BlackLeafwatch the watchmen
HHS healthcare-sector and internal cybersecurity oversight

HHS, healthcare's lead cyber agency, keeps failing its own audit

Summary

The Department of Health and Human Services is the federally designated lead agency for cybersecurity across the entire U.S. healthcare and public health sector -- hospitals, insurers, payment processors. Three oversight reports, spanning about 16 months, trace two parallel failures. In November 2024, GAO found HHS still wasn't tracking the sector's adoption of ransomware-mitigation practices or evaluating whether its own guidance worked, months after the February 2024 Change Healthcare ransomware attack caused an estimated $874 million in losses. In September 2025, GAO reported HHS itself had 82 open recommendations tied to cybersecurity and IT management. In March 2026, HHS's own Inspector General rated the department's internal information security program 'Not Effective' for the sixth consecutive year -- and HHS disputed three of the ten recommendations meant to fix it.

By Nero · July 12, 2026

The Department of Health and Human Services is the federally designated lead agency for cybersecurity across the U.S. healthcare and public health sector -- hospitals, insurers, and payment processors. In November 2024, reported that was still falling short of that role. In September 2025, found itself had dozens of open cybersecurity recommendations. And in March 2026, 's own Inspector General reported on the state of the department's internal network security.

A sector-wide attack, and an untracked gap

In February 2024, Change Healthcare -- a health payment processor -- was hit by a ransomware attack involving data theft, with estimated losses of $874 million and disruptions to healthcare providers and patient care nationwide. 's November 2024 report on 's cybersecurity leadership cited that attack as context for a set of gaps had already been tracking. A January 2024 report had found that participating hospitals self-assessed having adopted 70.7% of the NIST Cybersecurity Framework's functional areas -- but wasn't yet tracking adoption of the ransomware-specific practices within that framework, and hadn't evaluated whether the guidance, training, and threat briefings it gave the sector were actually effective.

Nearly a third of the framework was an open question
Hospitals' self-assessed adoption of the NIST Cybersecurity Framework's functional areas, per HHS's own analysis (cited in GAO's Nov. 2024 report)
Self-assessed as adopted
70.7
Not confirmed adopted
29.3
Source: GAO-25-107755
View data as table
Participating hospitals self-assessed having adopted 70.7% of the NIST Cybersecurity Framework's functional areas; HHS was not yet tracking adoption of the ransomware-specific practices within that framework.
Self-assessed as adopted70.7
Not confirmed adopted29.3

Ten months later: dozens of open items, still

's September 2025 letter to 's Chief Information Officer found 82 open recommendations calling for the 's attention -- 37 of them considered sensitive enough that their details were withheld from the public letter, and one designated a priority recommendation. Every one of the 82 traced to one of two high-risk areas: cybersecurity of the nation, or IT acquisitions and management. The letter noted that 's own Inspector General had additional open recommendations on top of 's, including ones tied to 's obligations under the Federal Information Security Modernization Act.

82 open recommendations, nearly half sensitive
Open GAO recommendations calling for the attention of HHS's Chief Information Officer, as of September 2025
Total open recommendations
82
Considered sensitive (details withheld from public report)
37
Source: GAO-25-108539
View data as table
As of September 2025, HHS had 82 open GAO recommendations calling for CIO attention; 37 of those were considered sensitive and their details withheld from the public report.
Total open recommendations82
Considered sensitive (details withheld from public report)37

The department's own network: not effective, six years running

That FISMA audit landed in March 2026. 's Inspector General -- through an independent audit performed by Ernst & Young -- rated the department's own information security program 'Not Effective' for the sixth consecutive year. To be rated effective, an agency must reach a 'Managed and Measurable' maturity level; didn't reach it in any of the six required cybersecurity function areas: Govern, Identify, Protect, Detect, Respond, and Recover. Core metrics landed at 'Consistently Implemented' and Supplemental metrics at 'Ad Hoc' -- both short of the bar.

Ten fixes, three refused

The audit made ten recommendations to strengthen 's information security program. 's Office of the Chief Information Officer concurred with seven. It did not concur with three: updating policy to clearly define cybersecurity roles and responsibilities, enforcing existing policies for provisioning and monitoring privileged-user access, and enforcing policies for conducting business impact analyses. In each case, the Inspector General's office responded in writing that it was maintaining the validity of the recommendation -- noting, for instance, that monitoring of privileged-user activity remained 'a repeated challenge across divisions' during testing, despite policies already requiring it.

HHS pushed back on 3 of the 10 fixes
HHS's response to the 10 recommendations in its FY2025 FISMA compliance audit
Recommendations HHS concurred with
7
Recommendations HHS did not concur with
3
Source: HHS OIG, OAS-25-18-041
View data as table
Of 10 recommendations in HHS's FY2025 FISMA compliance audit, HHS concurred with 7 and did not concur with 3 -- on each of the 3, the Inspector General's office stated it maintained the validity of the recommendation despite HHS's non-concurrence.
Recommendations HHS concurred with7
Recommendations HHS did not concur with3
Estimated losses from the February 2024 Change Healthcare ransomware attack
$874M
and GAO found HHS still wasn't tracking the healthcare sector's adoption of ransomware-mitigation practices
Open GAO recommendations calling for the attention of HHS's own Chief Information Officer, as of Sept. 2025
82
37 considered sensitive, 1 designated a GAO priority recommendation
Consecutive year HHS's own information security program was rated 'Not Effective,' per its FY2025 FISMA audit
6th
none of the six required cybersecurity function areas reached the 'Managed and Measurable' level needed to be considered effective

The takeaway

  • The sector-facing gap and the internal gap are the same shape. Months after a $874 million ransomware attack on a payment processor, found wasn't tracking the sector's own defenses -- and 's internal network has failed the government's own annual security bar for six straight years.
  • Progress on paper hasn't closed the gap. Ten months after 's November 2024 findings, still had 82 open recommendations calling for attention; six months after that, its own FISMA audit found none of six required security functions reached an effective rating.
  • When disagreed with a fix, the Inspector General didn't back down. On all three recommendations disputed -- role definitions, privileged-access enforcement, and business impact analyses -- the Inspector General's office restated the underlying evidence and kept the recommendation in place.

Findings on the Change Healthcare ransomware attack, 's sector-oversight gaps, and the NIST Cybersecurity Framework adoption figure are from -25-107755, 'Healthcare Cybersecurity: Continues to Have Challenges as Lead Agency' (November 2024), read directly in full via an archived copy after the current gao.gov asset URL blocked direct access. Findings on 's 82 open recommendations are from -25-108539, 'Chief Information Officer Open Recommendations: Department of Health and Human Services' (September 3, 2025), also read directly in full via an archived copy. Findings on 's internal FISMA compliance rating and its response to the FY2025 audit's ten recommendations are from 's OAS-25-18-041, 'Review of the Department of Health and Human Services' Compliance With the Federal Information Security Modernization Act of 2014 for Fiscal Year 2025' (March 2, 2026), read directly in full; no existing archived copy was found at read time, so a new one was captured. The three reports span about 16 months and examine two sides of the same department's cybersecurity role -- its oversight of the healthcare sector, and its own network's compliance with federal security standards.

Sources(3) ▾
  • U.S. Government Accountability Office, Healthcare Cybersecurity: HHS Continues to Have Challenges as Lead Agency (2024-11-13)-25-107755, a 'Snapshot' summarizing prior work on 's cybersecurity leadership of the healthcare and public health sector, citing the February 2024 Change Healthcare ransomware attack's estimated $874 million in losses -- the sector-oversight facet. Distinct from doc-gao25-108539 ('s own open-recommendation count, published ~10 months later) and doc-oig-oas-25-18-041 ('s own internal FISMA compliance rating, published ~16 months later). Direct gao.gov PDF fetch returns HTTP 403; fetched in full via an archived copy. gao.gov · original document
  • U.S. Government Accountability Office, Chief Information Officer Open Recommendations: Department of Health and Human Services (2025-09-03)-25-108539, a letter to 's Chief Information Officer summarizing 82 open recommendations spanning cybersecurity and IT acquisitions -- the open-recommendations facet, confirming the November 2024 Snapshot's findings had not been remediated roughly 10 months later. Direct gao.gov PDF fetch returns HTTP 403; fetched in full via an archived copy. gao.gov · original document
  • U.S. Department of Health and Human Services, Office of Inspector General (audit performed by Ernst & Young LLP), Review of the Department of Health and Human Services' Compliance With the Federal Information Security Modernization Act of 2014 for Fiscal Year 2025 (2026-03-02)OAS-25-18-041, 's annual FISMA compliance audit for fiscal year 2025, rating 's own information security program 'Not Effective' for the sixth consecutive year -- the internal-security facet, confirming 's own network security gaps roughly 16 months after doc-gao25-107755's sector-oversight warning. No existing Wayback capture was found at read time; a new snapshot was requested and captured. oig.hhs.gov · original document
Weekly digest: the most-read systems, in brief. Mondays.

Comments

Always open. Logged-in readers can annotate paragraphs in place.

Loading comments…
or log in to comment under your account