Since launching in March, the RISC 2.0 cybersecurity module has helped hundreds of facilities benchmark their defenses—and revealed where healthcare still falls short.
By Alyx Arnett
When the Administration for Strategic Preparedness and Response (ASPR), a division of the US Department of Health and Human Services, added a cybersecurity module to its Risk Identification and Site Criticality (RISC) 2.0 Toolkit in March, the goal was to give healthcare and public health organizations a standards-based way to measure their cyber readiness alongside other hazards. Six months later, the ASPR says uptake has been steady, and the assessment is beginning to expose the vulnerabilities that healthcare organizations most often fail to address.
The module scores users against the Healthcare and Public Health Cybersecurity Performance Goals (CPGs) and the NIST Cybersecurity Framework 2.0, giving facilities a way to identify gaps, prioritize spending, and compare cyber risk against other threats already tracked in RISC. According to ASPR, 366 facilities have been added to the RISC Toolkit since the module launched, and 266 have completed the cybersecurity assessment—a sign, the agency says, of pent-up demand among healthcare technology management (HTM) and IT teams for a free, objective benchmarking tool.
“The idea for a dedicated cybersecurity module in our RISC 2.0 platform came from listening to those on the ground in our healthcare and public health systems on what they truly needed,” an ASPR spokesperson says. “Recently, cyber attacks have consistently been ranking as a top threat of concern for our healthcare and public health sector.”
Where Organizations Are Falling Short
Early data from completed assessments points to a consistent pattern of weak spots. ASPR says the top vulnerability-tackling tactics that healthcare organizations struggle with most, from highest to lowest, are network segmentation, third-party incident reporting, third-party vulnerability disclosure, and vendor and supplier cyber requirements.
Network segmentation—separating critical assets to minimize lateral movement within an environment by threat actors—tops the list. The other three all center on managing risk introduced by outside parties, an area of particular relevance to HTM teams that oversee connected medical devices sourced from a wide range of vendors.
“A healthcare facility is only as cyber secure as their weakest vendor or connected device,” the spokesperson says.
A Tiered Approach for Stretched Teams
ASPR acknowledges that many organizations lack the staff or budget to address every finding at once. That’s why the CPGs are divided into essential and enhanced goals. The essential tier is aimed at organizations with limited resources—”a rural healthcare clinic with only one part-time IT worker who doubles as front desk support, a small pharmacy just getting started,” the spokesperson says.
The tiering is meant to give smaller facilities a defensible starting point rather than an all-or-nothing checklist.
“‘Doing cybersecurity’ is not a light switch that can be turned on,” the spokesperson says. “Staying cyber secure is something you build up each day and every step counts.”
Signs of Resilience—and Persistent Pressure
Asked how the sector’s overall posture looks in 2026, ASPR describes early but incomplete signs of progress. The spokesperson points to conversations with organizations that recovered more quickly from attacks because they had properly segmented backups, or resumed care faster because downtime procedure checklists told staff where to find items such as prescription pad lockbox keys.
Still, ASPR says the sector remains in what the spokesperson calls “an ongoing constant battle in this arms race.” Looking ahead, the agency expects attacks to continue advancing in sophistication, with defenders needing to keep pace by adopting new technologies, including AI, and by building relationships with response partners before an incident occurs.
“‘Hoping’ it probably won’t happen to you is not strategy,” the spokesperson says.
ID 332370105 © Dilok Klaisataporn | Dreamstime.com
Alyx Arnett is chief editor of 24×7 Magazine. Questions or comments? Email [email protected].
The last two paragraphs pretty much sums things up.
“ … the sector remains in what the spokesperson calls “an ongoing constant battle in this arms race … the agency expects attacks to continue advancing in sophistication, with defenders needing to keep pace by adopting new technologies, including AI, and by building relationships with response partners before an incident occurs.
“‘Hoping’ it probably won’t happen to you is not strategy,”
Agreed, hoping is not strategy. But is it sufficient to stay behind the scenes and react to every move by Silicon Valley?
I was unsuccessful while I was working in drawing attention to the risks posed by the accelerating rate of change of technology, the primary one of which is discerning how to adopt, and adapt to, changes in technology at the limited rate posed by human capability.
CE/HTM knows this, or at least used to know it. I see no evidence that it’s voicing that message in a manner that will get others to listen.
The warning of the movie “War Games” extends beyond nuclear war: The only way to win is not to play.
The public needs to know the challenges and the consequential risks they pose. They will not recognize their seriousness if they only get discussed within the community.
Silicon Valley has its hands full right now with dealing with the public response to the proliferation of data centers and, to a lesser extent, job displacement. When the public learns of significant risks, it responds.