Cybersecurity
Practices for Small
Health Care
Organizations
Comprehensive Guide
| Latest update
2025/2026
,Table of Contents
Introduction............................................................................................................................................... 2
Document Guide - Cybersecurity Practices ............................................................................................... 4
Cybersecurity Practice #1: E-mail Protection Systems .............................................................................. 6
Cybersecurity Practice #2: Endpoint Protection Systems .......................................................................... 9
Cybersecurity Practice #3: Access Management..................................................................................... 10
Cybersecurity Practice #4: Data Protection and Loss Prevention ........................................................... 13
Cybersecurity Practice #5: Asset Management ....................................................................................... 16
Cybersecurity Practice #6: Network Management ................................................................................. 18
Cybersecurity Practice #7: Vulnerability Management ........................................................................... 19
Cybersecurity Practice #8: Incident Response ........................................................................................ 20
Cybersecurity Practice #9: Medical Device Security ............................................................................... 22
Cybersecurity Practice #10: Cybersecurity Policies ................................................................................. 23
Appendix A: Acronyms and Abbreviations .............................................................................................. 25
List of Tables
Table 1. Five Prevailing Cybersecurity Threats to Healthcare Organizations...........................................5
Table 2. Cybersecurity Practices and Sub-Practices for Small Organizations...........................................5
Table 3. Anti-Phishing Techniques............................................................................................................8
Table 4. Effective Security Controls to Protect Organization Endpoints................................................10
Table 5. Security Controls Enabling Organizations to Manage User Access to Data..............................12
Table 6. Example Data Classification Structure......................................................................................14
Table 7. Incident Response Recommendations to Mitigate Risk of a Data Breach................................22
Table 8. Effective Policies to Mitigate the Risk of Cyberattacks.............................................................25
Table 9. Acronyms and Abbreviations....................................................................................................27
Introduction
Small health care organizations tend to have limited resources for managing their cybersecurity
practices, but they are no less subject to cyberattacks. Indeed, the five threats identified in the Main
Document can be very disruptive to small organizations. For example, if a small provider practice loses a
laptop with unencrypted personal health information (PHI), a publicized breach could result. Such a
breach could have consequences for both the provider’s patients and the practice’s reputation.
2
, Technical Volume 1 provides health care cybersecurity practices for small health care organizations. For
the purpose of this volume, small organizations generally do not have dedicated information technology
(IT) and security staff dedicated to implementing cybersecurity practices due to limited resources.
Personnel may consequently have limited awareness of the severity of cyber threats to patients and to
the organization, and thus awareness of the importance of cybersecurity.
The primary mission of small healthcare organizations is to provide health care to their patients in the
most cost-effective way. Cost-effectiveness enables small organizations to sustain operations, maintain
financial viability, justify future investments such as grants and, in the case of for-profit organizations,
generate an acceptable profit. Conducting day-to-day business usually involves the electronic sharing of
clinical and financial information with patients, providers, vendors, and other players to manage the
practice and maintain business operations. For example, small organizations transmit financial
information to submit invoices and insurance claims paid by Medicare, Medicaid, Health Maintenance
Organizations (HMOs), and credit card companies.
In general, small organizations perform the following functions:
• Clinical care, which includes but is not limited to sharing information for clinical care,
transitioning care (both social and clinical), electronic or “e-prescribing,” communicating with
patients through direct secure messaging, and operating diagnostic equipment connected to a
computer network, such as ultrasound and pictures archiving and communication systems
(PACS).
• Provider practice management, which includes patient access and registration, patient
accounting, patient scheduling systems, claims management, and bill processing.
• Business operations, which include accounts payable, supply chain, human resources, IT, staff
education, protecting patient information, and business continuity or disaster recovery.
Just as health care professionals must wash their hands before caring for patients, health care
organizations must practice good cyber hygiene in today’s digital world by including cybersecurity as an
everyday, universal precaution. Like hand washing, cyber awareness does not have to be complicated or
expensive. In fact, simple cybersecurity practices, such as always logging off a computer when finished
working, are very effective at protecting information that is sensitive and private.
This volume takes into consideration recommendations made by divisions of the U.S. Department of
Health & Human Services (HHS) including, but not limited to, the Office for Civil Rights (OCR), the Food
and Drug Administration (FDA), the Office of the Assistant Secretary for Preparedness and Response
(ASPR), the Office of the Chief Information Officer (OCIO), the Centers for Medicare and Medicaid
Services (CMS), and the Office of the National Coordinator for Health Information Technology (ONC), as
well as guidelines and leading practices from the National Institute of Standards and Technology (NIST)
and the Department of Homeland Security (DHS).
Small health care organizations must comply with multiple legal and regulatory guidelines and
requirements. They often ensure compliance by creating an internal infrastructure of personnel and
procedures to govern the transmission of sensitive data as needed internally and with authorized
external resources. For example, organizations may be subject to directives from:
• Electronic health records (EHR) interoperability guidelines
3