Health-ISAC's Medical Device Security Council published a white paper on September 17 setting nine capability domains for hospitals to use when they evaluate, procure, and deploy medical devices. The list: authentication, authorization, secure remote vendor access, privacy and data handling, encryption, event logging, patches and updates, secure cloud connectivity, and boundary protection. The paper is decision support, not a certification standard or a procurement checklist.
The baseline splits devices into two buckets: those running a full operating system, and those on embedded or constrained platforms that cannot support every native control. For a constrained device, hospitals are told to build layered protection around it instead of demanding the device do everything itself.
The named owner requirement is the part manufacturers should read twice. A device that cannot meet a hospital's own security standard now needs a documented exception, and that exception needs an executive's name attached to it. Phil Englert, Health-ISAC's VP of medical device security, put it plainly: the issue is a business risk, and "the CISO should be an internal advisor."
Samantha Jacques, VP of clinical engineering at McLaren Health Care, said hospitals already lean on compensating controls "very, very early to try and get that layered security." Native device security, in practice, often arrives second.
The baseline lands next to a separate HIPAA Security Rule proposal that would eliminate the "addressable" designation, the label that has let covered entities treat many security controls as optional for two decades. Health-ISAC frames its nine domains as the kind of specificity regulators are already moving toward, without waiting for that rule to finalize.
A manufacturer that cannot say where its product lands on encryption, event logging, and secure remote vendor access at RFP time is handing the hospital's procurement team an exception to write, with someone else's name on it. Build the nine-domain matrix once per product line and keep it current. Every major health system's clinical engineering group is about to start asking these same nine questions.