Since launching in March, the RISC 2.0 cybersecurity module has helped hundreds of facilities benchmark their defenses—and revealed where healthcare still falls short.
By Alyx Arnett
When the Administration for Strategic Preparedness and Response (ASPR), a division of the US Department of Health and Human Services, added a cybersecurity module to its Risk Identification and Site Criticality (RISC) 2.0 Toolkit in March, the goal was to give healthcare and public health organizations a standards-based way to measure their cyber readiness alongside other hazards. Six months later, the ASPR says uptake has been steady, and the assessment is beginning to expose the vulnerabilities that healthcare organizations most often fail to address.
The module scores users against the Healthcare and Public Health Cybersecurity Performance Goals (CPGs) and the NIST Cybersecurity Framework 2.0, giving facilities a way to identify gaps, prioritize spending, and compare cyber risk against other threats already tracked in RISC. According to ASPR, 366 facilities have been added to the RISC Toolkit since the module launched, and 266 have completed the cybersecurity assessment—a sign, the agency says, of pent-up demand among healthcare technology management (HTM) and IT teams for a free, objective benchmarking tool.
“The idea for a dedicated cybersecurity module in our RISC 2.0 platform came from listening to those on the ground in our healthcare and public health systems on what they truly needed,” an ASPR spokesperson says. “Recently, cyber attacks have consistently been ranking as a top threat of concern for our healthcare and public health sector.”
Where Organizations Are Falling Short
Early data from completed assessments points to a consistent pattern of weak spots. ASPR says the top vulnerability-tackling tactics that healthcare organizations struggle with most, from highest to lowest, are network segmentation, third-party incident reporting, third-party vulnerability disclosure, and vendor and supplier cyber requirements.
Network segmentation—separating critical assets to minimize lateral movement within an environment by threat actors—tops the list. The other three all center on managing risk introduced by outside parties, an area of particular relevance to HTM teams that oversee connected medical devices sourced from a wide range of vendors.
“A healthcare facility is only as cyber secure as their weakest vendor or connected device,” the spokesperson says.
A Tiered Approach for Stretched Teams
ASPR acknowledges that many organizations lack the staff or budget to address every finding at once. That’s why the CPGs are divided into essential and enhanced goals. The essential tier is aimed at organizations with limited resources—”a rural healthcare clinic with only one part-time IT worker who doubles as front desk support, a small pharmacy just getting started,” the spokesperson says.
The tiering is meant to give smaller facilities a defensible starting point rather than an all-or-nothing checklist.
“‘Doing cybersecurity’ is not a light switch that can be turned on,” the spokesperson says. “Staying cyber secure is something you build up each day and every step counts.”
Signs of Resilience—and Persistent Pressure
Asked how the sector’s overall posture looks in 2026, ASPR describes early but incomplete signs of progress. The spokesperson points to conversations with organizations that recovered more quickly from attacks because they had properly segmented backups, or resumed care faster because downtime procedure checklists told staff where to find items such as prescription pad lockbox keys.
Still, ASPR says the sector remains in what the spokesperson calls “an ongoing constant battle in this arms race.” Looking ahead, the agency expects attacks to continue advancing in sophistication, with defenders needing to keep pace by adopting new technologies, including AI, and by building relationships with response partners before an incident occurs.
“‘Hoping’ it probably won’t happen to you is not strategy,” the spokesperson says.
ID 332370105 © Dilok Klaisataporn | Dreamstime.com
Alyx Arnett is chief editor of 24×7 Magazine. Questions or comments? Email [email protected].