📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Governance, risk & compliance

HSCC Medical Device and Health IT Joint Security Plan v2.0 (March 2024)

A voluntary secure-product-development framework written by the Healthcare and Public Health Sector Coordinating Council for the medical device and health IT sector, published March 2024.

It describes how a manufacturer runs product security across the life cycle: security risk management, secure design, a software bill of materials, third-party component monitoring, coordinated vulnerability disclosure, product security incident response, and end-of-support communication. It is not a certification and there is nobody to certify you - a manufacturer follows it and says so.

Its value in a submission is that it is free, readable, and written by the sector, so naming it answers the question of what method you followed without claiming a conformity you have not declared. Where you need a standard you can declare conformity to instead, that is IEC 81001-5-1 for the life cycle and ANSI/AAMI SW96 for security risk management, both catalogued separately.

Assessment tiers & levels Lavawall supports

Lavawall assesses HSCC Medical Device and Health IT Joint Security Plan at every level below, so you can start where you are and step up as your program matures.

Tier / levelWhat it coversBuilds on lower
Joint Security PlanThe product security practices in JSP v2.0, applied across the life cycle. One tier, because the JSP is not written in levels.Yes

How Lavawall® helps you get to HSCC Medical Device and Health IT Joint Security Plan compliance

Most of HSCC Medical Device and Health IT Joint Security Plan comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to HSCC Medical Device and Health IT Joint Security Plan, and tracks your posture continuously instead of once a year at audit time.

  • Assess your current state against HSCC Medical Device and Health IT Joint Security Plan in the Lavawall GRC module, with the questionnaire and control set built in.
  • Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
  • Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.

Related

Lavawall® supports HSCC Medical Device and Health IT Joint Security Plan as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.

At a glance

Framework
HSCC Medical Device and Health IT Joint Security Plan v2.0 (March 2024)
Category
Industry
Region
Global
Levels
1 assessment tiers

Official source →


Map this framework freeTalk to our team

Data residency: We place your data and our AI processing in the region your obligations require: Canada, the United States, Europe, or Australia. How data residency works →