HSCC Joint Security Plan
An industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.
Definition
The Joint Security Plan (JSP), maintained by the Healthcare Sector Coordinating Council (HSCC), is an industry-developed reference framework for cybersecurity across the medical device and health IT product lifecycle - from design through end-of-life. The JSP provides templates, role-and-responsibility matrices, and shared expectations between manufacturers and Healthcare Delivery Organizations (HDOs). The current JSP 2.0 (2023) aligns with FDA's 2023 guidance and IMDRF N60/N73.What this means in practice
The JSP is most useful as a shared vocabulary between MedTech vendors and hospital security teams. Procurement contracts increasingly reference JSP roles and responsibilities, and manufacturers that align to it have an easier conversation with HDO security committees.- •Treating the JSP as a checkbox rather than tailoring its templates to your product and supply chain.
- •Ignoring the HDO-side responsibilities - leaves operators uncertain about what they need to do.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsA documented process for receiving, triaging, and responsibly disclosing security vulnerabilities reported by external researchers.
International harmonized guidance on medical-device cybersecurity from the IMDRF Cybersecurity Working Group.
Cybersecurity considerations for medical devices that cannot be reasonably protected against current threats.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
More in Cybersecurity
· Same categoryThe federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Primary references
3 sources- 1
HSCC Joint Security PlanVerifiedHSCChealthsectorcouncil.org
- 2
FDA Cybersecurity Guidance (Sept 2023)VerifiedFDAfda.gov
- 3
MDCG Cybersecurity GuidanceVerifiedMDCGhealth.ec.europa.eu
Inline markers like [1] jump to the matching reference above.