I treat HICP as a starting point - not proof that care can continue during an outage. My first checks: reconcile asset records, verify access, review patch exceptions, and test recovery with clinical teams and vendors.

The gap shows up in the numbers: organizations reported 83% governance coverage but only 48% medical device security coverage. Those figures came from a survey of 69 organizations, with optional HICP assessments - not independent tests of whether controls worked.[2]

I focus on three questions:

  • Who owns the work? Check staffing, funding, team handoffs, and vendor duties using HICP guidance for the organization’s size.
  • Do the controls work? Verify inventories, account access, patches, and safeguards for devices that cannot be patched.
  • Can care continue? Test patient-information access, downtime workflows, backup restoration, and vendor escalation.

My bottom line: <u>check results, not just policies</u>. Track unresolved risks, name owners, set deadlines, and retest fixes.

HICP Implementation Gap: Reported Coverage vs. Verified Readiness

HICP Implementation Gap: Reported Coverage vs. Verified Readiness

UnHack the Podcast: Raising Cyber Standards and Easing Implementation with Erik Decker

HICP Implementation Gaps

The table shows where reported coverage falls short, which evidence needs checking, and how these gaps affect daily clinical and IT work.

HICP recommended practice Reported field condition Missing evidence to request Operational consequence
Maintain asset visibility and control access Asset management coverage averaged 53%.[2] Reconciled asset records, assigned owners, sampled account records, and access-review results Unknown assets or access without approval remain outside security controls.
Resolve vulnerabilities and protect medical devices Mitigating known vulnerabilities had a 74% coverage rate among essential healthcare cybersecurity goals.[2] Patch status, approved exceptions, tested safeguards, and replacement decisions Known weaknesses remain exploitable.
Test response and recovery with suppliers 40% of organizations failed response and recovery planning with vendors and providers.[4] Joint exercise records, vendor escalation tests, recovery results, and closed findings Vendor dependencies delay recovery.

Start with inventory, access, patching, and recovery, where addressing gaps offers the most value.

Inventory Gaps and Access Control Failures

Limited staffing and unclear team handoffs can leave devices untracked and access unchecked.[1][4][5] Match inventory records to observed assets and assign owners. Check a sample of accounts against employment and vendor status to find shared accounts, delayed account removal, excessive privileges, and MFA gaps.

Unresolved Vulnerabilities and Device Ownership

Restrictions on clinical downtime, infrastructure costs, and split ownership across security, IT, and clinical engineering can leave devices exposed.[2][4][5] If patching isn't possible, document each exception's owner, clinical constraint, approved safeguard, remediation deadline, and replacement decision. Verify segmentation settings and permitted traffic.

When the CISO owned medical device security, HICP coverage increased from 45% to 63%.[5] This ownership gap also appears in response and recovery.

Response Plans Without Testing or Accountability

Recovery plans fail when teams write them for audits but don't test them with clinical teams and vendors. Reported response maturity often reflects after-action review rather than tested readiness for an outage.[4]

Test recovery, clinical downtime procedures, and vendor escalation paths. Check that staff can access patient information and keep care moving during an outage. Document findings, assign owners, and close corrective actions. Executive reports should show unresolved exposure, owners, and overdue deadlines - not just whether a plan exists.

Why Implementation Falls Short

A stated constraint does not prove that a control works. Having a policy is not the same as completing work on schedule. Use interviews to identify barriers, then check staffing, budget, exception, and workflow records to verify them. These barriers explain why HICP coverage on paper may not translate into reliable daily practice.

Barrier Observable indicator to check
Capacity Recurring security tasks lack protected staff hours, or core security tasks are outsourced to managed service providers.
Governance Named owners, exception decisions, and overdue corrective actions are missing.
Technical Legacy and clinically dependent systems lack documented segmentation exceptions and compensating controls.
Process Vendor and supplier requirements, incident notification, and inventory updates are not completed on schedule.

Staffing and Budget Limits

Vacancies and competing duties can leave teams short on capacity. Overdue work shows whether that shortage affects execution. Check IT and clinical engineering schedules for protected security time. Compare technology budgets, recurring funding, and protected staff hours for inventory upkeep and remediation. Then check who owns the work when capacity falls short.

Handoffs Between Teams and Vendors

Outsourcing a task does not settle who accepts the risk or verifies completion. Trace an open finding through security, infrastructure, compliance, clinical operations, procurement, and third-party vendor risk management. Check ownership, contract duties, and escalation records along the way. This lack of clarity often contributes to the economic impact of third-party risk across the organization. Without clear ownership, exceptions linger and controls age out.

Clinical Constraints and Misleading Metrics

Exceptions need approval, funding, deadlines, and verified safeguards - not indefinite postponement. Check whether constraints appear in funded work plans and exception reviews, rather than only in arguments about uptime.

Measure control performance, not policy status. Require named owners, tested safeguards, and tracking of overdue remediation alongside inventory coverage, recovery results, and residual risk. Use those checks to assign owners and close the highest-risk gaps.

Priorities for Putting HICP Into Practice

Assign Owners and Resolve High-Risk Gaps

Turn the inventory, access, and ownership gaps seen in the field into work with clear accountability.

Combine discovery, procurement, and clinical engineering records into one authoritative inventory. Give each asset an owner and a review date. Prioritize identity controls based on care and business risk, then verify access coverage using access reports and audit logs. Shared credentials make that evidence unreliable. [2]

Give high-risk vulnerabilities and device risks both business and technical owners, along with deadlines and escalation paths. For devices that cannot be patched, document and test network segmentation.

Test Readiness and Track Corrections

Documenting ownership isn't enough. Test it under outage conditions.

Run tabletop exercises and technical recovery tests with clinical operations, IT, security, and legal teams. Verify that backups can be restored and downtime workflows work. Record failures, assign corrections, and retest them. [1][2]

Review inventory, access coverage, remediation age, and overdue actions on a set schedule. Every unresolved risk should lead to a documented correction or a risk-acceptance decision.

Conclusion: Verify Controls in Daily Work

Use a short evidence checklist: accurate inventory, verified access coverage, documented remediation actions, tested response and recovery, named device owners, and documented executive reviews.

Require records and retest results that show corrections worked. Check that staff can use the controls reliably in daily care and during outages.

FAQs

How can we measure whether HICP controls actually work?

Go beyond self-reported adoption with objective benchmarks you can verify. Assess coverage across the ten HICP practice areas using a standard maturity scale: No, Partial, Substantial, or Full coverage.

Compare that coverage with ownership by information security leadership and the cost of protecting the workforce. Validate maturity through tabletop exercises, red team assessments, or purple team assessments - not vulnerability scanning alone. Scanning often lacks the processes needed to prioritize and remediate identified risks.

Which HICP gaps should we address first with limited resources?

Focus first on critical gaps where implementation is weakest. Data consistently shows that network-connected medical device security, data protection and loss prevention, and network management have the lowest coverage among HICP areas [1].

Also address supply chain and asset management. Both remain weaknesses across the industry, and both are key to resilience [1][2]. Give information security leaders more ownership of the program: greater ownership is strongly linked to better coverage in these HICP areas [3][4].

How can we test recovery without disrupting patient care?

Use tabletop exercises to simulate large-scale system downtime without interrupting live systems. Include executive leadership and key clinical stakeholders to check response plans, spot gaps in procedures, and improve recovery plans - all without disrupting clinical operations [1][2].

Back up systems frequently and test those backups regularly against defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO). Develop clinical downtime procedures to keep care running and protect patient safety [1].

Related Blog Posts