Health Sector Publishes Medical Product Manufacturing Cyber Incident Response Guide

The ‘Playbook’ offers step-by-step recommendations & processes to identify and respond to manufacturing cyber incidents.

Author Image

By: Rachel Klemovitch

Assistant Editor

The Healthcare and Public Health Sector Coordinating Council (HSCC) Joint Cybersecurity Working Group published a playbook to guide response to cyber incidents impacting medical product manufacturing and its operational technology (OT).

The “Medical Product Manufacturer Cyber Incident Response Playbook (MPM-CIRP)” is the Joint Cybersecurity Working Group’s fifth publication in 2024, and our twenty-eighth since 2019.  

The MPM-CIRP (“Playbook”) provides step-by-step recommendations and processes for medical product manufacturers (principally medical device and pharmaceutical companies) to use in identifying and responding to manufacturing cyber incidents, from preparation through remediation. 

The recommendations and procedures are tailored to be applicable across organizations of various sizes and types and to provide a basic platform that organizations may use or adapt according to their own needs. This Playbook is meant to serve as a starting point—or accelerator—for companies to create and tailor their internal playbooks for their specific circumstances. 

A portion of this product also demonstrates resourcefulness in that it adapted its guidance from a similar effort done by the American Public Power Association in 2019. The authors accordingly give acknowledgment to that cross-pollinating critical infrastructure support.

The next phase of the medical product manufacturing cybersecurity initiative will be to identify and document existing best practices and create new practices as applicable for ensuring cybersecurity and resiliency of processes and capabilities, with publication expected later in 2025.

Keep Up With Our Content. Subscribe To Medical Product Outsourcing Newsletters