No items found.

Healthcare Cybersecurity Benchmarking Study: Strengthening Cyber Resilience Across the Industry

October 30, 2025

The Healthcare Cybersecurity Benchmarking Study is a groundbreaking initiative co-sponsored by Censinet, the American Hospital Association (AHA), and KLAS Research. It enables hospitals and health systems to compare their cybersecurity investments, resources, and performance to peer organizations. The study uses anonymized, aggregated data to provide actionable insights and benchmarks aligned with the NIST Cybersecurity Framework (NIST CSF) and Health Industry Cybersecurity Practices (HICP).

Key Features of the Healthcare Cybersecurity Benchmarking Study:

Comprehensive Benchmarks: Provides peer comparisons across cybersecurity investments, resources, and performance.
Framework Alignment: Uses NIST CSF and HICP to ensure benchmarks are actionable and aligned with industry standards.
Actionable Insights: Delivers automated action plans to address gaps and prioritize cybersecurity investments.
Collaboration Opportunities: Fosters a community of healthcare leaders working to strengthen cybersecurity across the industry.

Frequently Asked Questions

What is the Purpose of the Study?

The study aims to: Strengthen cybersecurity maturity and resilience across the healthcare industry. Provide healthcare organizations with tools to identify gaps in cybersecurity controls and prioritize investments. Foster collaboration and transparency among healthcare providers to reduce enterprise risk and protect patient safety.

What Frameworks Does the Study Use?

The study leverages two widely recognized frameworks: NIST Cybersecurity Framework (NIST CSF): A comprehensive framework for managing cybersecurity risks. Health Industry Cybersecurity Practices (HICP): A set of best practices tailored to the healthcare sector to address cybersecurity threats. These frameworks ensure that benchmarks are aligned with industry standards and provide actionable guidance for healthcare organizations.

What Are the Benefits of Participating in the Study?

Participating organizations receive several key benefits, including: Free Access to Benchmarking Modules: Full access to NIST CSF and HICP Benchmarking modules at no cost during and after the study (until March 31, 2023). Automated Action Plans: Guidance to identify critical gaps in cybersecurity controls and prioritize future investments. Peer Benchmarks: Detailed comparisons at the NIST CSF Subcategory level to inform resource allocation and performance improvement. Collaboration Opportunities: The chance to join a community of healthcare leaders working to strengthen industry-wide cybersecurity.

Why is the Study Important for Healthcare Organizations?

Cybersecurity is now a critical enterprise risk for hospitals and health systems, with threats like ransomware and data breaches jeopardizing patient safety and care delivery. The study provides healthcare organizations with the tools and insights needed to improve their cybersecurity maturity, reduce risks, and ensure compliance with industry standards. By participating, organizations can benchmark their performance against peers and make data-driven decisions to enhance their cybersecurity programs.

Who Are the Sponsors and Partners of the Study?

The study is co-sponsored by: Censinet: A leader in healthcare risk management solutions. American Hospital Association (AHA): A national organization representing nearly 5,000 hospitals and health systems, advocating for improved healthcare across the U.S.1. KLAS Research: A trusted source of insights for the healthcare IT industry. Leading health systems, including Baptist Health, Cedars-Sinai, Dayton Children’s, Fairview Health Services, Hartford HealthCare, Intermountain Healthcare, Marshfield Clinic Health System, and Mass General Brigham, are also sponsors.

How Can Healthcare Organizations Participate?

Healthcare organizations can enroll in the study by: Contacting benchmarks@censinet.com. Speaking with Censinet representatives at events like CHIME22 Fall Forum in San Antonio, TX. Participation is open to hospitals and health systems looking to improve their cybersecurity maturity and resilience.

Related Links