top of page

The Medical Event Detection and Incident Coordination (MEDIC) system is a proof-of-concept cyber threat matrix for the Healthcare and Public Health (HPH) Sector that explores whether healthcare would benefit from a shared, sector-specific way to model cyber behaviors involving clinical systems, medical devices, healthcare data formats, and patient-care consequences. Inspired by efforts to provide sector-specific extensions to ATT&CK for Enterprise, such as SPARTA and ATM, MEDIC does not seek to replace general-purpose frameworks, but to test whether certain healthcare-native tactics, techniques, and sub-techniques can be described more clearly when the underlying asset, workflow, or impact is distinctly clinical. This initial draft is intentionally limited in scope and uses a small set of representative examples to demonstrate potential value rather than completeness.
bottom of page
