HHS Recommends Including Deception Technology as a Critical Component of Cybersecurity Practices for Healthcare Organizations
The Healthcare and Public Health Sector Coordinating Council, through the HHS 405(d) Program, publishes the Health Industry Cybersecurity Practices (HICP) Technical Volume 2: Cybersecurity Practices for Medium and Large Healthcare Organizations, a 140-page guide for security teams at medium and large healthcare organizations, most recently updated in 2023. Among its recommendations, the guide names deception technology as a critical component of a comprehensive security posture for healthcare delivery organizations, alongside the layered defenses that Section 8.1.F covers in detail. Deception technology creates decoys and traps that mislead attackers, and the guide values it for two reasons: it helps detect an intrusion in progress, and it reveals the attacker’s methods, techniques, and procedures on healthcare-specific systems.
At a glance
- HHS names deception technology a critical component of a comprehensive security posture for healthcare organizations, detailed in Section 8.1.F of HICP Technical Volume 2.
- The guide cites three benefits: shorter attacker dwell time, better threat intelligence, and stronger situational awareness.
- Recommended use cases include APT attacks, insider threats, ransomware, and identity threat detection and response.
- Acalvio is a Leader and Outperformer in the GigaOm Radar for Deception Technology, four consecutive years, most recently 2026.
What HHS recommends and why
HHS recommends deception technology because it directly supports three outcomes healthcare security teams already track: it shortens how long an attacker can operate inside the network undetected, it sharpens threat intelligence about how that attacker actually moves, and it strengthens situational awareness across clinical and IT systems.
- Reducing the time an attacker has to spend in the network, through early detection and misdirection
- Improving threat intelligence through insight into attacker behavior
- Increasing situational awareness through early warning of an attack in progress
The report also covers deployment methods such as honeypots, honeytokens, and decoys. Section 8.1.F explains how healthcare delivery organizations can use these layered defenses to disrupt an attack, provide early warning of an intrusion, and limit the impact of an attack that succeeds.
How deception supports compliance frameworks
HHS is one of several federal and industry bodies now recommending deception technology inside a broader security program, alongside frameworks that ask organizations to show detection and response capability rather than prevention alone. Deception generates high-confidence evidence of an intrusion attempt, engagement timestamps, attacker behavior, and the assets touched, which security teams can carry into an audit or an incident review to demonstrate active detection and response, without deception itself standing in for any single named control or replacing the underlying framework’s own requirements. Acalvio’s ShadowPlex Preemptive Cybersecurity Platform also holds FedRAMP authorization for its cloud offerings, which healthcare organizations can factor into their own cloud compliance planning alongside existing controls.
Deception use cases in healthcare
ShadowPlex applies the same decoy-based detection across four attack types healthcare security teams see most often, plus the connected devices unique to clinical environments.
Advanced persistent threats
Advanced persistent threat groups pose a particular risk in healthcare because their patient, stealthy approach blends into the ordinary background noise of a hospital network, which is exactly what a decoy is built to expose regardless of how long the group has already been inside.
Insider threats
Insider threats strain tools that judge behavior against a baseline, since valid credentials and normal access patterns look the same whether the activity is routine or malicious. A decoy asset removes that ambiguity: no legitimate employee has a reason to touch it, so a single interaction is a high-confidence signal.
Ransomware
Ransomware operators increasingly design their techniques around what signature and behavior-based tools already expect to see, which is why a decoy that does not depend on a behavior baseline can still flag the activity that reaches it.
Identity threat detection and response
Identity threat detection and response uses deceptive identities and credentials to catch credential misuse directly. When an attacker interacts with one of these decoys, ShadowPlex Identity Protection raises a high-confidence alert carrying the evidence a SOC needs to substantiate the activity, which can shorten investigation time.
Medical devices and IoT
Network-connected medical devices and other IoT equipment often cannot run an agent or take a conventional patch on the schedule security teams would prefer, which is part of why HHS also points to deception for this category: a decoy draws the same attacker interest as a real device, without requiring anything installed on equipment that cannot support it.
Recognition among EDR vendors
Endpoint detection and response vendors have taken note, with CrowdStrike partnering with Acalvio.
A second HHS framework
A related HHS document, the HHS Cybersecurity Program’s Cybersecurity Framework Profile for Healthcare Delivery Organizations, also emphasizes deception’s role against threats such as social engineering and attacks on network-connected equipment that resist conventional protection methods.
Ransomware kill chains in healthcare
A ransomware attack in a hospital moves through credential misuse, privilege escalation, and backup deletion before it ever encrypts a file, and a decoy placed along any of those stages can raise a high-confidence alert well before encryption begins. A compromised account has no legitimate reason to touch a decoy at any of those stages, so the alert lands while an operator is still moving through the network, not after the ransom note appears. Timing matters more in healthcare than elsewhere, since downtime during encryption or recovery can delay patient care rather than only business operations, which raises the value of catching the attack early.
Deception technology receiving this recommendation matters in practice, not only on paper: healthcare organizations already deploying cyber deception report benefits toward patient safety and well-being, addressing threats across IT, operational technology, and cloud environments alike. Schedule a consultation to see how 360 Deception applies these HHS-recommended practices.
Frequently asked questions
Yes. The HHS 405(d) Program’s HICP Technical Volume 2 names deception technology a critical component of security for medium and large healthcare organizations, citing shorter dwell time, better threat intelligence, and stronger situational awareness.
Deception produces high-confidence evidence, engagement timestamps, attacker behavior, and the assets touched, that security teams can use in an audit or incident review to demonstrate active detection and response, alongside other controls a compliance framework already requires.
Ransomware moves through credential misuse, privilege escalation, and backup deletion before it encrypts anything, and a decoy placed at any of those stages raises a high-confidence alert on contact, catching the operator while still moving rather than after the ransom note appears.
