I work in the UK Health Industry - our requirements are a little more precise than this
However, the UK Government and our National Cyber Security Centre (NCSC) have both published new guidelines and the guidance I've published internally to our staff reference those.