Healthcare Supply Chain Cybersecurity: HSCC’s HIC-SCRiM Toolkit for Risk Management

October 14, 2025

The HIC-SCRiM toolkit, developed by the Healthcare and Public Health Sector Coordinating Council (HSCC), provides small to mid-sized healthcare organizations with actionable guidance to manage supply chain cybersecurity risks. Aligned with the NIST Cybersecurity Framework (CSF), the toolkit offers practical tools to ensure secure supplier practices, protect patient safety, and strengthen the healthcare sector’s cybersecurity posture.

Learn More

Strengthen your healthcare organization’s supply chain cybersecurity today. Download the HIC-SCRiM toolkit and explore how it can help you manage supplier risks, protect patient safety, and align with the NIST Cybersecurity Framework. Visit HealthSectorCouncil.org to get started!

Frequently Asked Questions

What is the HIC-SCRiM toolkit?

The HIC-SCRiM toolkit is a resource designed to help healthcare organizations: Implement and sustain a supply chain cybersecurity risk management program. Align with the NIST Cybersecurity Framework (CSF) to follow industry best practices. Manage cybersecurity risks introduced by third-party suppliers and vendors.

What’s new in the second release of the HIC-SCRiM toolkit?

The second release of the toolkit builds on the first version by: Completing the five NIST CSF supply chain requirements. Adding guidance on adherence to contractual terms with suppliers. Introducing tools for response and recovery testing in case of supplier cybersecurity incidents.

Who is the HIC-SCRiM toolkit designed for?

Primarily targeted at small to mid-sized healthcare organizations with limited resources.Encourages large healthcare organizations, associations, and consultancies to promote adoption across the sector.

Why is supply chain cybersecurity critical in healthcare?

Healthcare organizations rely on third-party suppliers for technology and services, introducing cybersecurity risks into the system. Ensuring secure supplier practices protects patient safety and critical healthcare operations. A structured, repeatable, and measurable supply chain risk management system is essential to mitigate these risks.

How does the HIC-SCRiM toolkit align with the NIST Cybersecurity Framework?

The toolkit follows the Supply Chain requirements within the NIST CSF and provides: Risk assessment templates to evaluate supplier risks. Contractual language for supplier agreements to ensure compliance. Tools for response and recovery testing to prepare for cybersecurity incidents.

Who contributed to the development of the HIC-SCRiM toolkit?

The toolkit was developed by the Supply Chain Security task group, co-chaired by Chris van Schijndel of Johnson & Johnson and Vish Gadgil of Merck. The task group includes over 20 supply chain and cybersecurity professionals from a broad spectrum of health sector organizations.

Related Links