effectiveness. We encourage readers to share their experiences with the RISC 2.0 toolkit and to contribute to the ongoing dialogue about healthcare cybersecurity.
- How OBBBA and Federal Policy Shifts Are Threatening Hospital Financial Stability: Urban Institute Report
- Lung Cancer: How Stigma, Fear, and Guilt Delay Life-Saving Diagnosis
- Havenwood Heritage Heights Concord NH: Fitness Centers, Outdoor Activities, and Health Services for Seniors (news-usa.today)
- PCOS to PMOS: Why the Name Change Matters for Women’s Health (archynewsy.com)