Health Sector Coordinating Council - Cybersecurity
The Health Sector Coordinating Council Cybersecurity Working Group is a government-recognized, industry-led non-profit advisory coalition of 480+ healthcare organizations that develops and publishes freely available cybersecurity frameworks, strategic plans, and policy recommendations for the U.S. healthcare sector under PPD-21.
- Company typePrivate
- Founded2016
- Headquarters—
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Health Sector Coordinating Council - Cybersecurity does
The Health Sector Coordinating Council (HSCC) Cybersecurity Working Group (CWG) is a government-recognized, industry-led non-profit advisory council that develops and publishes freely available cybersecurity best practices, frameworks, and policy recommendations for the U.S. healthcare sector. The organization operates as a coalition of more than 480 member organizations spanning healthcare delivery providers, medical device and health IT manufacturers, pharmaceutical companies, payers, health IT vendors, and federal agencies (HHS, CISA, FDA), and it holds formal standing as the critical infrastructure industry partner under Presidential Policy Directive 21.
Its core output consists of approximately 40 named publications organized across strategic planning (Health Industry Cybersecurity Strategic Plan 2024-2029), medical device security (Joint Security Plan version 2, Model Contract Language for MedTech Cybersecurity v2, Medtech Vulnerability Communications Toolkit), incident response (Coordinated Healthcare Incident Response Plan, Medical Product Manufacturer Cyber Incident Response Playbook, Cyber Incident Response Executive Checklist), risk management (HIC-MaLTS legacy technology guide, HIC-SCRiM supply chain guide, SMART Toolkit), AI cybersecurity governance (AI Cyber Glossary, AI Cybersecurity Governance Framework, Third-Party AI Risk Guide), workforce development, telehealth security, and framework implementation (NIST CSF Implementation Guide). All publications are developed through multi-stakeholder consensus and distributed at no cost.
The business model is non-commercial: there are no priced products, no subscription tiers, and no revenue from publications. Operations are funded through voluntary membership contributions and government partnership support, with a 1-10 person paid staff led by Executive Director Greg Garcia and Chairman Erik Decker (CISO, Intermountain Health). The council extends its reach through congressional testimony, regulatory comments, government advisory relationships, industry events, and a partnership with Health-ISAC for threat information sharing. Geographic operations are concentrated in the United States.
Health Sector Coordinating Council - Cybersecurity firmographics
Firmographics- Name
- Health Sector Coordinating Council - Cybersecurity
- Legal name
- Health Sector Coordinating Council
- Website
- https://healthsectorcouncil.org
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- The Health Sector Coordinating Council Cybersecurity Working Group is a government-recognized, industry-led non-profit advisory coalition of 480+ healthcare organizations that develops and publishes freely available cybersecurity frameworks, strategic plans, and policy recommendations for the U.S. healthcare sector under PPD-21.
- Ownership category
- akta.pro rank
Health Sector Coordinating Council - Cybersecurity industry classification
Industry- Product category
- Healthcare Cybersecurity Advisory
- NAICS
- Business Associations (813910), Professional Organizations (813920), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Membership Organizations (8600), Services-Health Services (8000)
- akta.pro primary industry
- Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF)
- akta.pro secondary industries
- Backup, Disaster Recovery & Ransomware Resilience for Healthcare (HLACAJAO), Health Systems Strengthening & Primary Care Development (HLAJAKAJ)
Keywords
Health Sector Coordinating Council - Cybersecurity business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales
Revenue model
- Membership Dues/Fees: HSCC CWG operates as a non-profit industry coalition. Membership is voluntary and organizations join to participate in developing cybersecurity best practices and policy recommendations. The organization appears to be funded through membership contributions and may receive support from government partnerships.
- Freely Available Publications: All cybersecurity leading practices and policy recommendations are published freely as public resources for the healthcare sector. No revenue is generated from these publications.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Freely available publications and resources |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels6 records
Health Sector Coordinating Council - Cybersecurity product offering
Product offeringCore offering
The Health Sector Coordinating Council (HSCC) Cybersecurity Working Group is a government-recognized critical infrastructure industry advisory council comprising over 400 healthcare organizations. It develops and publishes freely-available cybersecurity frameworks, guidance documents, model contracts, toolkits, and policy recommendations covering strategic planning, medical device security, AI cybersecurity governance, incident response, supply chain risk, and workforce development for the healthcare sector.
Product overview
The Health Sector Coordinating Council (HSCC) Cybersecurity Working Group is NOT a traditional software product company. Rather, it is a government-recognized critical infrastructure industry advisory council comprising over 400-490 healthcare organizations that develops and publishes freely-available cybersecurity guidance, frameworks, best practices, and policy recommendations for the healthcare sector. The portfolio consists of multiple named publications organized under key focus areas: (1) Strategic Planning - Health Industry Cybersecurity Strategic Plan (HIC-SP); (2) AI Cybersecurity - AI Cyber Glossary, AI Cybersecurity Governance Framework Implementation Guide, Third-Party AI Risk and Supply Chain Transparency Guide; (3) Medical Device Security - Joint Security Plan (JSP/JSP2), Model Contract-Language for MedTech Cybersecurity (MC2), Medtech Vulnerability Communications Toolkit (MVCT); (4) Incident Response - Coordinated Healthcare Incident Response Plan (CHIRP), MPM Cyber Incident Response Playbook, OCCI Checklist, Executive Checklist; (5) Risk Management - HIC-MaLTS, HIC-SCRiM, SMART Toolkit; (6) Privacy & Telehealth - HIC-CPSP, HIC-STAT; (7) Workforce & Training - Cybersecurity for Clinician Video Series, HIC Workforce Guide; and (8) Framework Implementation - NIST CSF Implementation Guide, HICP. All publications are free public resources developed collaboratively by healthcare industry and government partners.
Differentiator
Problem solved
Functional benefit
Brands
- Health Industry Cybersecurity Strategic Plan (HIC-SP): A call to action for healthcare ecosystem organizations to implement foundational cybersecurity programs addressing operational, technological, and governance challenges (2024-2029).
- Medical Device and Health IT Joint Security Plan (JSP)
- Health Industry AI Cyber Governance Framework
- Third-Party AI Risk and Supply Chain Transparency Guide
- AI Cyber Glossary
Products and services
- Health Industry Cybersecurity Strategic Plan (HIC-SP) Five-year strategic plan (2024-2029) providing a call to action for healthcare ecosystem organizations to implement foundational cybersecurity programs addressing operational, technological, and governance challenges.
- Health Industry Cybersecurity Practices (HICP)
Quantifiable outcome
- HIPAA data breaches nearly doubled to 725 in 2023 since 2018, highlighting the critical need for HSCC guidance
- +2 more outcomes
Companies that use Health Sector Coordinating Council - Cybersecurity
Customer profileNamed customers9 records
Segments7 records
Ideal customer profiles5 records
Health Sector Coordinating Council - Cybersecurity technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability9 records
Feature7 records
Health Sector Coordinating Council - Cybersecurity partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered minor and core.
- Medical Device Innovation Consortium (MDIC)minorMDIC partnered with HSCC and Booz Allen Hamilton to prepare a benchmarking report on progress in medical device cybersecurity, supporting JSP development.
- U.S. Department of Health and Human Services (HHS)coreHHS is the primary government partner for HSCC CWG. The council is recognized by the HHS Secretary as the critical infrastructure industry partner under PPD-21. HSCC and HHS jointly develop publications including Health Industry Cybersecurity Practices (HICP), Hospital Cyber Resiliency Landscape Analysis, and NIST CSF Implementation Guide. HHS 405(d) Program works with HSCC on cybersecurity practices alignment.
- Cybersecurity and Infrastructure Security Agency (CISA)coreCISA is a key government partner for cross-sector cybersecurity coordination. HSCC provides comments on CISA cybersecurity performance goals and aligns health sector resources with CISA frameworks. Joint work on critical infrastructure protection and incident response coordination.
- U.S. Food and Drug Administration (FDA)coreFDA's Center for Devices and Radiological Health partners with HSCC on medical device cybersecurity. FDA co-chairs the JSP Task Group and participates in developing Joint Security Plan guidance. FDA regulatory work aligns with HSCC publications for medical device security.
- Health Information Sharing and Analysis Center (Health-ISAC)coreHealth-ISAC is a trusted community of healthcare critical infrastructure owners and operators for sharing threat intelligence. HSCC and Health-ISAC collaborate on CIRCIA comments, joint publications, and coordinated responses to cyber incidents affecting the healthcare sector.
- Intermountain HealthcarecoreIntermountain Healthcare serves as co-lead of the HIC-MaLTS Task Group and Chairman Erik Decker leads the overall CWG. Major contributor to legacy technology security guidance and strategic planning.
- MedtroniccoreMedtronic Vice President Chris Reed co-chairs the JSP Task Group. Major medical device manufacturer contributing to product security guidance development.
- ElektacoreElekta co-led the HIC-MaLTS Task Group, contributing to legacy technology security guidance for the healthcare sector.
Scale indicators9 records
Recent moves6 records
Expansion highlights5 records
Health Sector Coordinating Council - Cybersecurity competitors and assessment
Company assessmentBroad incumbents
- National Institute of Standards and Technology (NIST): Federal body issuing the Cybersecurity Framework that HSCC's NIST CSF Implementation Guide operationalizes for healthcare. Functions as the upstream standards authority whose output HSCC adapts for sector use.
- American Hospital Association (AHA): Larger healthcare industry association with broader policy mandate but overlapping healthcare cybersecurity advocacy. Many AHA member hospitals are also HSCC CWG participants, making AHA a structural peer for healthcare-sector convening.
- Cybersecurity and Infrastructure Security Agency (CISA): Federal agency that publishes cross-sector cybersecurity performance goals which HSCC members adapt for healthcare. HSCC's value proposition is partly defined by translating CISA's broad guidance into sector-specific operational practice.
- HITRUST: Healthcare-focused cybersecurity assurance and certification organization. Provides certifiable frameworks that overlap with HSCC's voluntary best-practice approach, offering healthcare providers a paid, auditable alternative to HSCC's free guidance.
Direct peers
- Medical Device Innovation Consortium (MDIC): Public-private partnership that partnered with HSCC on medical device cybersecurity benchmarking and JSP development. Comparable nonprofit coalition model focused on medical device security and lifecycle risk.
- Health Information Sharing and Analysis Center (Health-ISAC): Healthcare-focused ISAC for threat intelligence sharing among critical infrastructure owners. HSCC names Health-ISAC as a core partner for CIRCIA comments and joint incident response, indicating substantial operational overlap in serving the same healthcare cyber community.
- Financial Services Information Sharing and Analysis Center (FS-ISAC): Sector-based ISAC model that HSCC's healthcare counterpart explicitly mirrors. Same industry-coalition structure, same PPD-21 critical infrastructure designation logic, comparable threat-sharing mandate in financial services.
- HHS 405(d) Program: Government program that jointly develops healthcare cybersecurity practices with HSCC, including HICP. Operates as a co-author and primary federal channel for HSCC content, making it the closest institutional peer in mission and output.
Emerging players
- MedSec: Healthcare and medical device cybersecurity consultancy whose leadership (Debra Bruemmer, formerly Mayo Clinic) co-chairs HSCC's JSP initiative. Demonstrates the boundary between HSCC volunteer leadership and the commercial cybersecurity services market.
- Claroty: Commercial cybersecurity vendor specializing in medical device and operational technology security. Represents the private-sector alternative to HSCC's voluntary medical device security guidance (JSP2, MC2), with paid product offerings.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Health Sector Coordinating Council - Cybersecurity social profiles
Digital presenceHealth Sector Coordinating Council - Cybersecurity financial estimates
Financial estimateRevenue estimate
Valuation estimate
Health Sector Coordinating Council - Cybersecurity leadership team
Management profileNumber of profiles
Profiles8 records
Health Sector Coordinating Council - Cybersecurity funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Health Sector Coordinating Council - Cybersecurity M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Health Sector Coordinating Council - Cybersecurity
What does Health Sector Coordinating Council - Cybersecurity do?
The Health Sector Coordinating Council (HSCC) Cybersecurity Working Group is a government-recognized critical infrastructure industry advisory council comprising over 400 healthcare organizations. It develops and publishes freely-available cybersecurity frameworks, guidance documents, model contracts, toolkits, and policy recommendations covering strategic planning, medical device security, AI cybersecurity governance, incident response, supply chain risk, and workforce development for the healthcare sector.
Is Health Sector Coordinating Council - Cybersecurity a public or private company?
Health Sector Coordinating Council - Cybersecurity is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Health Sector Coordinating Council - Cybersecurity founded?
Health Sector Coordinating Council - Cybersecurity was founded in 2016. It employs 1 to 10 people.
How does Health Sector Coordinating Council - Cybersecurity make money?
Two revenue lines are on record. Membership Dues/Fees are the primary driver. The others are freely Available Publications.
Who are Health Sector Coordinating Council - Cybersecurity's main competitors?
Broad incumbents on record are National Institute of Standards and Technology (NIST), American Hospital Association (AHA), Cybersecurity and Infrastructure Security Agency (CISA) and HITRUST. Direct peers are Medical Device Innovation Consortium (MDIC), Health Information Sharing and Analysis Center (Health-ISAC), Financial Services Information Sharing and Analysis Center (FS-ISAC) and HHS 405(d) Program. Emerging players are MedSec and Claroty.
Does Health Sector Coordinating Council - Cybersecurity have an API?
No public API is recorded for Health Sector Coordinating Council - Cybersecurity.
What industry is Health Sector Coordinating Council - Cybersecurity in?
Health Sector Coordinating Council - Cybersecurity's product category is Healthcare Cybersecurity Advisory. Its primary akta.pro industry code is BPAHAFAF, Privacy, Data Protection & Cyber Governance (GRC), with a secondary code of HLACAJAO, Backup, Disaster Recovery & Ransomware Resilience for Healthcare. Its NAICS code is 813910 and its SIC code is 8600.