A new assessment tool for healthcare facilities
In 2026, HHS’s Administration for Strategic Preparedness and Response published a voluntary Healthcare Facility-Level Cybersecurity Assessment. The tool is designed to help facilities evaluate their cybersecurity posture, identify vulnerabilities, highlight strengths, and guide planning conversations. ASPR also expanded its RISC 2.0 toolkit with a cybersecurity module scored against the NIST Cybersecurity Framework 2.0 and HHS healthcare cybersecurity performance goals.
For Central Florida clinics, ambulatory centers, imaging practices, senior-care organizations, and business associates, the assessment can create structure around a risk discussion. It does not replace a HIPAA Security Rule risk analysis, legal advice, or organization-specific judgment.
Assemble an accountable team
Include leadership, clinical operations, privacy, compliance, IT, facilities, emergency management, and key vendors. Cybersecurity questions often cross boundaries: downtime affects patient safety, network diagrams affect recovery, vendors handle electronic protected health information, and facility systems may depend on connected technology.
Assign one owner to maintain the assessment record and one executive to approve priorities and accepted risks.
Gather evidence before scoring
Collect current inventories, data-flow diagrams, risk-analysis documentation, policies, vendor agreements, training records, vulnerability results, backup tests, incident exercises, access reviews, and remediation tracking. A confident answer without supporting evidence can conceal a control that exists only on paper.
Where evidence is missing, record the gap rather than guessing. The assessment is most useful when it produces an honest work queue.
Connect security to patient care
Evaluate how a cyber incident could interrupt scheduling, medication, imaging, laboratory interfaces, clinical documentation, referrals, claims, or communication with patients. Identify safe manual workarounds and the maximum tolerable outage for essential services.
Central Florida facilities should coordinate cyber continuity with hurricane, generator, communications, and regional vendor planning. A backup is not sufficient if staff cannot authenticate, reach the restored application, or operate safely during an extended outage.
Prioritize findings
Group findings by potential patient-safety impact, ePHI exposure, operational disruption, likelihood, and dependency. Assign an owner, deadline, planned safeguard, and validation method. Quick improvements may include MFA coverage, removal of inactive accounts, tested backups, vendor access restrictions, updated contact rosters, and staff exercises.
Preserve the governance record
Keep the dated assessment, participants, evidence reviewed, assumptions, scores, decisions, remediation proof, and follow-up dates. Link findings to the HIPAA risk-management process where relevant, while keeping the distinction between voluntary guidance and legal requirements clear.
Review checklist
1. Confirm scope across clinical, administrative, facility, and vendor systems.
2. Gather evidence before assigning scores.
3. Map technology dependencies to patient-care services.
4. Record gaps honestly and assign accountable owners.
5. Prioritize using safety, privacy, operational, and likelihood factors.
6. Validate corrective work with tests and documentation.
7. Reassess after major system, facility, vendor, or threat changes.
This article is educational and is not legal advice. Regulated organizations should coordinate compliance decisions with qualified legal, privacy, and healthcare security professionals.

