Cloud 101CircleEventsBlog
Call for Presentations: Share your expertise at 2024! Submit your proposals by June 28th.

CSA Official Press Release

Published 05/12/2022

Cloud Security Alliance Issues Best Practices for Healthcare Delivery Organizations (HDO) to Mitigate Supply Chain Cyber Risks

Cloud Security Alliance Issues Best Practices for Healthcare Delivery Organizations (HDO) to Mitigate Supply Chain Cyber Risks

HDOs must take a multidisciplinary approach that includes criteria for supplier evaluation, risk management, risk treatment, and monitoring and response

SEATTLE May 12, 2022 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining standards, certifications, and best practices to help ensure a secure cloud computing environment, today released a new paper, Healthcare Supply Chain Cybersecurity Risk Management. Drafted by the Health Information Management Working Group, the report provides best practices that healthcare delivery organizations (HDOs) can use to manage the cybersecurity risks associated with their supply chains.

HDOs face risks from many different types of supply chain vendors, everything from food suppliers, software providers, medical devices, pharmaceuticals, and day-to-day medical supplies. This complexity and extended interdependency dramatically increases the consequences of a cyber incident, ranging from the leakage of sensitive personal information to the disruption of the actual provision of the supply chain.

“Healthcare delivery organizations spend billions of dollars across thousands of suppliers each year. However, research indicates that current approaches to assessing and managing vendor risks are failing. The move to the cloud and edge computing have expanded HDOs’ electronic perimeters, not only making it harder for them to secure their infrastructure but also making them more attractive targets for cyberattacks. Given the importance of the supply chain, it’s critical that HDOs identify, assess, and mitigate supply chain cyber risks to ensure their business resilience,” said Dr. James Angle, the paper’s lead author and co-chair of the Health Information Management Working Group.

Cyberattacks are more costly than ever as HDOs and their suppliers remain high-value targets. Moreover, problems with current approaches to supply chain risk management are creating additional economic burdens as organizations are experiencing an increase in fines and investigations from the Department of Health and Human Services and the Office of Civil Rights.

“Unfortunately, supply chain exploitation is not just a potential risk, it is a reality. An insecure supply chain can significantly impact an HDO’s risk profile and security, not to mention its bottom line,” said Michael Roza, risk, audit, control, and compliance professional, CSA Fellow and a contributor to the paper. “It’s incumbent on HDOs, therefore, to ensure that their supply chain partners comply with data management policies in order to keep their organizations and their users safe.”

When addressing cyber risk and security within the supply chain, it’s recommended that HDOs:

  1. Inventory all suppliers, then prioritize, and identify those they consider to be strategic suppliers
  2. Tier suppliers based on risk, using a third-party risk rating service if possible
  3. Contractually require suppliers to maintain security standards
  4. Develop a schedule for reevaluating suppliers

To learn more about addressing cyber risk within the HDO supply chain, download Healthcare Supply Chain Cybersecurity Risk Management.

The CSA Health Information Management Working Group aims to provide a direct influence on how health information service providers deliver secure cloud solutions (services, transport, applications, and storage) to their clients, and to foster cloud awareness within all aspects of healthcare and related industries. Individuals interested in becoming involved in Health Information Management future research and initiatives are invited to join the working group.

About Cloud Security Alliance
The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, training, certification, events, and products. CSA's activities, knowledge, and extensive network benefit the entire community impacted by the cloud — from providers and customers to governments, entrepreneurs, and the assurance industry — and provide a forum through which different parties can work together to create and maintain a trusted cloud ecosystem. For further information, visit us at, and follow us on Twitter @cloudsa.

Share this content on your favorite social network today!

About Cloud Security Alliance

The Cloud Security Alliance is a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing, and to provide education on the uses of Cloud Computing to help secure all other forms of computing. The Cloud Security Alliance is led by a broad coalition of industry practitioners, corporations, associations and other key stakeholders. For further information, follow us on Twitter @cloudsa.

For press inquiries, email Zenobia Godschalk of ZAG Communications or reach her by phone at 650.269.8315.