Back to Columns
Healthcare Security13 min read

Supply Chain Risk for Hospitals: Seeing the Suppliers You Cannot See

September 14, 2026

Supply Chain Risk for Hospitals: Seeing the Suppliers You Cannot See
Share this article

Discussions of hospital security pull inwards almost by gravity: staff training, endpoint management, EMR permissions. All of it matters. But looking at the structure common to published breach cases, the entry point frequently was not inside the hospital at all.

A known vulnerability in an appliance installed for maintenance. A dedicated line pulled in for one departmental system. A device manufacturer's remote monitoring link. A connection to an affiliated facility. Every one of them was installed because it was needed. And in most cases, the department that installed it is not the department watching security.

Supply chain risk is the set of connections built for good reasons that nobody is looking at as a whole. This article sets out where that risk sits structurally, how to prioritise visibility with limited staff, and what to fix in contracts and operations.

Disclaimer: This article is general information. It does not discuss any specific hospital's breach; it organises the structures common to published cases as patterns. The authoritative texts are the MHLW and METI/MIC publications.

Four Routes In

RouteExamplesWhy it stays invisible
① The supplier's suppliersCloud platforms, monitoring SaaS and offshore development behind your EMR vendorThey sit behind your counterparty and are not visible to you
② Departmental systemsLaboratory, dialysis, rehabilitation, endoscopy, health screening, cateringThe department owns the relationship; IT never registered the system
③ Medical devices and maintenance pathsImaging systems, patient monitors, remote monitoring, maintenance linesProcured as "equipment", never managed as network equipment
④ Partners and affiliated facilitiesLaboratories, pharmacies, home-visit nursing, group sitesYou cannot control the other party's security level

What unites them is that each was installed as an operational necessity before anyone framed it as a security question. Nobody cut corners. Which is exactly why individual vigilance does not solve it and a structural mechanism for visibility is required.

The MHLW guidelines (edition 6.0) apply to "all those involved in the introduction, operation, use, maintenance and disposal of any medical information system" — not only the EMR. See The Three-Ministry Guidelines.

① The Suppliers You Never Contracted With

You contract with one vendor. Behind them sit the cloud platform, monitoring services, a CDN, mail delivery, outsourced development. Without visibility into that chain, an incident leaves you unable to locate even where it originated.

Ask "do you subcontract?" on a check sheet and the answer often comes back no — not from bad faith, but because industry habit does not call cloud use subcontracting. The remedy is one added clause:

Will any work be subcontracted? Include use of cloud services, and describe the platform, monitoring, development and support layers.

Beyond that, three things:

ItemWhy
Name, country and scope of each subcontractorA subcontractor whose name cannot be produced may not be managed
How their safeguards are verifiedWithout a method, subcontracting is a break in the chain of management
Prior notice when a subcontractor changesThe chain shifts during the term; without notice your picture goes stale

The third is the practical one. Verify at signature and a year later it may be different. A prior-notice clause is what keeps the picture current. See Questions to Ask Your Vendor and Security Check Sheets for Vendors.

From the vendor's side, being able to describe that chain at all requires their own supplier management to be in order. Annex A of ISO/IEC 27001 includes organisational controls covering supplier relationships, so a certified vendor has at least had a third party confirm that a mechanism for managing suppliers exists. See What Is an ISMS?.

② The Departmental Blind Spot

The larger the hospital, the more systems run alongside the EMR — laboratory, dialysis, rehabilitation, endoscopy, screening, catering, time and attendance. Each arrived by its own route, and the contract and the vendor relationship often sit with the department.

What follows:

  1. IT does not know it exists — servers absent from the network diagram
  2. Only the department has the support contact — nobody knows who to call in an incident
  3. Each has its own remote maintenance path — a different VPN or remote tool per vendor
  4. The OS is never updated — the PC bundled with the equipment runs an out-of-support OS
  5. It is integrated with the EMR — standalone the impact is limited; integrated it propagates

Three and four are the dangerous ones. A recurring structure in published cases is exactly this: an appliance or remote path installed for maintenance serving as the entry point. A separate remote path per department means an entry point per department.

The first step is an inventory of connections. You do not need a perfect network diagram; filling in these five columns from departmental interviews already changes what you can see.

ColumnContent
System nameThe department's own name for it is fine
Vendor and contactSupport desk plus an emergency contact
External connectivityAny path outside the hospital (VPN, leased line, internet)
Remote maintenanceDoes the vendor connect remotely? By what method, and is each session requested?
EMR integrationWhether integrated, and in which direction

The rows you cannot fill in are your investigation queue. See Network Segmentation and Asset Management and Securing Remote Maintenance.

③ Medical Devices and Maintenance Paths

Medical devices fall out of network management for three reasons.

1. Clinical departments lead procurement. The device is chosen on clinical grounds; network requirements are incidental, and IT may never see the specification.

2. Replacement cycles are long. Imaging systems run well past a decade. OS support ends during that life, and the device's regulatory configuration cannot simply be changed, so updating is not straightforward.

3. Remote monitoring is assumed. Manufacturer monitoring and predictive maintenance raise availability — and also mean a permanent connection from outside.

None of this makes devices "dangerous". It means they must be brought inside the management frame.

MeasureContent
Register themInclude network-connected devices in the asset register, with OS and support status
Segment themWhere a device cannot be updated, segment the network to bound the impact
Narrow the pathRestrict the destination, protocol and hours of remote monitoring
Write it into the contractRequire the manufacturer's response to disclosed vulnerabilities — notification and remediation — in the maintenance agreement
Fix ownershipDetermine, contract by contract, who applies firmware updates

That last row is the gap. The device manufacturer treats the device as theirs and the network as someone else's; the network contractor covers the circuit but not firmware. Nobody is watching. Lay the contracts side by side and settle firmware ownership device by device. See Writing SLAs and Responsibility Boundaries, Demarcating Responsibility, and Securing Network-Connected Medical Devices.

④ Partners and Affiliated Facilities

Laboratories, pharmacies, home-visit nursing, other sites in the group. Connections built for regional coordination or group operations are also routes.

The difficulty here is that you cannot control the other party's security level. A supplier can be held to contract terms; an equal partner or a small counterparty often cannot.

The realistic move is not raising their level but lowering the granularity of the connection.

  1. Connect the minimum — open only the data exchange path required, not the networks
  2. Constrain direction — if one-way transmission suffices, do not make it bidirectional
  3. Separate the credentials — connection accounts distinct from staff accounts, tightly scoped
  4. Log it — record access arriving over the link and review it periodically
  5. Decide how to cut it — know in advance which path is severed, and on whose authority, if the partner is compromised

The fifth matters most. When the call comes that a partner has been breached, not knowing who decides to cut which link stalls the entire response. Build link severance into your incident plan. See Hospital Incident Response Plans.

Where to Start with Limited Staff

PriorityCondition
HighestPermanently connected from outside and integrated with the EMR
HighExternally connected, not integrated with the EMR
MediumNo external connection, but on the hospital network with an unpatched OS
LowStandalone, exchanging data only by portable media

The highest priority is the product of external connectivity and EMR integration. Anything in that cell you cannot account for means your visibility does not match your exposure.

Deciding who owns this inventory is the starting point. The FY2026 electronic clinical information coordination system development addition requires, as a common criterion, a dedicated medical information system safety management officer. Writing the connection inventory and its upkeep explicitly into that role keeps it from depending on one individual's memory. See The Medical Information System Safety Management Officer and The FY2026 Fee Revision.

Conclusion

  1. There are four routes: suppliers' suppliers, departmental systems, medical devices and maintenance paths, partners and affiliated facilities
  2. Subcontracting only surfaces if you write "including use of cloud services" — and add a prior-notice clause for changes
  3. Start departmental visibility with a five-column inventory of connections. A perfect network diagram is not required
  4. For devices, settle who owns firmware updates by laying the contracts side by side
  5. With partners, lower the granularity of the connection rather than trying to raise their standard, and decide the severance procedure in advance
  6. Prioritise by external connectivity × EMR integration
  7. Write the inventory into the safety management officer's duties so it does not depend on one person

Supply chain visibility is not a one-off exercise; it needs updating every time a connection is added. For help designing the first inventory or approaching existing suppliers, contact us. If you are on the supplier side and being asked to evidence your posture, see ISMS certification support.

References and Sources

Note: this article organises structures common to published cases as patterns and does not address any specific incident. Guideline requirements and fee criteria change with revisions.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.