I'm Mary Ann Kolbesekke, Executive Editor at Information Security Media Group. Today I'm speaking with Greg Garcia, who is Executive Director for Cybersecurity of the Healthcare Sector Coordinating Council. We're going to be discussing the impact on the healthcare and public health sector of the Biden Administration's recent National Security Memo-22 or NSM-22, which pertains to critical infrastructure, security and resilience. So Greg, in late April, the Biden Administration issued NSM-22, which was a rewrite of Presidential Policy Directive 21, which among other things designates critical infrastructure sectors and their federal oversight.
The new memo left intact the 16 sectors that have been in place since the Obama Administration, but newly tasked to start with overseeing national critical infrastructure protections. With all of that said, what's new in NSM-22 as it pertains to the healthcare public health sector, which is one of the 16 critical infrastructure sectors, what changes for the healthcare sector, if anything? I think, you know, a lot of this is really an update to PPD-21 and simply putting a stronger emphasis on it. What we're going to be focusing on, and really something that we've known for some time that we need to do, is this broader health sector mapping.
You know, you start first with, you know, this is something we did back in the financial services sector when I was there about 10 years ago, is you map out the whole sector really and sort of put out on a schematic, how does the healthcare system work? You know, here are the hospital systems, here are the pharmacies, here are the labs, you know, this square represents the medical technology companies, and that circle represents the pharmaceuticals, and there's all these arrows and lines in between all of them depicting process flows, and really understanding how the infrastructure works is the first order of business. What the national security memorandum requires is that all of the sector risk management agencies need to do this mapping exercise, but then further assess the risk to all of those operational functions for each sector, and then develop a risk management plan around that. So this calls for a 278 process from the date of the publication.
So I estimate that takes us to January 24 of next year that we need to submit that HHS needs to submit to the White House, and to SISA, the health sector risk assessment and risk management plan. So does that mean that the memo affects mostly the agencies, the Department of Health and Human Services, as opposed to, you know, the entities that are part of the healthcare and public health sector, you know, do those entities need to do anything, or is it mainly now an exercise for HHS and its agencies to figure this out? Yeah, by extension, it's going to require the involvement of the sector coordinating councils and other major stakeholders like the ISACs, so Health Information Sharing and Analysis Centers, or Center, rather. The requirement of pretty much most executive orders is a requirement from the White House to the cabinet agencies, the executive branch.
So if the directive is to, in our case, Health and Human Services, it's saying, look, if you're going, you need to do a broad sector risk assessment and a risk management plan in consultation with the owners and operators. So the sector coordinating councils represent the owners and operators, and it's not just the sector coordinating councils, it's many of the industry trade groups, industry associations that represent their various sub-sectors. But if this is going to be an accurate and meaningful risk assessment and risk management plan, I would say that there's no sector risk agency that can do a good job without consulting with their industry stakeholders. So we are the owners and operators.
We have responsibility. We are, you know, under the SISA definition of critical infrastructure entity. It essentially says, critical infrastructure entities are owners and operators that are held responsible for the delivery of critical assets and services to the public and for restoring those critical assets and services. Should they be substantially disrupted by some major event like a severe weather event or a cyber attack?
So it is our responsibility and the responsibility lies with the sector agencies to coordinate the process of mapping out that infrastructure, identifying what are the key vulnerabilities, the key threats facing that infrastructure, assigning risk to it, and then a management plan. So Greg, with that said, you mentioned your massive sort of event. And as we know, we just saw such an event with the attack on change healthcare, which affected so many players in the ecosystem of the healthcare sector. Do you think that will educate some of the thinking that will go now in forming what's needed to comply with this memo in terms of the impact that such a devastating attack on one player could have on everybody else?
Oh, absolutely. I mean, I would say that the administration had been working on this national security memorandum for some time well before the change healthcare attack happened. But in a silver lining moment, I think the coincidence of the memorandum and the change healthcare attack was that it really put an exclamation point on the requirement for us to do this kind of risk assessment and risk management plan. That is to identify what are those critical choke points?
What are those potential single points of failure within healthcare system or any critical infrastructure that if substantially disrupted because rippling and catastrophic impact across the entire sectors of change healthcare, we know, as they indicate, they serve at least a third of the nation's healthcare data. Well, that's that's pretty close to being a single point of failure, or at least a substantial point of failure. And if this process succeeds, then at least we will have a good idea of where those other change healthcare, like critical utilities or critical services are in the sector. And then we can we can apply appropriate levels of due diligence, third party risk management, perhaps on government side, there are regulatory options.
But this is a way of really bringing into light a level of transparency in a sector that is so complex and multi layer that the adage in cyber security is you cannot control, you cannot protect what you cannot see. So hopefully this brings light to what what we need to do. So with such risk analysis of this, you know, the overall ego system and, you know, the failure points that could happen and, you know, what ifs and types of scenarios with that then potentially help prepare the healthcare sector in a more efficient, effective way to respond to something like that or what is the goal that really is the goal. Like I said, if you know that that as a hospital system or a medical technology company, you are relying on a certain service, and in this case, let's just let's just take the reimbursement service, for example, and you know that there are very few alternatives to the service that you are using low redundancy.
Well, you're going to need to apply certain certain backups to that service so that if it is disrupted in a way, you're going to have an alternative method if it's available. So it's really about being able to have backup, being able to have incident response plans, being able to better assign risk, and when you assign appropriate risk, you're better able to apply resources. Now for a lot of the small organizations out there, they cannot afford redundancy, right? It's like buying extra enterprise level generators if the power goes out, how many of those can you afford and where can you put them?
That's like big iron, that's just a sort of a physical security example, but there are many other things in our communications and IT infrastructure that are critical to what we do, but they are unseen. So the ultimate goal of this mapping is, again, to sort of bring transparency to our infrastructure and better apply our resources. And then, you know, one of the things I had recommended to the House Energy and Commerce Committee when I justified their own April 16 is that we need to think about what are some of the root causes of having single points of failure? I mean, I think what came to light in a very pronounced way from the Change Healthcare attack is that there's sometimes deleterious effect of consolidation, of market concentration, and that one of the recommendations was that for any future mergers and acquisitions proposals that need to be cleared by the government, they should add to their assessment, the government should add to the assessment, the extent to which a particular consolidation may cause a higher level of risk as a cyber attack, because of that very point of being a single point of failure.
So there are other recommendations there, including the longer term recommendation we have is for the industry to be implementing our five-year strategic plan, that the health industry, the health industry, cyber security strategic plan that the Health Secretary counsel released in February. So Greg, what other regulatory developments are you keeping an eye on as they pertain to cyber security in the health care and public health sector this year? So you reported a while back, Mary Ann, that HHS had published its so-called CPGs, the cyber performance goals, 10 essential goals that every organization simply must have as a matter of standard practice and then enhance goals that would be for more a more mature cyber risk management program. They did telegraph back then that they would likely, while they are voluntary now, those cyber performance goals in the coming months, there may be some of those select essential goals that would become mandatory, that would become required.
So we do expect, at some point, I noticed some proposed rulemaking from HHS that would specify which of those cyber performance goals they would expect health providers and perhaps maybe other sub-sectors, but for now I believe it's respected to the health providers that they would be accountable for. And of course we saw the indication of that in the president's FY 25 budget proposal to the Congress recommending $1.3 billion to be allocated to the implementation of both essential $800 million for essential cyber performance goals, $500 million for enhanced cyber performance goals that would be distributed to what the budget proposal says are the 2000, they have identified 2000 health providers most in need that would use that money to come up to compliance with the cyber performance goals and by FY 2029 and beyond, if they are found to not be in compliance with cyber performance goals, they would suffer some penalties in the form of CMS reimbursement cuts. So that is a bit of a stick, but it starts off with an incentive. It's sort of like the old meaningful use program, which they don't call that anymore, but it's the interoperability program, which provided funding for health IT companies to come into compliance, to come into interoperability compliance, after which if they do not, then there would be some penalties that would apply.
The same concept is envisioned in this upcoming budget. So what is the timeline, do you think by the end of the fiscal year, by the end of the calendar year, and it sounds like there would be multiple years for these entities to kind of get their racks together to comply before they start seeing penalties? Is that sort of your understanding? Yeah, so the budget shows that it would be, I believe in FY 29, that there would be an assessment of those health providers that took advantage of the upfront funding support to come into cyber compliance.
So by FY 29, if they are not, then there would be impact on their CMS reimbursements. And then that would be for the essential, the essential cyber performance goals and for the enhanced cyber performance goals, I think that that assessment would take place beginning, I think, FY 2030. But as for the notice of proposed rulemaking, I understand to be, I think, an amendment to the health security rule, and that would apply to all health providers. So we'll see what that looks like.
I'm hearing it's not too far off. It could be a matter of weeks or into the sometime into the summer that we could see this notice of proposed rulemaking coming out. And of course, then there is a period of time for the industry, for the public to comment on that proposed rule, after which at some point, those comments are adjudicated. And then a final rule will come out effective when I'm not sure.
So the proposed rule would be the update to the security rules. That's what I believe. Yes, it will be. Yes, I expect it will be perhaps tracing back to the cyber performance goals, what all health providers, what minimum level of cybersecurity controls health providers will be held accountable for.
Are there any other upcoming or pending regulations that health care sector and public health sector entities should be closely watching at this point? On cybersecurity, no. Of course, I know there's a lot of activity on artificial intelligence, but it goes without saying that we are heading into an election year. I suppose politically any administration needs to be circumspect about how heavily they want to apply new regulations going into an election year, especially when there could be a different administration next year that could reverse everything.
Now that should necessarily take that into account. But still, this is the time when a lot of senior officials begin to cycle out of their posts, the political appointees, and just the whole process of governing starts to slow down as we head into an election year. So I think that will just affect the cadence. I think that will affect the volume of regulations that this administration might otherwise have wanted to promulgate.
But we'll see. And finally, Greg, anything that we should be watching for from the warning council in coming months? We are marching ahead very smartly. We have new publications that will be coming out soon, updates to our model contract.
You recall a couple of years ago, we developed a model contract between medical device companies and hospital systems about what are 80% of the most common cybersecurity terms and conditions in the contract when you are purchasing or servicing medical devices in a clinical environment. We are working with HHS on co-publishing and operational continuity cyber incident plan. We will be publishing soon a document on vulnerability communications, how to medical device companies best communicate cyber vulnerabilities and medical devices to the hospital systems in a way that is uniform, and then how do the hospitals themselves prioritize patching or other remedial measures to ensure that those vulnerabilities are taken into account. So those are just a couple of things that are on the way.
We've stood up task groups on what are the needs of the underserved health providers as it pertains to cybersecurity regulation and assistance, technical and financial assistance. So there's a lot going on, but we are at a very strategic level focused on implementing our five-year strategic plan, all the 10 major goals and 12 objectives so that we can get the healthcare industry, cybersecurity out of critical condition as we were once diagnosed into stable condition by 2029. Well, thank you so much, Greg. Always a pleasure.
I've been speaking to Greg Garcia. I'm Mary-Angle Bizakmiki of Information Security Media Group. Thanks for joining us.