The Health Sector Coordinating Council (HSCC) has released a new, free guidance document called the Health Industry Cybersecurity Sector Mapping and Risk Toolkit (SMART) to assist healthcare organizations in managing third-party risk. The toolkit is designed to address the complex and persistent challenges posed by third-party security and supply-chain risk in the healthcare sector, which faces a vast array of vendors providing mission-critical products and services. Developed over 16 months, the SMART Toolkit involved collaboration among 80 organizations spanning all healthcare subsectors, including patient care providers, insurance companies, laboratories, pharmaceutical and blood services, medical technology firms, public health entities, and health IT providers. The toolkit offers templates and a structured methodology to help organizations visualize, identify, and measure systemic risk associated with third-party technology, software, and communications services. It recognizes that not all vendors pose the same level of risk and provides guidance to help teams prioritize their risk management efforts accordingly. The SMART Toolkit aims to empower healthcare entities of all sizes and types, from small clinics to large hospital systems, to make informed decisions about vendor risk. By mapping and ranking third-party risks, the toolkit supports organizations in allocating resources more effectively and strengthening their overall cybersecurity posture. The guidance is intended to be practical and actionable, enabling healthcare organizations to better understand the interconnectedness of their supply chains and the potential impact of third-party failures. The release of the toolkit comes at a time when healthcare organizations are increasingly targeted by cyberattacks exploiting third-party vulnerabilities. The HSCC emphasizes the importance of cross-sector collaboration in developing robust risk management strategies, as demonstrated by the diverse participation in the toolkit's creation. The SMART Toolkit is freely available, reflecting a commitment to sector-wide improvement in cybersecurity resilience. It also aligns with broader industry efforts to enhance governance and risk management practices in healthcare. The toolkit is expected to become a valuable resource for CISOs, risk managers, and compliance teams seeking to address regulatory requirements and industry best practices. By providing a standardized approach to third-party risk assessment, the SMART Toolkit helps reduce ambiguity and supports more consistent risk mitigation across the sector. The HSCC encourages all healthcare organizations to adopt the toolkit as part of their ongoing risk management programs. The initiative underscores the critical role of third-party risk management in safeguarding patient data and ensuring the continuity of healthcare operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The Health Sector Coordinating Council released the Health Industry Cybersecurity Sector Mapping and Risk Toolkit (SMART), a free guidance document to help healthcare organizations identify, visualize, and measure systemic third-party and supply-chain cyber risk. The toolkit was developed over 16 months with input from 80 organizations across multiple healthcare subsectors.
A ransomware attack hit UnitedHealth Group's Change Healthcare in February 2024, disrupting a critical supplier and affecting thousands of healthcare entities for months. The incident became a prominent example of cascading third-party and supply-chain cyber risk in healthcare.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.