> ## Content Index
> Fetch the complete content index at: https://www.fdaweb.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Joint Security Plan on Cybersecurity Challenges
- URL: https://www.fdaweb.com/joint-security-plan-on-cybersecurity-challenges/
- Published: 2019-01-30T12:00:00.000Z
- Updated: 2026-09-15T00:58:54.000Z
- Author: David McFarland
- Tags: Devices, #legacy-id-D5143258

The Healthcare and Public Sector Coordination Council Joint Cybersecurity Working Group, of which FDA is a member, has produced a Joint Security Plan (JSP) to address cybersecurity challenges in using software-based medical technologies. The [document](https://healthsectorcouncil.org/wp-content/uploads/2019/01/HSCC-MEDTECH-JSP-v1.pdf?ref=fdaweb.com) says the challenges include but are not limited to transparency and disclosure between vendors and end users, security by design and throughout the product lifecycle, and product end of life.

The plan includes: 

- cybersecurity practices in design and development of medical technology products;
- handling product complaints relating to cybersecurity incidents and vulnerabilities;
- managing security risk throughout the lifecycle of medical technology; and
- assessing the maturity of a product cybersecurity program.

“The JSP is voluntary and seeks to aid organizations (medical device manufacturers, healthcare information technology vendors, and healthcare providers) in enhancing their product cybersecurity irrespective of organization size or maturity,” the document says. “It is intended to be globally applicable, inspire organizations to raise the bar for product cybersecurity, and is expected to evolve as product cybersecurity evolves. As such, it is anticipated that there will be future iterations of the JSP and feedback on this initial version is welcome. It is important for medical device manufacturers and health IT vendors … to consider the JSP’s voluntary framework and its associated plans and templates throughout the lifecycle of medical devices and health IT because doing so is expected to result in better security and thus better products for patients…. Our primary ask of organizations is to make a commitment to implementing the JSP as it is expected that patient safety will be positively impacted as a result.”