Evidence library / Last reviewed 2026-08-21
Health Security Sources
Direct answer
Start with accountable official agencies and standards bodies, read the current source directly, and use secondary reporting only for context. A link here does not imply agency endorsement of this site.
Health security and preparedness
WHO Health SecurityOfficial guidance ↗Useful for: Global framing for proactive and reactive health-security capacity.Limit: Global overview; consult current national and local authorities for operational instructions.CDC Global Health SecurityOfficial guidance ↗Useful for: Prevent, detect, and respond capacity framing.Limit: Describes CDC programs and priorities; it is not a local emergency plan.CDC Preparedness and Response CapabilitiesOfficial framework ↗Useful for: Public-health preparedness capability structure.Limit: Jurisdictions must adapt capabilities to authority, resources, and risk.ASPR Healthcare System Cybersecurity ReadinessOfficial operational guidance ↗Useful for: Preparedness, response, downtime, restoration, and continuity considerations.Limit: A planning reference, not a substitute for an incident response or emergency operations plan.
State and local public health
CDC Health Department DirectoriesOfficial directory ↗Useful for: Find accountable state, local, territorial, and tribal public-health authorities.Limit: Directory entries point to agencies; verify the correct authority for the event and jurisdiction.Colorado Public Health Emergency PreparednessState official source ↗Useful for: Example of jurisdiction-specific preparedness information and reporting routes.Limit: Colorado-specific; readers elsewhere should use their own health department.
Healthcare cybersecurity
HHS Cyber GatewayOfficial sector guidance ↗Useful for: Healthcare and Public Health sector cybersecurity resources.Limit: Resources are voluntary unless another authority makes a requirement applicable.HHS HPH Cybersecurity Performance GoalsOfficial sector framework ↗Useful for: Prioritized healthcare cybersecurity outcomes.Limit: Goals do not by themselves demonstrate compliance or complete risk management.HHS Health Industry Cybersecurity PracticesOfficial sector guidance ↗Useful for: Health-industry practices and threat-oriented defensive planning.Limit: Implementation must be tailored to organizational size, systems, and clinical context.ASPR TRACIE Hospital Downtime Operations ChecklistOfficial operational guidance ↗Useful for: Healthcare downtime activation and operating considerations during cyber disruption.Limit: Hospital-oriented material; organizations must use approved local clinical and emergency procedures.CISA Cybersecurity Performance GoalsOfficial cross-sector framework ↗Useful for: High-impact baseline cybersecurity outcomes.Limit: Cross-sector guidance requires healthcare-specific consequence and workflow analysis.
Standards and frameworks
NIST Cybersecurity Framework 2.0Standards / framework ↗Useful for: Govern, Identify, Protect, Detect, Respond, and Recover outcomes for managing cyber risk.Limit: Outcome-based and non-prescriptive; it must be profiled for mission and risk.NIST SP 800-66 Revision 2Standards / framework ↗Useful for: Cybersecurity resource guide and control mappings for regulated health information environments.Limit: Technical resource only; it is not legal advice or a compliance determination.AAMI TIR57 Medical Device Security Risk ManagementStandards body guidance ↗Useful for: Medical-device security risk management in a safety-risk context.Limit: The full standard is licensed; applicability and implementation require qualified review.IEC 81001-5-1 Health Software Security LifecycleInternational standard ↗Useful for: Security activities across the health-software product lifecycle.Limit: The full standard is licensed and conformance cannot be inferred from this summary.
Medical device security
FDA Premarket Cybersecurity GuidanceOfficial regulatory guidance ↗Useful for: Manufacturer design, documentation, and premarket cybersecurity considerations.Limit: Read the current document and applicable requirements; this site does not interpret regulatory obligations.FDA Postmarket Cybersecurity GuidanceOfficial regulatory guidance ↗Useful for: Postmarket monitoring and vulnerability-management concepts.Limit: Device decisions require current FDA information, manufacturer input, and qualified review.Health-ISAC Medical Device SecuritySector guidance ↗Useful for: Coordinated disclosure education and manufacturer product-security links.Limit: Sector material complements but does not replace regulators, manufacturers, or local policy.Health-ISAC Device Lifecycle RolesSector guidance ↗Useful for: Shared manufacturer and healthcare-organization responsibilities over the device lifecycle.Limit: Sector synthesis; validate decisions against product evidence and official guidance.
Biosurveillance and One Health
CDC Wastewater MonitoringOfficial data guidance ↗Useful for: Program scope, methods context, update cadence, and limitations.Limit: Population-level signals do not diagnose individuals and preliminary data can change.WHO One Health Joint Plan of ActionOfficial multilateral framework ↗Useful for: Human, animal, plant, and environmental coordination framework.Limit: Strategic framework rather than a local operating procedure.
Peer-reviewed evidence
JAMA Health Forum Ransomware Trends StudyPeer-reviewed research ↗Useful for: Documented operational disruption in reported U.S. healthcare ransomware events.Limit: Historical observational data with incomplete public reporting; it does not predict a specific event.Critical Care Ransomware Spillover StudyPeer-reviewed research ↗Useful for: Evidence that regional cyber disruption can affect adjacent hospitals.Limit: Single-event observational design; association does not establish universal effects.Wastewater Surveillance Public Health Action ReviewPeer-reviewed research ↗Useful for: Evidence about when wastewater studies have informed public-health action.Limit: Scoping review of heterogeneous studies; actionability varies by target, program, and setting.Wastewater Surveillance Systematic ReviewPeer-reviewed research ↗Useful for: Breadth of pathogens studied and the need to connect signals with other surveillance.Limit: Study methods and evidence quality vary; wastewater is a complementary signal.