Governance, risk & compliance
HSCC Medical Device and Health IT Joint Security Plan v2.0 (March 2024)
A voluntary secure-product-development framework written by the Healthcare and Public Health Sector Coordinating Council for the medical device and health IT sector, published March 2024.
It describes how a manufacturer runs product security across the life cycle: security risk management, secure design, a software bill of materials, third-party component monitoring, coordinated vulnerability disclosure, product security incident response, and end-of-support communication. It is not a certification and there is nobody to certify you - a manufacturer follows it and says so.
Its value in a submission is that it is free, readable, and written by the sector, so naming it answers the question of what method you followed without claiming a conformity you have not declared. Where you need a standard you can declare conformity to instead, that is IEC 81001-5-1 for the life cycle and ANSI/AAMI SW96 for security risk management, both catalogued separately.
Assessment tiers & levels Lavawall supports
Lavawall assesses HSCC Medical Device and Health IT Joint Security Plan at every level below, so you can start where you are and step up as your program matures.
| Tier / level | What it covers | Builds on lower |
|---|---|---|
| Joint Security Plan | The product security practices in JSP v2.0, applied across the life cycle. One tier, because the JSP is not written in levels. | Yes |
How Lavawall® helps you get to HSCC Medical Device and Health IT Joint Security Plan compliance
Most of HSCC Medical Device and Health IT Joint Security Plan comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to HSCC Medical Device and Health IT Joint Security Plan, and tracks your posture continuously instead of once a year at audit time.
- Assess your current state against HSCC Medical Device and Health IT Joint Security Plan in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Lavawall® supports HSCC Medical Device and Health IT Joint Security Plan as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.
At a glance
- Framework
- HSCC Medical Device and Health IT Joint Security Plan v2.0 (March 2024)
- Category
- Industry
- Region
- Global
- Levels
- 1 assessment tiers
Map this framework freeTalk to our team