Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Healthcare's SMART Toolkit for Third-Party Risk Management

Claroty
05/11/2026
19
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • The Health Sector Coordinating Council released the SMART toolkit in October 2024, providing 17 workflow maps that visualize critical third-party dependencies across healthcare operations from claims processing to pharmaceutical manufacturing.
  • The toolkit enables organizations to assess material impact across clinical, financial, administrative, and regulatory dimensions, then prioritize risks based on market leverage and concentration factors.
  • Born from the Change Healthcare attack, SMART addresses a strategic objective to develop cross-sector third-party risk management strategies for supply chain and service provider cybersecurity risks.
  • The methodology is scalable for organizations of all sizes and designed as a living document that will evolve with industry feedback and technological changes, particularly as AI automation matures.
  • Over 460 healthcare organizations collaborated on the toolkit's development, representing providers, payers, technology vendors, and public health agencies in a sector-led approach to systemic risk visibility.

The SMART Toolkit: Mapping Healthcare's Critical Dependencies

The Health Sector Coordinating Council Cybersecurity Working Group has released the Sector Mapping and Risk Toolkit (SMART), a 16-month initiative born from the Change Healthcare attack in February 2024. The toolkit provides 17 workflow maps covering critical healthcare functions from blood supply distribution to claims processing, pharmaceutical manufacturing, and dialysis services. Each map visualizes the complex web of third-party dependencies that support daily healthcare operations, offering organizations a template to identify single points of failure and concentration risks. The toolkit is designed to be scalable, serving both large health systems with complex vendor ecosystems and smaller practices with simpler workflows. By making the invisible infrastructure visible, SMART enables healthcare organizations to understand where their critical dependencies lie and what would happen if those services were disrupted.

Materiality Assessment and Risk Prioritization

The toolkit introduces a structured approach to measuring material impact across clinical, administrative, financial, and regulatory dimensions. Organizations use the maps to assign relative risk ratings to third-party services based on factors including cybersecurity hygiene, market concentration, and geographic risk. This materiality framework helps healthcare entities prioritize where to invest in risk mitigation and where to focus on resilience planning. For services where organizations have market leverage, they can demand better security practices or switch providers. For concentrated markets where a single vendor controls 70-80% of the market, the focus shifts to right-of-boom preparedness — developing continuity plans, backup procedures, and manual override capabilities. The methodology acknowledges that not all risks can be mitigated, but all can be prepared for through awareness and planning.

Industry Collaboration and Future Evolution

The SMART toolkit represents a collaborative effort involving approximately 460 organizations across the healthcare spectrum, including providers, payers, medical technology companies, pharmaceutical manufacturers, and health IT firms. The working group deliberately excluded AI-driven workflows from the current version, recognizing that AI's role in healthcare automation is still maturing too rapidly to capture accurately. The toolkit is positioned as a living document that will evolve based on user feedback and industry changes. Early adopters have already begun implementing the maps, with one healthcare provider presenting lessons learned just six weeks after publication. The working group is actively seeking feedback on accuracy, usability, and implementation experiences to refine future versions. This sector-led approach mirrors similar critical infrastructure mapping efforts in financial services, where visualization of systemic dependencies helped government agencies understand where to focus preparedness and recovery resources.

Chapters

0:00 - Introduction and Podcast Overview
1:32 - Health Sector Coordinating Council Background
3:56 - Origins of the SMART Toolkit
7:07 - Development Process and Workflow Mapping
13:46 - Visual Impact and Plumbing Analogy
15:45 - Third-Party Risk Focus and Rationale
21:04 - Materiality Assessment Framework
23:48 - Scalability for Different Organization Sizes
27:40 - Early Feedback and Implementation
29:22 - Living Document and AI Considerations
32:01 - Future Roadmap and Government Role

Key Quotes

4:48 "Develop meaningful cross-sector third-party risk management strategies for evaluating, monitoring, and responding to supply chain and third-party provider cybersecurity risks."
6:56 "Let's rip up the floorboards and look at the plumbing and where are the loose joints? Where are the leaks in the plumbing that we need to fix? ..."
18:48 "Until such time that third party providers are held to a higher standard of cybersecurity because they are supporting the nation's critical infrastructure, you know, critical infrastructure means life and death."
27:36 "If you can't influence it, be prepared for it."
31:41 "AI has just rendered irrelevant what we wrote last week. I'm overstating that point, but that's kind of the idea."

Categories:
  • » Data Protection » Backup & Recovery
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Data Protection
  • Compliance & Governance
  • Best Practices
  • Technical Deep Dive
  • Threat Intelligence
  • Healthcare Cybersecurity
  • Third-Party Risk Management
  • Supply Chain Security
  • Critical Infrastructure Protection
  • Healthcare Workflow Mapping
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Healthcare's SMART Toolkit for Third-Party Risk Management

              Upcoming Webinar Calendar

              • 06/10/2026
                11:00 AM
                06/10/2026
                Action1: Vulnerability Digest--Patch Tuesday & Other Updates
                https://www.truthinit.com/index.php/channel/1997/action1-vulnerability-digest-patch-tuesday-other-updates/
              • 06/10/2026
                02:00 PM
                06/10/2026
                Understanding the True Costs of DIY Data Classification vs. Buying Solutions
                https://www.truthinit.com/index.php/channel/1985/understanding-the-true-costs-of-diy-data-classification-vs-buying-solutions/
              • 06/23/2026
                10:00 AM
                06/23/2026
                Stay Informed on the Latest Keepit Partner Developments – June 23
                https://www.truthinit.com/index.php/channel/1990/stay-informed-on-the-latest-keepit-partner-developments-–-june-23/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/

              Upcoming Events

              • Jun
                10

                Action1: Vulnerability Digest--Patch Tuesday & Other Updates

                06/10/202611:00 AM ET
                • Jun
                  10

                  Understanding the True Costs of DIY Data Classification vs. Buying Solutions

                  06/10/202602:00 PM ET
                  • Jun
                    23

                    Stay Informed on the Latest Keepit Partner Developments – June 23

                    06/23/202610:00 AM ET
                    • Jun
                      25

                      Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                      06/25/202601:00 PM ET
                      More events
                      Truth in IT
                      • Sponsor
                      • About Us
                      • Terms of Service
                      • Privacy Policy
                      • Contact Us
                      • Preference Management
                      Desktop version
                      Standard version