Endpoint/Device Security, Vulnerability Management
New HSCC insights target cybersecurity contract language for medical tech

Medical devices are a crucial piece to any healthcare delivery organizations, but remain a key security risk for the sector. New HSCC guidance targets the relationship between manufacturers and delivery organizations beginning at the contract process. (Photo by Manuel Medir/Getty Images)
New insights from the Healthcare and Public Health Sector Coordinating Council (HSCC) Cybersecurity Working Group targets the oft-uneven relationship between medical device manufacturers and delivery organizations that lead to maturity and security challenges in the healthcare sector.The provided framework for cybersecurity contract terms and conditions aims to improve patient safety, while reducing complexity and costs of the contract process.HSCC is an advisory council comprised of health companies and providers, focused on the development of collaborative tools to mitigate threats posed to the healthcare sector. Its working group is made up of over 300 provider entities, medical device and health IT companies, and other related entities.The “Model Contract-Language for Medtech Cybersecurity (MC2),” was jointly compiled by Mayo Clinic, Siemens Healthineers, and Premier over the course of the last two years, in response to the systemic challenges of medical device security.Claroty report showed over half of the vulnerabilities in end-of-life devices are remotely exploitable.
The process involved “pre-negotiating” the model contract language outlined in the framework, which inevitably led to an increase in mutual understanding and trust between manufacturers and providers. HSCC added, “The sector owes the leaders and members of the task group its thanks and congratulations.”Transparency into device challenges has drastically improved across healthcare for the last few years, recognizing that uneven investments, infrastructure complexities, patch management and inventory issues, and other visibility challenges hinder real progress on the security front.The joint project targets accountability challenges faced between medical device manufacturers and health delivery organizations, such as manufacturer design and production capabilities, investments in cybersecurity controls, and varied security expectations of the providers they serve.The insights also address the high costs of cybersecurity management in the health system operational environment throughout the device lifecycle. A recent Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds