Vendor hacked? 3 steps taken by hospital supply chain leaders

Advertisement

The Aug. 25 cyberattack targeting Boston Scientific disrupted order and shipment processing worldwide.  Although the company said Sept. 3 it has resumed shipping most products at its major distribution centers, as of Sept. 4 it was still working through a backlog of orders. The incident underscores how quickly a vendor cybersecurity incident can become a hospital supply chain problem.

The Boston Scientific incident follows a March cyberattack on Stryker that delayed surgeries for some patients after disruptions to ordering, manufacturing and shipping delayed the delivery of patient-specific implants.

Hospital and health system supply chain leaders describe a shared playbook for responding when a vendor is hit with a cyberattack, built around three moves: assess exposure quickly, maintain constant communication and have substitutes lined up before a crisis hits. Above all, hospital and health system leaders said vendor cyberattacks should be treated as patient care issues from the first hour, not just IT problems to be resolved on a vendor’s timeline.

Assess exposure quickly

Speed of assessment is the first priority. At Munson Healthcare in Traverse City, Mich., a supplier cyberattack triggers what Vice President of Supply Chain Tracy Cleveland called a standardized review of product exposure, inventory levels, PAR levels, procedural dependencies, scheduled patient care activities, ordering capabilities and the availability of clinically acceptable alternatives.

“This allows us to quickly assess patient care risk and implement mitigation strategies,” he said, adding that the goal is to protect clinical operations and preserve uninterrupted patient care.

Carlos Maceda, vice president of supply chain and chief supply chain officer at New York City-based Mount Sinai Health System, said his team runs every disruption through the same rubric regardless of cause: how long it will last, how many other vendors serve that space and how unique and critical the item is.

“Based on that rubric, we try to go to the market as quickly as possible,” he said.

Keep communication constant

That urgency carries into how leaders communicate once an incident hits. Livonia, Mich.-based Trinity Health leans on daily huddles with suppliers and internal teams to track risk and supply status, with a single assigned supply chain leader distributing formal updates to keep messaging consistent, said Senior Vice President of Supply Chain Management Dameka Miller. Daily inventory counts at each location round out the picture, guiding coordination between supply chain and clinical departments.

Judi Melton, director of supply chain at Salinas Valley Health in Salinas, Calif., described a similar cadence: sharing vendor communications immediately with executives, department leaders and physicians, then reviewing vendor updates daily and delivering action items during a daily leader huddle.

Don Barton, chief technical officer and director of supply chain management at Major Health Partners in Shelbyville, Ind., said his team stays in direct contact with the vendor and its representatives while looping in clinical end users right away “so they understand the situation and can help prioritize critical cases.”

Line up alternatives before a crisis

Several leaders said the real work happens before an attack, not during one. Mr. Barton’s team maintains a list of clinically acceptable alternatives for key products in its item master specifically so the supply chain “isn’t starting from scratch trying to find a substitute” when a vendor goes down. That preparation lets his team move quickly to evaluate availability, pricing, contracts and clinical acceptability once a switch is needed.

“The biggest lesson is that cybersecurity is now a supply chain risk, not just an IT risk,” he said. “Our goal is to have the communication, product alternatives and decision-making process established before the disruption occurs, not while we’re trying to find a product for tomorrow’s surgery.”

Ms. Melton’s team takes a similar approach, working with department subject matter experts to qualify alternate suppliers or substitute products and prioritize scarce inventory while documenting contingencies so procurement and clinical teams “can pivot quickly if the disruption persists.”

Sourcing alternatives quickly often means looking outside the usual competitive lines. At Bloomington, Minn.-based HealthPartners, Vice President of Supply Chain Services Vini Manchanda said staying connected with competitors can be valuable once an incident occurs, since internal stakeholders are gathered right away to identify alternate product portfolios. Procurement then activates a sourcing exercise, with daily check-ins established for affected service lines and coordination with group purchasing organizations where dependencies exist.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Supply Chain

Advertisement