HSCC Updates Model Contract Language to Improve Medical Device Cybersecurity

When negotiating contracts with medical device manufacturers (MDMs), the responsibility for ensuring the cybersecurity of the devices throughout the product lifecycle must be clearly stated in the terms of the contract. Cybersecurity is a shared responsibility between a healthcare delivery organization (HDO) and an MDM. The MDM must ensure that certain cybersecurity controls are implemented to ensure the security of their devices, and there are Food and Drug Administration (FDA) requirements that must be adhered to. By their very nature, medical devices collect, store, and transmit patient data, and HDOs must ensure that protected health information is safeguarded to ensure compliance with the HIPAA Rules.

According to the Health Sector Coordinating Council (HSCC), ambiguities in cybersecurity and accountability between MDMs and HDOs have historically been reconciled inconsistently in purchase contract negotiations, leading to inadequate security measures, downstream disputes, and potential patient safety implications. HDOs negotiate contracts with many different MDMs, and miscommunications between HDOs and MDMs have led to inconsistent contract terminology, resulting in cybersecurity responsibility and accountability ambiguity. To address the issue, in 2020, HSCC formed a Cybersecurity Working Group (CWG) consisting of 50 representatives from HDOs, MDMs, and security and compliance specialists, and in 2022, the HSCC CWG released Model Contract Language that can be referenced during contract negotiations.

The Model Contract Language serves as a pre-negotiated contract that is scalable and can be used by organizations of different sizes with varying security needs. HSCC received comments and feedback on the Model Contract Language, and last year, the HSCC CWG reconvened to assess almost 100 comments on the Model Contract Language. After careful consideration of the feedback, changes have been made to the Model Contract Language, along with updates to align with the healthcare industry’s increasing security maturity and changes to the regulatory environment.

HSCC has now released Version 2 of its Model Contract Language, which serves as an updated reference for shared cooperation and coordination between HDOs and MDMs regarding compliance, management, maintenance, operation, and the security of medical devices, solutions, and connections. The Model Contract Language is as important as ever. “In today’s partnership between HDOs and MDMs, cybersecurity requirements are often unclear, resulting in a lack of understanding and prioritization of cybersecurity best practices,” explained HSCC. “For HDOs and MDMs alike, this leads to an investment in security controls that are not always aligned between stakeholders.”

The Model Contract Language is split into three pillars: maturity, product design maturity, and performance, with contract clauses within each pillar divided into 14 core principles. The Model Contract Language provides HDOs with contract terms that can be used as a standalone agreement covering HDO cybersecurity requirements for all medical products, services, and solutions, or it can be used as an addendum to a Business Associate Agreement (BAA), Master Service Agreement (MSA), or for Requests for Proposals (RFP).

The updated Model Contract Language will help to reduce ambiguities between HDOs and MDMs, simplify the contracting process, ensure cybersecurity responsibilities are clearly stated, and make the contracting process more predictable, less costly, and less time-consuming.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/