Healthcare Supply Chain Risk: The 2026 Framework That Works
Healthcare supply chain risk explained: risk types, a 5-step management framework, vendor tiering, disruption prevention and contingency planning for providers.
Contents
The 6 types of healthcare supply chain risk
What the 2024 to 2026 disruptions proved ⚠
Regulations that govern supplier risk
The 5-step risk management framework ★
Vendor tiering by clinical impact
Contingency planning and testing
Metrics that show the programme works
5 mistakes that sink programmes ⚠
How Neotas screens healthcare suppliers
Frequently asked questions
Of daily US IV solutions came from the single Baxter plant closed by Hurricane Helene, per the FDA [2]
Annual ransomware attacks on US healthcare organisations more than doubled from 2016 to 2021, per JAMA Health Forum [4]
Quick answer
Healthcare supply chain risk is the exposure a hospital or health system carries when a supplier, distributor or service vendor fails and the failure reaches patient care.
It spans cyberattacks on clearinghouses like Change Healthcare, physical shutdowns like the Baxter IV fluid plant after Hurricane Helene, drug shortages, and compliance failures under HIPAA and FDA QMSR. Managing it takes a supplier inventory, clinical-impact tiering, due diligence, contract controls and tested contingency plans.
Key takeaways
- The Change Healthcare ransomware attack of February 2024 affected 192.7 million individuals, the largest healthcare data breach recorded by HHS, and it started at a third-party claims vendor rather than a hospital. [1]
- Physical concentration risk can do more clinical damage than a cyberattack: one flooded Baxter plant in North Carolina produced roughly 60% of the 2.5 million IV solution bags US providers use daily, and the FDA had to authorise temporary imports from 5 overseas facilities. [2]
- US drug shortages hit an all-time high of 323 active shortages in Q1 2024, and roughly three-quarters of shortages active in 2025 began in 2022 or later, so scarcity is a standing condition rather than a passing event. [3]
- Healthcare supply chain risk and vendor risk are different disciplines: supply chain risk covers the physical and clinical flow of goods and services, while healthcare vendor risk management covers the data, IT and compliance exposure each individual vendor creates.
- HIPAA makes supplier failures your failures: 45 CFR 164.308(b) requires written business associate contracts with security assurances before a vendor touches protected health information. [5]
- A 5-step framework closes most gaps: build a supplier inventory, tier by clinical impact, screen with real due diligence, write enforceable contract controls, and test contingency plans against named scenarios at least twice a year.
What is healthcare supply chain risk?
Healthcare supply chain risk is the probability that a supplier, manufacturer, distributor or service vendor fails in a way that disrupts patient care, breaches regulation or damages the organisation financially. The failure can be a ransomware attack, a flooded factory, a recalled device component, a bankrupt distributor or a sanctioned sub-supplier 3 tiers down.
The defining feature in healthcare is that the downside lands on patients, not just the balance sheet. When a retailer loses a supplier, shelves go empty. When a hospital loses its IV fluid supplier, surgeries get postponed and clinicians ration saline. That difference is why regulators treat healthcare suppliers differently from suppliers in any other industry.
The discipline sits inside a wider set of programmes, and the terms get mixed up constantly. The table below separates them, because the distinction decides who owns the risk and which page of your policy applies.
| Discipline | What it covers | Typical owner | Where to go deeper |
|---|---|---|---|
| Healthcare supply chain risk | The flow of drugs, devices, consumables and services into care delivery: disruption, shortages, concentration, quality and continuity. | VP Supply Chain, COO | This guide |
| Healthcare vendor risk management | The data, IT, security and compliance exposure each individual vendor creates, especially vendors touching PHI. | CISO, Compliance | Healthcare vendor risk management guide |
| Healthcare third-party risk management | The governance programme covering every external relationship: vendors, suppliers, affiliates, contractors and their lifecycle. | CRO, General Counsel | Healthcare TPRM guide |
| General supply chain risk management | The cross-industry discipline: mapping, assessing and mitigating supplier risk in any sector. | Procurement, Risk | Supply chain risk management guide |
Why are healthcare supply chains so vulnerable?
Healthcare supply chains are vulnerable because production is concentrated, the chain is deep, and demand cannot pause. A single plant produced roughly 60% of the IV solutions US providers use each day, so one flood created a national shortage within a week. [2]
Depth compounds the concentration. A hospital contracts with a distributor, the distributor buys from a manufacturer, the manufacturer depends on an API producer, and the API producer sits in a jurisdiction the hospital has never assessed. Visibility usually stops at tier 1, which is exactly where it stops being useful.
Then there is the demand problem. A hospital cannot defer demand for saline, blood or oncology drugs the way a manufacturer defers a component order. Thin generic-drug margins keep redundancy out of the system, and just-in-time inventory removed the buffer stock that used to absorb shocks.
Related: Supply chain risk assessment methodology | Healthcare third-party risk management | What is risk intelligence
The 6 types of healthcare supply chain risk
Healthcare supply chain risk breaks into 6 categories: cyber, concentration, clinical quality, geopolitical, regulatory and financial. Every major disruption since 2020 fits at least one, and the worst incidents combine 2 or 3 at once.
1. Cyber and data risk
Ransomware and breaches at vendors holding PHI or running clinical and billing systems. Change Healthcare showed one clearinghouse can halt claims for thousands of providers at once.
2. Concentration risk
A single plant, supplier or region carrying a product category alone. One flooded North Carolina facility took out roughly 60% of daily US IV solution supply in 2024.
3. Clinical quality risk
Defective components, contaminated ingredients and recalls that reach patients. FDA QMSR now holds device makers to ISO 13485 purchasing controls for exactly this reason.
4. Geopolitical and tariff risk
Export controls, sanctions, tariffs and regional conflict cutting off APIs, chips and raw materials. Most hospitals cannot name the country their generic APIs come from.
5. Regulatory and compliance risk
Supplier failures that become your HIPAA, FDA or state enforcement problem. A vendor breach without a compliant business associate agreement is a direct covered-entity liability.
6. Financial and integrity risk
Supplier insolvency, hidden ownership, sanctions exposure and fraud. These surface in vendor due diligence and screening, not in delivery metrics.
One observation from our screening work that cuts against the industry’s instinct: budgets treat this as a cyber problem, but the deepest clinical damage of 2024 came from water, not code. The Baxter shutdown postponed surgeries nationwide for months. Most ransomware attacks did not. A programme weighted 90% to cyber controls is defending one of the 6 categories.
What the 2024 to 2026 disruptions proved
Three disruptions between 2024 and 2026 rewrote the risk assumptions for healthcare supply chains: the Change Healthcare ransomware attack, the Baxter IV fluid shutdown and the record run of drug shortages. Each one exposed a different failure mode, and each one was survivable for the organisations that had mapped their dependencies in advance.
| Incident | Failure mode | Documented impact | The lesson |
|---|---|---|---|
| Change Healthcare ransomware, February 2024 | Cyber, at a services vendor | 192.7 million individuals affected, the largest healthcare breach on the HHS OCR portal; claims and billing disrupted for providers nationwide [1] | A services vendor can be a bigger single point of failure than any physical supplier. Map revenue-cycle dependencies, not just clinical ones. |
| Baxter North Cove shutdown, September 2024 | Concentration, physical | Hurricane Helene closed the plant making ~60% (1.5 million bags) of daily US IV solutions; the FDA declared shortages and cleared temporary imports of 23 products from 5 overseas facilities [2] [6] | Ask every category owner one question: if this supplier’s largest site closed tomorrow, who else could supply us, and at what volume. |
| Drug shortage peak, 2024 through 2026 | Structural scarcity | 323 active shortages at the Q1 2024 peak, the highest since ASHP began tracking in 2001; 77% of shortages active in 2025 began in 2022 or later [3] | Shortage response cannot live in the pharmacy alone. It needs supplier intelligence, substitution protocols and pre-agreed conservation triggers. |
The pattern across all 3 is the same. The primary victim was never the only victim, and the organisations that recovered fastest were the ones that already knew which clinical services each supplier fed. That mapping exercise is step 1 of the framework below.
The intelligence gap behind every incident
In Neotas screening engagements, the supplier a hospital knows least about is rarely the software vendor with a completed questionnaire. It is the distributor’s manufacturer, or the manufacturer’s ingredient source. Questionnaires stop at tier 1. Open-source intelligence is how you see past it without waiting for the supplier to volunteer the information.
Which regulations govern healthcare supplier risk?
Four regulatory regimes reach healthcare supplier relationships in the US, and 2 more apply to organisations with EU operations. Each one converts a supplier failure into an enforcement exposure for the provider, which is why supply chain risk in healthcare is a compliance discipline and not only an operational one.
| Regulation | What it requires of supplier relationships | Who it applies to |
|---|---|---|
| HIPAA Security Rule, 45 CFR 164.308(b) and 164.314(a) [5] | A written business associate agreement with satisfactory security assurances before any vendor creates, receives, maintains or transmits PHI on your behalf. | Covered entities and business associates, including subcontractor chains |
| FDA QMSR, 21 CFR Part 820, effective 2 February 2026 [7] | Purchasing and supplier controls under ISO 13485:2016 clause 7.4: supplier evaluation, selection criteria, monitoring and re-evaluation, with records. Our 21 CFR 820 QMSR supplier control guide covers the transition in detail. | Medical device manufacturers and their supplier chains |
| HHS HPH Cybersecurity Performance Goals [8] | Voluntary goals that include vendor and supplier cybersecurity requirements and incident planning; increasingly the reference point OCR and payers use to judge reasonableness. | Hospitals and health systems |
| DSCSA, FD&C Act Section 582 [9] | Trading only with authorised partners and package-level traceability across the pharmaceutical distribution chain. | Manufacturers, wholesalers, dispensers |
| EU NIS2 Directive, Article 21(2)(d) [10] | Supply chain security measures covering relationships with direct suppliers and service providers, for essential entities including the health sector. | EU healthcare entities and their suppliers |
| EU CSDDD, Directive 2024/1760 [11] | Human rights and environmental due diligence across the chain of activities for large companies; provisions remain subject to the EU omnibus simplification process, so check current scope before building obligations on it. | Large EU and EU-active companies, phased |
The practical consequence: your supplier files need to survive an audit under at least 2 of these regimes at once. A HIPAA vendor risk assessment that documents security assurances, and supplier evaluation records that satisfy QMSR purchasing controls, are the 2 files US providers get asked for first.
Neotas | Rated Chartis FCC50
Find the supplier risks your questionnaires missed
Neotas screens healthcare suppliers with open-source intelligence across 200+ languages: sanctions, litigation, adverse media, hidden ownership and integrity risks that self-attestation never surfaces. Analyst-reviewed reports, with a full audit trail for OCR and FDA inspections.
Healthcare supply chain risk management: the 5-step framework
Healthcare supply chain risk management works in 5 steps: inventory every supplier, tier by clinical impact, screen with real due diligence, write enforceable contract controls, then monitor and test contingency plans. Run the steps in order. Each one depends on the output of the one before it, and skipping the inventory step is the single most common reason programmes stall.
Build a single supplier inventory mapped to clinical services
List every supplier, distributor and service vendor in one register: what they provide, which clinical or revenue service depends on them, what data they touch, contract end dates and named alternatives. The mapping to clinical services is the part most inventories skip, and it is the part that decides everything downstream. Pull the initial list from accounts payable, not from procurement’s contract file, because AP catches the suppliers nobody formally onboarded.
Tier suppliers by clinical impact and replaceability
Score each supplier on 2 axes: how badly patient care degrades if they fail, and how quickly a substitute can reach the loading dock. A supplier scoring high on both is Tier 1 regardless of contract value. The tiering matrix in the next section gives the full definitions and the assessment cadence each tier earns.
Screen suppliers with due diligence that goes past the questionnaire
Questionnaires record what a supplier says about itself. Screening records what the world says about the supplier: sanctions lists, litigation, insolvency signals, regulatory actions, adverse media and beneficial ownership. Tier 1 suppliers warrant enhanced due diligence with analyst review; lower tiers can run on a structured vendor risk assessment template. For vendors touching PHI, fold the HIPAA vendor risk assessment into the same file so one review satisfies both owners.
Write contract controls you can actually enforce
Four clauses do most of the work. Security obligations with named controls and audit rights inside the business associate agreement, not vague compliance language. Measurable SLAs: uptime floors, patch windows, fill rates, notification deadlines for incidents and supply interruptions. Renegotiation triggers for tariff shocks, plant closures and ownership changes. Offboarding terms covering data return or destruction, access termination and a closing audit. If a clause has no measurement and no consequence, it is decoration.
Monitor continuously and test contingency plans on a calendar
Annual reassessment is a snapshot of a moving target. Tier 1 suppliers need continuous monitoring across integrated sources, with alerts on sanctions changes, litigation, insolvency markers and adverse media between review cycles. Pair the monitoring with contingency tests: tabletop a named scenario twice a year, with the supplier in the room for your top dependencies. The contingency planning section below sets out the scenarios worth running.
The framework plugs into the wider TPRM lifecycle: steps 1 and 2 are the identification phase, step 3 is due diligence, step 4 is contracting, and step 5 is monitoring and offboarding. If your organisation already runs a third-party risk management framework, this is the healthcare supply chain overlay, not a competing programme.
How do you tier healthcare suppliers by clinical impact?
Tier suppliers by asking 2 questions: what happens to patients if this supplier stops tomorrow, and how many days until a substitute delivers at volume. Contract spend is a distraction here. A £40,000 contract for a sole-source surgical consumable outranks a £4 million contract for office services every time.
| Tier | Definition | Examples | Due diligence depth | Monitoring and testing |
|---|---|---|---|---|
| Tier 1: Clinical-critical | Failure degrades patient care within 72 hours, or no substitute can deliver at volume within 30 days, or the vendor is a single point of failure for revenue cycle. | IV fluids, blood products, claims clearinghouse, EHR host, sole-source device components | Enhanced due diligence with analyst review, beneficial ownership, site-level concentration check | Continuous monitoring; contingency tabletop every 6 months with the supplier involved |
| Tier 2: Operational | Failure disrupts operations or compliance but care continues; substitutes exist within 30 to 90 days. | Non-sole-source consumables, lab couriers, scheduling software, facilities contractors with PHI access | Structured screening plus questionnaire; HIPAA assessment where PHI is touched | Semi-annual review; alert-based monitoring; annual scenario inclusion |
| Tier 3: Commodity | Failure is an inconvenience; substitutes are immediate and interchangeable. | Office supplies, general maintenance, catering without patient data | Baseline checks at onboarding: sanctions, registration, insurance | Annual attestation; re-screen on contract renewal |
Two rules keep the tiering honest. First, any supplier that is a single point of failure gets Tier 1 treatment even if its product looks mundane; saline bags looked mundane until September 2024. Second, re-tier on trigger events, not just annually: an acquisition, a plant consolidation or a new sole-source designation changes the answer immediately.
Practice: dual-source the top 20
Qualify a second supplier for your 20 highest clinical-impact items before you need one. Qualification during a shortage takes 3 to 6 times longer than qualification in peacetime.
Practice: check the site, not the brand
Two suppliers can resolve to the same manufacturing site. Concentration hides at plant level, which is where the Baxter lesson lives.
Practice: screen the owners
Sanctions and integrity risk attach to people, not logos. Beneficial ownership screening catches the exposure a company-name check misses. OSINT techniques do this at scale.
Practice: set conservation triggers early
Decide in advance which inventory level triggers clinical conservation protocols for each Tier 1 consumable. Deciding during the shortage costs days you do not have.
Which metrics show the programme is working?
Six metrics tell you whether a healthcare supply chain risk programme works: inventory coverage, single-point-of-failure count, assessment currency, time-to-substitute, contingency test cadence and incident notification speed. Report them to the board quarterly. Activity metrics like questionnaires sent measure effort, and these measure exposure.
| Metric | What it measures | Working target |
|---|---|---|
| Inventory coverage | Share of active suppliers in the register, mapped to a clinical or revenue service | 100% of AP-active suppliers within 12 months of programme start |
| Single points of failure | Count of Tier 1 items with no qualified alternative supplier | Falling quarter on quarter, with a named owner per remaining item |
| Assessment currency | Share of Tier 1 suppliers with due diligence completed or refreshed inside the cycle | 95%+ current at any point in time |
| Time-to-substitute | Days from Tier 1 supplier failure to substitute delivering at volume, per contingency plan | Documented and under the clinical tolerance set for each item |
| Contingency test cadence | Tabletop and simulation exercises completed against named scenarios | 2 per year minimum, with findings assigned and closed |
| Incident notification speed | Hours from supplier incident to your team knowing, versus the contractual deadline | Within SLA on every tracked incident; misses escalated to contract review |
Related: Third-party risk management framework | Supply chain risk management | Vendor due diligence
How do you build and test supplier contingency plans?
A supplier contingency plan answers 4 questions before the failure happens: which clinical services stop, how long care can tolerate the gap, who supplies the substitute, and who calls whom in the first hour. Write one per Tier 1 supplier. A generic business continuity plan that never names suppliers fails the first time it meets a real shortage.
Set the downtime tolerance clinically, not operationally. Pharmacy can tolerate a 10-day gap in one antibiotic with substitution protocols; the OR cannot tolerate 48 hours without irrigation fluids. Those tolerances, agreed with clinical leadership in advance, are what turn a supplier incident into a managed event instead of a scramble.
Then test against named scenarios. The 3 worth running every year, because each rehearses a different muscle:
Scenario 1: the clearinghouse goes dark
Claims and eligibility down for 21 days. Tests revenue-cycle workarounds, cash reserves, manual claim routing and payer communication. Change Healthcare made this the mandatory scenario.
Scenario 2: the sole-source plant closes
A physical consumable at 60% supply loss for 90 days. Tests conservation triggers, substitute qualification speed, allocation fairness across sites and clinical substitution protocols.
Scenario 3: the supplier fails compliance
A Tier 1 supplier appears on a sanctions list or loses its FDA registration. Tests screening alert speed, legal review, contract exit rights and replacement onboarding under time pressure.
Run each tabletop with procurement, IT, clinical operations and finance in the same room, and bring the supplier in for your top 5 dependencies. Every exercise ends with a findings list, an owner per finding and a close date. An untested plan is a hypothesis; treat the first test as the real draft.
Neotas | Rated Chartis FCC50
Know which of your suppliers is a single point of failure
A Neotas supplier risk review screens your Tier 1 suppliers for sanctions, ownership, litigation, insolvency signals and adverse media, delivered as analyst-reviewed reports your auditors can trace. Scoped to your register, with configurable risk models to match your tiering.
5 mistakes that sink healthcare supply chain risk programmes
The same 5 failures appear across the incidents we study and the programmes we screen for. Each one is cheap to fix before an incident and expensive to explain after one.
1. Tiering by contract spend instead of clinical impact
Spend-ranked registers bury the cheap sole-source consumables that stop surgeries. Saline was nobody’s strategic supplier until September 2024. Rank by what stops when the supplier stops.
2. Treating the questionnaire as the assessment
Self-attestation records the supplier’s opinion of itself. Sanctions exposure, litigation, insolvency markers and ownership changes live in external data, and they change between annual cycles. Verification is the assessment; the questionnaire is the cover sheet.
3. Signing BAAs without enforceable technical terms
A business associate agreement that says “reasonable safeguards” and nothing else gives you no lever when the vendor’s controls turn out to be thin. Name the controls, add audit rights, set incident notification in hours. 45 CFR 164.314(a) sets the floor, not the ceiling.
4. Stopping visibility at tier 1
Your distributor’s manufacturer and the manufacturer’s ingredient source carry your risk whether or not you can see them. Ask Tier 1 suppliers to disclose their own concentration points, and verify what you can through open sources.
5. Writing contingency plans nobody has tested
Plans written for the audit file fail on contact with a real shortage: the substitute’s number is stale, the conservation trigger was never agreed with clinicians, the supplier contact left 2 years ago. Two tabletop exercises a year keep the plan real.
Who owns healthcare supply chain risk, and how Neotas helps
Supply chain risk in a health system has 4 owners, and the programme works when each one gets the intelligence their decisions need. The framework above only runs if these roles share one supplier register and one evidence file per supplier.
VP Supply Chain / COO
Owns the inventory, tiering and continuity plans. Needs concentration analysis and time-to-substitute data per Tier 1 item.
CISO / IT Risk
Owns vendor cyber exposure and BAA technical terms. Needs the supplier register joined to the vendor risk management programme.
Compliance / General Counsel
Owns HIPAA, QMSR and audit readiness. Needs due diligence evidence with a traceable audit trail per supplier.
Procurement / Category leads
Own onboarding, contracts and dual-sourcing. Need screening results before signature, not after.
Neotas supplies the intelligence layer of that programme. We combine structured database checks with open-source intelligence and analyst-led investigation, screening suppliers and their owners across 200+ languages. The table maps what we do to the framework steps above.
| Framework step | Neotas capability |
|---|---|
| Step 3: Screening and due diligence | OSINT and social media intelligence on suppliers and beneficial owners, sanctions and watchlist checks via premium data sources, adverse media in 200+ languages, and analyst-led enhanced due diligence for Tier 1 relationships. |
| Step 5: Continuous monitoring | Continuous monitoring across our sources with custom alerting, so sanctions changes, litigation and insolvency signals reach you between review cycles rather than at the next annual refresh. |
| Programme fit and audit | Configurable risk models to match your tiering, dashboards for the 4 owner roles, and a full audit trail per supplier that stands up to OCR, FDA and internal audit review. |
Neotas | Rated Chartis FCC50
Build a healthcare supplier risk programme that survives its first audit
Talk to our team about screening your supplier register: tiered due diligence, continuous monitoring and analyst-reviewed evidence files, mapped to HIPAA and QMSR supplier control requirements.
Related reading
Healthcare Vendor Risk Management
The companion discipline to this guide: how to assess and manage the data, IT and compliance risk each individual healthcare vendor creates, with programme design for CISOs and compliance leads.
Healthcare Third-Party Risk Management
The governance layer above supplier and vendor risk: building a healthcare TPRM programme covering the full lifecycle from onboarding through offboarding, with roles, policy and board reporting.
HIPAA Business Associate Agreement Guide
What a BAA must contain under 45 CFR 164.314(a), which supplier relationships need one, and the enforceable technical terms that separate a working agreement from compliance decoration.
How to run and document a HIPAA-focused risk assessment for vendors handling protected health information, including the evidence OCR expects to see when a business associate is breached.
21 CFR 820 FDA QMSR Supplier Control Guide 2026
The QMSR transition explained for device makers: how 21 CFR Part 820 now incorporates ISO 13485:2016 purchasing controls, and what supplier evaluation records the FDA expects from 2 February 2026.
Vendor Risk Assessment Template
A structured template for assessing vendors and suppliers, covering the risk domains, scoring approach and evidence fields a defensible assessment file needs.
The cross-industry pillar guide: supply chain risk categories, the management process and the frameworks that apply in any sector, of which this healthcare guide is the vertical deep dive.
The assessment methodology behind step 3 of the framework: how to score supplier risk across financial, operational, compliance and ESG domains, with an assessment structure you can reuse.
Healthcare supply chain risk: frequently asked questions
What is healthcare supply chain risk?▼
What is healthcare supply chain risk management?▼
What is the difference between healthcare supply chain risk and vendor risk?▼
Why are healthcare supply chains so vulnerable to disruption?▼
What are examples of healthcare supply chain disruptions?▼
What caused the 2024 IV fluid shortage in the healthcare supply chain?▼
How do hospitals manage healthcare supply chain risk?▼
What is a single point of failure in a healthcare supply chain?▼
What is concentration risk in the healthcare supply chain?▼
How does HIPAA apply to healthcare suppliers and the supply chain?▼
What supplier controls does FDA QMSR require from 2026?▼
What should a healthcare supplier contingency plan include?▼
What KPIs measure healthcare supply chain risk management?▼
How does OSINT improve healthcare supplier due diligence?▼
Who is responsible for supply chain risk in a hospital?▼
References
[1] HHS OCR, Change Healthcare Cybersecurity Incident FAQ (192.7M individuals):
https://www.hhs.gov/hipaa/for-professionals/special-topics/change-healthcare-cybersecurity-incident-frequently-asked-questions/index.html
[2] FDA, Responses to 2023 Intergovernmental Working Meeting on Drug Compounding (Baxter North Cove ~60% / 1.5M bags daily):
https://www.fda.gov/drugs/human-drug-compounding/fda-responses-action-items-identified-2023-intergovernmental-working-meeting-drug-compounding
[3] ASHP / University of Utah Drug Information Service, Drug Shortages Statistics (323 record; 77% began 2022+):
https://www.ashp.org/drug-shortages/shortage-resources/drug-shortages-statistics
[4] Neprash et al., JAMA Health Forum 2022, Trends in Ransomware Attacks on US Health Care Delivery Organizations 2016-2021 (43 to 91 annual attacks; ~42M PHI):
https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9856685/
[5] 45 CFR 164.308 (Administrative safeguards, business associate contracts), eCFR:
https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
[6] FDA Roundup 18 October 2024 (temporary importation of 23 products from 5 facilities):
https://www.fda.gov/news-events/press-announcements/fda-roundup-october-18-2024
[7] Federal Register, Medical Devices; Quality System Regulation Amendments (QMSR final rule, effective 2 Feb 2026):
https://www.federalregister.gov/documents/2024/02/02/2024-01709/medical-devices-quality-system-regulation-amendments
[8] HHS, Healthcare and Public Health Cybersecurity Performance Goals:
https://hphcyber.hhs.gov/performance-goals.html
[9] FDA, Drug Supply Chain Security Act (DSCSA):
https://www.fda.gov/drugs/drug-supply-chain-integrity/drug-supply-chain-security-act-dscsa
[10] EUR-Lex, Directive (EU) 2022/2555 (NIS2), Article 21(2)(d):
https://eur-lex.europa.eu/eli/dir/2022/2555/oj
[11] EUR-Lex, Directive (EU) 2024/1760 (CSDDD):
https://eur-lex.europa.eu/eli/dir/2024/1760/oj











