HHS published Cybersecurity Performance Goals for the healthcare and public health sector in January 2024, split into Essential Goals and Enhanced Goals. The department describes them as a floor of safeguards addressing the common attack vectors identified in its 2023 Hospital Cyber Resiliency Landscape Analysis. None of it is mandatory, and the HHS has been explicit that this is a starting position rather than a settled one.
What the goals actually contain
Essential Goals cover practices most security teams would recognize immediately, including multi-factor authentication, basic cybersecurity training, email security, incident planning, and vulnerability management. Enhanced Goals extend into asset inventory, third-party risk management, network segmentation, and cybersecurity testing.
Healthcare IT News reported that the goals align with the HHS 405(d) Program and the Health Sector Coordinating Council's Health Industry Cybersecurity Practices, alongside the NIST Cybersecurity Framework and CISA's National Cybersecurity Strategy. Each goal links back to the corresponding HICP sub-practices, which means an organization already following HICP is mostly already compliant.
Erik Decker, CISO at Intermountain Health and co-chair of the HHS 405(d) task force, described the document's origins in comments to GovInfoSecurity, noting that "these CPGs leveraged five years of work with the release of HICP."
Why voluntary has not worked so far
Healthcare has had access to voluntary frameworks for years, and OCR's own audit findings describe the result. The agency audited 166 covered entities and 41 business associates across 2016 and 2017, and its Industry Report found 14% of covered entities substantially fulfilling their risk analysis responsibilities and 6% implementing adequate risk management.
Ty Greenhalgh, an HHS 405(d) Ambassador, put the objection to voluntary standards plainly in an interview with TechTarget, saying "voluntary goals alone will not drive the cyber-related behavioral change needed." He also warned that mandating them on cash-strapped hospitals without funding risks doing more damage than good, which is the tension running through the entire policy.
Paubox research supports the affordability argument. Its study of rural providers found 50% citing budget limitations as a top barrier, nearly double the rate among urban peers, and 73% struggling to maintain HIPAA compliance through a lack of staff and funding.
What the HHS is proposing
The concept paper HHS published in December 2023 set out a route from voluntary to enforceable, running through Medicare and Medicaid rather than through HIPAA alone. Analysis by Mintz detailed the proposed mechanics.
Funding would come first. HHS proposed transferring $800 million from the Medicare Hospital Insurance Trust Fund across fiscal years 2027 and 2028 to roughly 2,000 high-needs hospitals implementing practices, followed by $500 million across 2029 and 2030 available to all hospitals for enhanced practices.
Penalties would follow through the Promoting Interoperability Program. Acute care hospitals not adopting cybersecurity practices would face penalties of up to 100% of their annual market basket increase, with additional penalties of up to 1% off base payment beginning in fiscal year 2031. Critical Access Hospitals would face payment reductions of up to 1%.
The American Hospital Association pushed back on the enforcement proposal, arguing that penalising hospitals already struggling to fund security compounds the problem rather than solving it.
Where the HIPAA Security Rule update fits
Running alongside the CPG work, OCR published a Notice of Proposed Rulemaking in December 2024 covering the first major Security Rule overhaul in more than a decade. The proposal removes the distinction between required and addressable implementation specifications.
That change matters for email directly. Encryption has been addressable since the Security Rule took effect, meaning an organization can document a rationale for not implementing it rather than implementing it. Under the proposal, encryption and multi-factor authentication both become mandatory. A maintained technology asset inventory covering every piece of software touching ePHI would also be required, which addresses the scope gaps that make a risk analysis inadequate.
Two policy tracks are therefore converging on the same set of controls, one through payment mechanisms and one through the Security Rule itself.
What an organization can do now
Several Essential Goals resolve directly to email configuration, covering email security, multi-factor authentication, and incident planning. The organizations most exposed are the ones whose email controls depend on someone choosing to apply them.
Paubox's 2026 Healthcare Email Security Report found 41% of breached healthcare organizations in 2025 classified as high risk based on email configuration alone, up from 31% in 2024, and recorded a 47% increase in attacks getting past the defenses built into Microsoft 365 and Google Workspace.
Paubox Email Suite encrypts every outbound message by default, which satisfies the encryption requirement without depending on sender behavior and without the documentation burden of an addressable alternative. Paubox Inbound Email Security reads sender behavior, message intent, and contextual signals before delivery.
Learn more: HIPAA Compliant Email: The Definitive Guide
Why the funding question decides the outcome
The gap between what HHS recommends and what hospitals can afford is the variable that determines whether any of this changes behavior. Fierce Healthcare's coverage of the CPG release noted the goals arrived at through the Administration for Strategic Preparedness and Response alongside a new gateway site consolidating federal cybersecurity resources for the sector.
Resources are not the same as funding, and the proposed transfers from the Medicare Hospital Insurance Trust Fund require congressional authority HHS does not currently hold. Without that money arriving first, the penalty structure lands on the organizations least able to absorb it, which are the same rural and small providers already reporting budget as their primary barrier. The policy works if the sequence holds and fails if it reverses.
FAQs
Are the Cybersecurity Performance Goals mandatory?
Not currently. HHS published them as voluntary practices in January 2024 while stating it intends to propose enforceable standards informed by them, through Medicare and Medicaid programs and through updates to the HIPAA Security Rule.
What is the difference between Needed and Enhanced Goals?
Needed Goals cover foundational practices such as multi-factor authentication, email security, basic training, and incident planning. Enhanced Goals extend to asset inventory, third-party risk management, network segmentation, and security testing.
How do the CPGs relate to 405(d) and HICP?
They align directly, with each goal linking to the corresponding Health Industry Cybersecurity Practices sub-practices. An organization already following HICP will find most of the Needed Goals already addressed.
What penalties has HHS proposed?
Through the Promoting Interoperability Program, acute care hospitals not adopting needed practices could face penalties of up to 100% of their annual market basket increase, with up to 1% off base payment from fiscal year 2031, and Critical Access Hospitals could face payment reductions of up to 1%.
Which goals affect email specifically?
Email security, multi-factor authentication, and incident planning all appear in the Needed tier, and the proposed Security Rule update would make encryption mandatory rather than addressable, which removes the option of documenting an alternative.
