Federal Analysis
HHS Updates Cybersecurity Toolkit
March 16, 2026
The U.S. Department of Health and Human Services (HHS) has released an updated version of its Risk Identification and Site Criticality (RISC) 2.0 Toolkit, now incorporating a dedicated cybersecurity module. This enhancement integrates cyber risk assessment with traditional operational hazards, framing cybersecurity as a critical component of patient safety and enterprise risk management for healthcare organizations. The updated toolkit enables hospital leaders and healthcare system procurement professionals to identify vulnerabilities, benchmark cybersecurity posture against federal standards such as those from NIST, and prioritize investments to strengthen resilience across healthcare operations.
- Why this matters: Healthcare procurement teams should consider incorporating the RISC 2.0 Toolkitโs cybersecurity module into their risk management and vendor evaluation processes to align with federal guidance and improve system-wide cyber resilience.
- The integration of cybersecurity with operational risk highlights the growing importance of procuring solutions that address both IT security and patient safety.
- Vendors offering cybersecurity products and services tailored to healthcare settings may find increased demand as organizations seek to comply with updated federal frameworks.
- Procurement strategies should emphasize comprehensive risk assessment tools that support benchmarking and prioritization aligned with HHS and NIST standards.
Agencies
U.S. Department of Health and Human Services, National Institute of Standards and Technology
Sources
- How Hospital Leaders Can Use HHS' Updated Cybersecurity Toolkit to Strengthen Resilience | HealthLeaders Media · Health Leaders Media · Mar 16