Challenge
Organizations in the healthcare and medical industry in North America are challenged with achieving and maintaining HIPPA the Health Insurance Portability and Accountability Act, PCI-DSS the Payment Card Industry Data Security Standard and “State Data Breach” laws to ensure the privacy and security of personal healthcare information and credit card transactions. Similar to laws and regulations in North America, HIPPA and DPA the Data Protection Act, are the standards for handling personal information in the United Kingdom.
In addition to the laws and regulations enforced by these agencies to personal healthcare information and credit card transactions IT departments must meet the challenges of supporting remote workers through end point security, managing virtual and physical environments and implementing security solutions closer to the data source.
Traditional solutions such as network firewalls, virtual local area networks (VLANs) may be inadequate to meet the requirements set by compliance agencies and to difficult to deploy and manage.
Solution
Medical and healthcare organizations like CIGNA and the University Pennsylvania Health System have exceeded the requirements set by these compliance agencies by implementing the EpiForce Security software by Apani.
With the EpiForce security solution, Apani implements a layered approach to network segmentation. The first layer proactively eliminates vulnerabilities within the company’s network by isolating into logical security zones computers and the electronic patient health information stored on them. Traditional solutions such as network firewalls and virtual local area networks (VLANs) devices approach network segmentation from a hardware perspective limiting network management and flexibility, creating security gaps within the network.
Once computers are isolated into logical security zones, EpiForce strictly controls access to these zones and optionally and selectively encrypts data in motion between the computers in them creating a second level of security, regardless of platform or physical location or computer.
This solution reduces a healthcare firm’s attack surface leading to a lower risk of an internal data breach, a simplified compliance procedure and audit and flexibility in configuring end point security.
Related Resources
- California Agencies Become HIPAA Compliant
Here is how California agencies complied with HIPAA regulations by establishing and maintaining secure communications within a proprietary healthcare records management system. Initial Microsoft IPSec deployment had
limited effectiveness and no scalability due to significant management issues and multi-vendor incompatibilities.
|