---
title: "HSCC JSP, HSCC Joint Security Plan | MedTech Terms"
description: "An industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity."
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/hscc-jsp#term",
        "name": "HSCC Joint Security Plan",
        "alternateName": "HSCC JSP",
        "description": "The Joint Security Plan (JSP), maintained by the Healthcare Sector Coordinating Council (HSCC), is an industry-developed reference framework for cybersecurity across the medical device and health IT product lifecycle - from design through end-of-life. The JSP provides templates, role-and-responsibility matrices, and shared expectations between manufacturers and Healthcare Delivery Organizations (HDOs). The current JSP 2.0 (2023) aligns with FDA's 2023 guidance and IMDRF N60/N73.",
        "url": "https://medtechterms.com/terms/hscc-jsp",
        "termCode": "hscc-jsp",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/hscc-jsp#article",
        "headline": "HSCC JSP, HSCC Joint Security Plan",
        "description": "An industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.",
        "url": "https://medtechterms.com/terms/hscc-jsp",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/hscc-jsp"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/hscc-jsp#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "HSCC Joint Security Plan, HSCC JSP, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-05-05",
        "dateModified": "2026-05-05",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "HSCC Joint Security Plan",
            "url": "https://healthsectorcouncil.org/the-joint-security-plan/",
            "publisher": {
              "@type": "Organization",
              "name": "HSCC"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "FDA Cybersecurity Guidance (Sept 2023)",
            "url": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions",
            "publisher": {
              "@type": "Organization",
              "name": "FDA"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "MDCG Cybersecurity Guidance",
            "url": "https://health.ec.europa.eu/medical-devices-sector/new-regulations/guidance-mdcg-endorsed-documents-and-other-guidance_en",
            "publisher": {
              "@type": "Organization",
              "name": "MDCG"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/section-524b#term",
            "name": "Section 524B of the FD&C Act",
            "alternateName": "524B",
            "url": "https://medtechterms.com/terms/section-524b"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/imdrf-cyber-principles#term",
            "name": "IMDRF Principles and Practices for Medical Device Cybersecurity",
            "url": "https://medtechterms.com/terms/imdrf-cyber-principles"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/premarket-cybersecurity#term",
            "name": "Premarket Cybersecurity Submission",
            "url": "https://medtechterms.com/terms/premarket-cybersecurity"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/legacy-device-cyber#term",
            "name": "Legacy Device Cybersecurity",
            "url": "https://medtechterms.com/terms/legacy-device-cyber"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/cvd#term",
            "name": "Coordinated Vulnerability Disclosure",
            "alternateName": "CVD",
            "url": "https://medtechterms.com/terms/cvd"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "HSCC Joint Security Plan",
            "item": "https://medtechterms.com/terms/hscc-jsp"
          }
        ]
      },
      {
        "@type": "FAQPage",
        "@id": "https://medtechterms.com/terms/hscc-jsp#faq",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "Is the JSP binding?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "No. It is industry-consensus guidance with strong public-private endorsement, not regulation. FDA cites it in the 2023 guidance as a recommended resource."
            }
          },
          {
            "@type": "Question",
            "name": "Where does the JSP overlap with IMDRF guidance?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "JSP 2.0 was deliberately aligned with IMDRF N60 and N73, so the lifecycle framings are compatible. JSP adds more operational templates than IMDRF documents typically do."
            }
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  HSCC Joint Security Plan

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)HSCC JSP 

# HSCC Joint Security Plan

An industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed May 5, 2026 

## Definition

The Joint Security Plan (JSP), maintained by the Healthcare Sector Coordinating Council (HSCC), is an industry-developed reference framework for cybersecurity across the medical device and health IT product lifecycle - from design through end-of-life. The JSP provides templates, role-and-responsibility matrices, and shared expectations between manufacturers and Healthcare Delivery Organizations (HDOs). The current JSP 2.0 (2023) aligns with FDA's 2023 guidance and  [IMDRF](/terms/imdrf) N60/N73. 

What the regulation says

FDA explicitly references the HSCC JSP in the 2023 guidance as an industry resource. HSCC products are public-private (CISA, HHS, FDA, manufacturers, HDOs), giving them quasi-regulatory weight in MedTech cybersecurity practice without binding legal authority. 

## What this means in practice

The JSP is most useful as a shared vocabulary between MedTech vendors and hospital security teams. Procurement contracts increasingly reference JSP roles and responsibilities, and manufacturers that align to it have an easier conversation with HDO security committees. 

Common pitfalls

-   • Treating the JSP as a checkbox rather than tailoring its templates to your product and supply chain. 
-   • Ignoring the HDO-side responsibilities - leaves operators uncertain about what they need to do. 

## Frequently asked questions

Is the JSP binding? 

No. It is industry-consensus guidance with strong public-private endorsement, not regulation. FDA cites it in the 2023 guidance as a recommended resource. 

Where does the JSP overlap with IMDRF guidance? 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

Coordinated Vulnerability Disclosure(CVD) 

A documented process for receiving, triaging, and responsibly disclosing security vulnerabilities reported by external researchers.





](/terms/cvd)[

Cybersecurity

IMDRF Principles and Practices for Medical Device Cybersecurity

International harmonized guidance on medical-device cybersecurity from the IMDRF Cybersecurity Working Group.





](/terms/imdrf-cyber-principles)[

Cybersecurity

Legacy Device Cybersecurity

Cybersecurity considerations for medical devices that cannot be reasonably protected against current threats.





](/terms/legacy-device-cyber)[

Cybersecurity

Premarket Cybersecurity Submission

The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.





](/terms/premarket-cybersecurity)

### More in Cybersecurity

· Same category 

[

Cybersecurity

Section 524B of the FD&C Act(524B) 

The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.





](/terms/section-524b)[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)[

Cybersecurity

AAMI TIR57

AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.





](/terms/aami-tir57)[

Cybersecurity

AAMI TIR97(TIR97) 

AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.





](/terms/aami-tir97)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (1)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

HSCC· 1 FDA· 1 MDCG· 1 

1.  [1 
    
    HSCC Joint Security Plan
    
    Verified 
    
    HSCC · healthsectorcouncil.org 
    
    
    
    ](https://healthsectorcouncil.org/the-joint-security-plan/)
2.  [2 
    
    FDA Cybersecurity Guidance (Sept 2023)
    
    Verified 
    
    FDA · fda.gov 
    
    
    
    ](https://www.fda.gov/regulatory-information/search-fda-guidance-documents/cybersecurity-medical-devices-quality-system-considerations-and-content-premarket-submissions)
3.  [3 
    
    MDCG Cybersecurity Guidance
    
    Verified 
    
    MDCG · health.ec.europa.eu 
    
    
    
    ](https://health.ec.europa.eu/medical-devices-sector/new-regulations/guidance-mdcg-endorsed-documents-and-other-guidance_en)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Acronym

HSCC JSP

Sources

3

Updated

5/5/2026

[Compare with another term](/compare?a=hscc-jsp)

Learn in 60 seconds

Card Lesson Quiz

An industry-developed reference framework from the Healthcare Sector Coordinating Council for end-to-end MedTech cybersecurity.

-   · The JSP is most useful as a shared vocabulary between MedTech vendors and hospital security teams. 
-   · Procurement contracts increasingly reference JSP roles and responsibilities, and manufacturers that align to it have an easier conversation with HDO security committees. 
-   · The JSP provides templates, role-and-responsibility matrices, and shared expectations between manufacturers and Healthcare Delivery Organizations (HDOs). 

Remember this

Watch out: Treating the JSP as a checkbox rather than tailoring its templates to your product and supply chain.

Related terms

-   [Section 524B of the FD&C Act(524B) ](/terms/section-524b)
-   [IMDRF Principles and Practices for Medical Device Cybersecurity ](/terms/imdrf-cyber-principles)
-   [Premarket Cybersecurity Submission ](/terms/premarket-cybersecurity)
-   [Legacy Device Cybersecurity ](/terms/legacy-device-cyber)
-   [Coordinated Vulnerability Disclosure(CVD) ](/terms/cvd)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [NIST IR 8473, Cybersecurity Framework Profile for HPH(NIST IR 8473) ](/terms/nist-cswp-35)
-   [IEC 80001-1 ](/terms/iec-80001)
-   [NIST Cybersecurity Framework(NIST CSF) ](/terms/nist-csf)
-   [Secure Product Development Framework(SPDF) ](/terms/spdf)
-   [Health Industry Cybersecurity Practices(HICP) ](/terms/hicp)
-   [Health Information Sharing and Analysis Center(H-ISAC) ](/terms/h-isac)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)