HHS, healthcare's lead cyber agency, keeps failing its own audit
Summary
The Department of Health and Human Services is the federally designated lead agency for cybersecurity across the entire U.S. healthcare and public health sector -- hospitals, insurers, payment processors. Three oversight reports, spanning about 16 months, trace two parallel failures. In November 2024, GAO found HHS still wasn't tracking the sector's adoption of ransomware-mitigation practices or evaluating whether its own guidance worked, months after the February 2024 Change Healthcare ransomware attack caused an estimated $874 million in losses. In September 2025, GAO reported HHS itself had 82 open recommendations tied to cybersecurity and IT management. In March 2026, HHS's own Inspector General rated the department's internal information security program 'Not Effective' for the sixth consecutive year -- and HHS disputed three of the ten recommendations meant to fix it.
A sector-wide attack, and an untracked gap
In February 2024, Change Healthcare -- a health payment processor -- was hit by a ransomware attack involving data theft, with estimated losses of $874 million and disruptions to healthcare providers and patient care nationwide. 's November 2024 report on 's cybersecurity leadership cited that attack as context for a set of gaps had already been tracking. A January 2024 report had found that participating hospitals self-assessed having adopted 70.7% of the NIST Cybersecurity Framework's functional areas -- but wasn't yet tracking adoption of the ransomware-specific practices within that framework, and hadn't evaluated whether the guidance, training, and threat briefings it gave the sector were actually effective.
View data as table
| Self-assessed as adopted | 70.7 |
|---|---|
| Not confirmed adopted | 29.3 |
Ten months later: dozens of open items, still
's September 2025 letter to 's Chief Information Officer found 82 open recommendations calling for the 's attention -- 37 of them considered sensitive enough that their details were withheld from the public letter, and one designated a priority recommendation. Every one of the 82 traced to one of two high-risk areas: cybersecurity of the nation, or IT acquisitions and management. The letter noted that 's own Inspector General had additional open recommendations on top of 's, including ones tied to 's obligations under the Federal Information Security Modernization Act.
View data as table
| Total open recommendations | 82 |
|---|---|
| Considered sensitive (details withheld from public report) | 37 |
The department's own network: not effective, six years running
That FISMA audit landed in March 2026. 's Inspector General -- through an independent audit performed by Ernst & Young -- rated the department's own information security program 'Not Effective' for the sixth consecutive year. To be rated effective, an agency must reach a 'Managed and Measurable' maturity level; didn't reach it in any of the six required cybersecurity function areas: Govern, Identify, Protect, Detect, Respond, and Recover. Core metrics landed at 'Consistently Implemented' and Supplemental metrics at 'Ad Hoc' -- both short of the bar.
Ten fixes, three refused
The audit made ten recommendations to strengthen 's information security program. 's Office of the Chief Information Officer concurred with seven. It did not concur with three: updating policy to clearly define cybersecurity roles and responsibilities, enforcing existing policies for provisioning and monitoring privileged-user access, and enforcing policies for conducting business impact analyses. In each case, the Inspector General's office responded in writing that it was maintaining the validity of the recommendation -- noting, for instance, that monitoring of privileged-user activity remained 'a repeated challenge across divisions' during testing, despite policies already requiring it.
View data as table
| Recommendations HHS concurred with | 7 |
|---|---|
| Recommendations HHS did not concur with | 3 |
The takeaway
- The sector-facing gap and the internal gap are the same shape. Months after a $874 million ransomware attack on a payment processor, found wasn't tracking the sector's own defenses -- and 's internal network has failed the government's own annual security bar for six straight years.
- Progress on paper hasn't closed the gap. Ten months after 's November 2024 findings, still had 82 open recommendations calling for attention; six months after that, its own FISMA audit found none of six required security functions reached an effective rating.
- When disagreed with a fix, the Inspector General didn't back down. On all three recommendations disputed -- role definitions, privileged-access enforcement, and business impact analyses -- the Inspector General's office restated the underlying evidence and kept the recommendation in place.
Findings on the Change Healthcare ransomware attack, 's sector-oversight gaps, and the NIST Cybersecurity Framework adoption figure are from -25-107755, 'Healthcare Cybersecurity: Continues to Have Challenges as Lead Agency' (November 2024), read directly in full via an archived copy after the current gao.gov asset URL blocked direct access. Findings on 's 82 open recommendations are from -25-108539, 'Chief Information Officer Open Recommendations: Department of Health and Human Services' (September 3, 2025), also read directly in full via an archived copy. Findings on 's internal FISMA compliance rating and its response to the FY2025 audit's ten recommendations are from 's OAS-25-18-041, 'Review of the Department of Health and Human Services' Compliance With the Federal Information Security Modernization Act of 2014 for Fiscal Year 2025' (March 2, 2026), read directly in full; no existing archived copy was found at read time, so a new one was captured. The three reports span about 16 months and examine two sides of the same department's cybersecurity role -- its oversight of the healthcare sector, and its own network's compliance with federal security standards.
Sources(3) ▾
- U.S. Government Accountability Office, Healthcare Cybersecurity: HHS Continues to Have Challenges as Lead Agency (2024-11-13) — -25-107755, a 'Snapshot' summarizing prior work on 's cybersecurity leadership of the healthcare and public health sector, citing the February 2024 Change Healthcare ransomware attack's estimated $874 million in losses -- the sector-oversight facet. Distinct from doc-gao25-108539 ('s own open-recommendation count, published ~10 months later) and doc-oig-oas-25-18-041 ('s own internal FISMA compliance rating, published ~16 months later). Direct gao.gov PDF fetch returns HTTP 403; fetched in full via an archived copy. gao.gov · original document
- U.S. Government Accountability Office, Chief Information Officer Open Recommendations: Department of Health and Human Services (2025-09-03) — -25-108539, a letter to 's Chief Information Officer summarizing 82 open recommendations spanning cybersecurity and IT acquisitions -- the open-recommendations facet, confirming the November 2024 Snapshot's findings had not been remediated roughly 10 months later. Direct gao.gov PDF fetch returns HTTP 403; fetched in full via an archived copy. gao.gov · original document
- U.S. Department of Health and Human Services, Office of Inspector General (audit performed by Ernst & Young LLP), Review of the Department of Health and Human Services' Compliance With the Federal Information Security Modernization Act of 2014 for Fiscal Year 2025 (2026-03-02) — OAS-25-18-041, 's annual FISMA compliance audit for fiscal year 2025, rating 's own information security program 'Not Effective' for the sixth consecutive year -- the internal-security facet, confirming 's own network security gaps roughly 16 months after doc-gao25-107755's sector-oversight warning. No existing Wayback capture was found at read time; a new snapshot was requested and captured. oig.hhs.gov · original document
Comments
Always open. Logged-in readers can annotate paragraphs in place.
The Department of Health and Human Services is the federally designated lead agency for cybersecurity across the U.S. healthcare and public health sector -- hospitals, insurers, and payment processors. In November 2024⧉, reported that was still falling short of that role. In September 2025⧉, found itself had dozens of open cybersecurity recommendations. And in March 2026⧉, 's own Inspector General reported on the state of the department's internal network security.