Skip to main content

HEALTHCARE COMPLIANCE

What Is HPH Cybersecurity Performance Goals (CPGs)?

DEFINITION

The HPH Cybersecurity Performance Goals (CPGs) are voluntary cybersecurity practices published by the US Department of Health and Human Services for the healthcare and public health sector. Split into Essential and Enhanced tiers, they cover practices such as multifactor authentication, email security, incident planning, and vendor risk management, and serve as a widely referenced baseline for healthcare cyber hygiene.

The HPH CPGs translate broad cybersecurity frameworks into a short, prioritized list of practices for healthcare organizations. The Essential goals cover the fundamentals that blunt the most common attacks, including multifactor authentication, basic email protections, credential revocation for departing staff, incident response planning, and mitigation of known exploited vulnerabilities. The Enhanced goals address more mature capabilities such as network segmentation, asset inventory, third-party vulnerability disclosure, and centralized log collection.

The CPGs are aimed at the entire healthcare and public health sector: hospitals, physician practices, payers, and the vendors that support them. They are voluntary today, but HHS has signaled that they inform its broader regulatory direction, and many of their themes appear in the proposed HIPAA Security Rule update, so treating them as optional indefinitely is a risky bet.

The practical value of the CPGs is speed. A resource-constrained security team can self-assess against roughly twenty concrete goals in days, not months, and the resulting gap list maps cleanly onto the risk management work the HIPAA Security Rule already requires. A documented security risk assessment is the natural companion exercise, and healthcare organizations can see how Z Cyber operationalizes both on our healthcare industry page.

Running a program that has to satisfy this?

A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.

Meet Your Security Team →