Why Health Care Needs Its Own Lens
Consumer and Product Responsibility: A Starter Guide lays out the generic case for Standard ESG subject S5 — product safety, fair marketing, complaint handling, data protection — across every industry that sells to consumers. Health care sharpens every one of those generic categories into something with materially higher stakes: a mislabelled product recall is a costly inconvenience for a furniture retailer and a patient-safety event for a pharmaceutical company; a data breach exposes a shopping history for an e-commerce site and a patient's health diagnosis for a pharmacy. SASB's response is four separate Health Care sector standards — Biotechnology & Pharmaceuticals (SICS HC-BP), Health Care Distributors (HC-DI), Medical Equipment & Supplies (HC-MS), and Drug Retailers (HC-DR) — each covering a different stage of the same value chain, rather than one generic "health care" standard papering over how differently a drugmaker, a distributor, a device manufacturer, and a pharmacy actually operate.
The Four SASB Health Care Standards at a Glance
Each standard organizes its material risks into a small set of named disclosure topics, each with its own accompanying metrics (SASB's own terms: disclosure topics describe a specific sustainability-related risk or opportunity; metrics quantify or describe an entity's performance against a topic; activity metrics normalize company size so metrics can be compared across entities):
- Biotechnology & Pharmaceuticals — Safety of Clinical Trial Participants, Access to Medicines, Affordability & Pricing, Drug Safety, Counterfeit Drugs, Ethical Marketing, Employee Recruitment/Development/Retention, Supply Chain Management, Business Ethics.
- Health Care Distributors — Fleet Fuel Management, Product Safety, Counterfeit Drugs, Product Lifecycle Management, Business Ethics.
- Medical Equipment & Supplies — Affordability & Pricing, Product Safety, Ethical Marketing, Product Design & Lifecycle Management, Supply Chain Management, Business Ethics.
- Drug Retailers — Energy Management in Retail, Data Security & Privacy, Drug Supply Chain Integrity, Management of Controlled Substances, Patient Health Outcomes.
Four clear threads run across multiple standards despite each having its own industry-specific framing: product/patient safety (Drug Safety, Product Safety, Patient Health Outcomes), supply chain integrity against counterfeiting (Counterfeit Drugs in both HC-BP and HC-DI, Supply Chain Management in HC-MS, Drug Supply Chain Integrity in HC-DR), business ethics toward health care professionals (a named topic in HC-BP, HC-DI, and HC-MS alike), and pricing/affordability (HC-BP and HC-MS both disclose list- and net-price changes). The sections below work through what each thread actually requires, drawing the metric codes directly from the standards so template authors can trace every claim back to its source.
Drug Pricing, Access, and Affordability
HC-BP's Access to Medicines topic asks entities to describe actions and initiatives promoting access to health care products for priority diseases and in priority countries, as defined by the Access to Medicine Foundation's Access to Medicine Index (HC-BP-240a.1), and to disclose which of the entity's products appear on the WHO's List of Prequalified Medicinal Products under its Prequalification of Medicines Programme (HC-BP-240a.2) — a concrete, checkable list rather than a self-reported narrative. Affordability & Pricing then turns to the commercial side of the same issue: HC-BP requires the annualized percentage change in both the revenue-weighted average list price and the average net price across an entity's full product portfolio compared to the previous reporting period (HC-BP-240b.2), plus the same figures isolated for whichever single product saw the largest increase (HC-BP-240b.3) — a metric specifically designed to surface the kind of outlier price hike that draws the most public and regulatory scrutiny. Medical Equipment & Supplies carries a lighter version of the same topic: a description of how price information is disclosed to customers or their purchasing agents, including how often confidentiality clauses restrict providers from sharing what they actually paid (HC-MS-240a.2), plus the same weighted list/net price change metric (HC-MS-240a.3). Distributors and retailers don't carry a dedicated pricing topic of their own — pricing pressure reaches them indirectly, through the affordability dynamics of the products they move rather than as a standalone disclosure topic.
Clinical Trial Safety and Data Integrity
Safety of Clinical Trial Participants is unique to Biotechnology & Pharmaceuticals, reflecting how much of that industry's risk sits upstream of any product actually reaching a patient. HC-BP-210a.1 requires a region-by-region discussion of the entity's oversight of contract research organizations (CROs) — audit type and frequency, enforcement mechanisms, and how informed consent is obtained and documented. HC-BP-210a.2 requires the number of inspections that identified objectionable clinical conditions or practices, split between those the entity voluntarily remediated and those that triggered a regulatory or administrative action — a distinction that lets a reader tell self-correction apart from enforcement-forced correction. HC-BP-210a.3 requires the total monetary losses from legal proceedings tied specifically to clinical trials conducted in developing countries, on the reasoning that trial-participant protections are hardest to verify, and most consequential to get wrong, in jurisdictions with weaker regulatory oversight capacity.
Product Safety, Adverse Events, and Recalls
Every product-facing standard in the Health Care sector carries some version of this topic, and the metrics are unusually specific for an ESG framework. HC-BP's Drug Safety and HC-MS's Product Safety both require: the number of the entity's products listed in public medical product safety or adverse-event alert databases, including the WHO's VigiBase (HC-BP-250a.1 / HC-MS-250a.2); the total number of product-related fatalities (HC-BP-250a.2 / HC-MS-250a.3); the number of recalls issued and total units recalled (HC-BP-250a.3 / HC-MS-250a.1); and the number of enforcement actions taken over violations of good manufacturing practices, or GMP (HC-BP-250a.5 / HC-MS-250a.4). HC-BP adds a fifth metric specific to pharmaceuticals: the total weight of product accepted back for take-back, reuse, or disposal (HC-BP-250a.4), covering both controlled redistribution to underserved populations and safe destruction of expired or unwanted medication. Drug Retailers' Patient Health Outcomes topic closes the loop at the point of sale: first-fill medication-adherence rate (HC-DR-260b.1), a description of policies to prevent prescription dispensing errors (HC-DR-260b.2), and monetary losses from legal proceedings tied to dispensing errors specifically (HC-DR-260b.3) — the one place in the sector's four standards where the metric measures a patient's actual clinical outcome rather than a product's design or handling.
Counterfeit Drugs and Supply Chain Integrity
Counterfeit and compromised product is the sector's most consistently recurring disclosure topic, appearing under a different name in three of the four standards. HC-BP's and HC-DI's Counterfeit Drugs topics both require a description of the technologies used to maintain product traceability and prevent counterfeiting — barcode and RFID tagging are the two SASB names explicitly — and a description of how customers and business partners are alerted to known or potential counterfeit risk. HC-DI adds a distributor-specific metric that HC-BP doesn't carry: a discussion of the due-diligence process used to qualify suppliers of drug products and medical equipment (HC-DI-260a.2), reflecting that a distributor's primary counterfeit exposure is upstream, in who it buys from, rather than downstream in who it sells to. HC-BP alone requires a quantitative count of counterfeit-related enforcement — raids, seizures, arrests, or criminal charges filed (HC-BP-260a.3). Medical Equipment & Supplies frames the same underlying risk as Supply Chain Management: the percentage of the entity's own facilities and its Tier I suppliers' facilities participating in third-party audit programmes for manufacturing and product quality (HC-MS-430a.1), traceability efforts within the distribution chain (HC-MS-430a.2), and a description of how the entity manages risk associated with critical materials (HC-MS-430a.3). Drug Retailers' Drug Supply Chain Integrity rounds this out from the pharmacy-counter end: a description of efforts to reduce the occurrence of compromised drugs within the supply chain, and the number and percentage of recalls issued for private-label products specifically (HC-DR-250a.2) — a metric that exists because a retailer's own store-brand products carry supply chain integrity risk the retailer can't simply pass upstream to a manufacturer.
Data Security and Controlled Substances in Pharmacy Retail
Two topics are unique to Drug Retailers, both a direct consequence of operating the point of sale where a patient's identity, health condition, and medication history all converge in one transaction. Data Security & Privacy requires a description of policies to secure customers' personal health data and other personal data (HC-DR-230a.1); the number of data breaches, split between those involving personal data only and those involving personal health data specifically, and the number of customers affected in each category (HC-DR-230a.2); and the total monetary losses from legal proceedings tied to data security and privacy (HC-DR-230a.3) — a three-tier structure that lets a reader distinguish a minor loyalty-card breach from one that exposed diagnosis-level health information. Management of Controlled Substances requires the total monetary losses from legal proceedings associated specifically with controlled substances (HC-DR-260a.2), reflecting the retailer's distinct regulatory exposure — diversion, over-dispensing, and opioid-related liability — that a generic-merchandise retailer simply doesn't carry. Neither topic has a direct counterpart anywhere else in the sector's four standards.
Business Ethics and Marketing to Health Care Professionals
Business Ethics appears by name in HC-BP, HC-DI, and HC-MS, each requiring the total monetary losses from legal proceedings tied to bribery or corruption, and a description of the entity's code of ethics governing interactions with health care professionals — language that targets the sector's specific corruption exposure: payments, gifts, and incentives offered to the physicians and institutions that decide what gets prescribed or purchased. HC-BP and HC-MS both additionally carry a dedicated Ethical Marketing topic: monetary losses from legal proceedings tied to false marketing claims, and a description of the entity's code of ethics governing promotion of off-label use — marketing a drug or device for a purpose the regulator never approved it for, one of the industry's most heavily enforced categories of misconduct. HC-DI is the one standard in the sector without a separate ethical marketing topic, consistent with a distributor's more limited direct marketing exposure to prescribers and patients relative to a manufacturer.
Mapping to Standard ESG Subjects
The bulk of these four standards' disclosure topics — access to medicines, affordability, drug and product safety, counterfeit-drug protection, data security, and patient health outcomes — sit squarely inside Standard ESG's S5 — Consumer/end-user responsibility, the same industry-dependent subject Consumer and Product Responsibility introduces generically. For a health care SEIC group, these SASB topics give S5's generic product-safety and data-protection indicators specific, checkable content: a recall-and-take-back process, a documented counterfeit-detection and supplier due-diligence programme, and health-data-specific breach reporting are all more concrete than the generic S5 language alone would produce. The sector's Business Ethics and Ethical Marketing topics map instead to G2 — Ethics, anti-corruption & fair operating practices, since payments to prescribers and off-label promotion are fair-operating-practices risks toward business counterparts (health care professionals and institutions), not consumer-facing risks. The counterfeit and supplier-audit metrics also touch G4 — Sustainable procurement & supply-chain management, particularly HC-MS's Tier I supplier audit percentage and HC-DI's supplier due-diligence discussion, which are supply-chain oversight metrics as much as they are consumer-safety ones. HC-BP's single Employee Recruitment, Development & Retention topic — turnover by seniority tier among scientists and R&D staff — is the sector's only direct touch on S1 — Labour practices & decent work, and HC-DI's and HC-DR's fleet-fuel and retail-energy topics are each a narrow, sector-specific instance of E2 — Resource use.
Which SEIC Sectors This Deepens Coverage For
These four standards carry the most weight for exactly the SEIC groups their SICS codes name directly: pharmaceutical and biotechnology manufacturers (HC-BP), wholesale pharmaceutical and medical-equipment distributors (HC-DI), medical device and supply manufacturers (HC-MS), and retail pharmacy chains (HC-DR). A company straddling more than one stage of the value chain — a vertically integrated manufacturer-distributor, or a pharmacy chain with its own private-label manufacturing — should, per SASB's own guidance, consider the disclosure topics of every relevant standard rather than only its primary SICS industry. Outside health care, a handful of these topics have direct analogues elsewhere in the library worth cross-referencing: counterfeit and supply chain integrity parallels the authentication and traceability themes in Sustainable Sugarcane Production: The Bonsucro Standard Explained's chain-of-custody discussion, and business ethics toward professional counterparts parallels Corporate Governance, Ethics and Anti-Corruption's general G2 treatment.
Getting Started
A health care company building out its S5 and G2 evidence base can work through these four standards' shared threads roughly in order of how directly they touch patients:
- Identify which of the four standards actually apply to your business — most companies sit primarily in one, but a vertically integrated business should check all that apply, per the SEIC sector mapping above.
- Inventory your product-safety and recall processes first: every product-facing standard in the sector treats this as foundational, and it's the metric set most directly tied to patient harm.
- Document your supply chain and counterfeit-prevention controls, including supplier due-diligence and audit-participation records if you're a distributor or device manufacturer.
- If you handle patient data directly — a pharmacy or a digital health service — confirm your breach-reporting process can actually distinguish personal data from personal health data, per HC-DR-230a.2's own three-tier structure.
- Review your code of ethics governing interactions with health care professionals and, if applicable, promotion of off-label use — this is the sector's most consistently recurring governance exposure across all four standards.
See What to Expect from an On-Site ESG Assessment (Level 3) for how supply-chain and data-trail evidence like this gets checked physically on site.
Standard ESG (standardesg.org) draws on SASB's four Health Care sector standards to deepen subject S5 for pharmaceutical, distribution, medical-device, and retail pharmacy companies, alongside G2 and G4 for the sector's ethics and supply-chain exposure. See The Standard ESG Certification Protocol: A Public Overview for how industry-dependent subjects fit into the full pillar and subject architecture.
Was this page useful?