Homeland Security is developing standards and processes for how the congressionally-mandated Information Sharing and Analysis Organizations (ISAOs) will help the government and private sector sharing data on the latest cybersecurity threats. But, in the meantime, DHS has encouraged agencies and sectors to start building their own relationships and the Department of Health and Human Services has taken heed of that suggestion.
On July 25, HHS offices announced two funding opportunities totaling $1.25 million to help existing Information Sharing and Analysis Centers (ISACs) — the private sector version of an ISAO — work with federal agencies like HHS and DHS to share and analyze threat information in the name of better security for all.
Funding Opportunities: ONC | ASPR
The two opportunities — which combined offer $250,000 a year for up to five years — are open to any public or private nonprofit organization “that are already providing outreach and technical assistance to participating organizations on cybersecurity threats” specific to the health care and public health sectors, according to the listing on Grants.gov.
“Establishing robust threat information sharing infrastructure and capability within the health care and public health sector is crucial to the privacy and security of health information, which is foundational to the digital health system,” said Karen DeSalvo, national coordinator for health IT (ONC), whose office issued one of the grants. “This coordinated resource will focus on sharing the most up-to-date threat information across the health and public health sectors and will better equip health systems to identify potential threats and further protect electronic health information.”
According to a release put out by ONC and the assistant secretary for preparedness and response (ASPR), the funding will be used to bolster an ISAC’s outreach efforts in four ways:
- Provide cybersecurity information and education on cyber threats affecting the health care and public health sector.
- Expand outreach and education activities to assure that information about cybersecurity awareness is available to the entire sector.
- Equip stakeholders to take action in response to cyber threat information.
- Facilitate information sharing widely within the sector, regardless of the size of the organization.
“Not only do we need to worry about natural disasters but also increasingly we must combat — and prevent — cyber threats,” ASPR Nicole Lurie said. “Many parts of the health care system don’t have access to the information they need to protect themselves from these threats. Using an ISAO to exchange cyber threat information with these healthcare organizations, bi-directionally between HHS and the health care and public health sector, we hope to build the capacity to better prevent, detect and respond to cyberattacks.”




