Background
An Acute Care Facility in the Midwest part of US with over 700 physicians and nearly 200 beds; discharges more than 10,000 patients per year. The organization wanted to comply with the regulatory requirements and perform the gaps identified in a recent HIPAA/ HITECH Security Risk Assessment.
In order to effectively implement the HIPAA safeguards and also to safeguard the organization against breaches, the acute care facility has implemented the following security solutions like
- Endpoint Detection and Response (EDR),
- Security Information and Event Management (SIEM),
- Intrusion prevention systems (IPS),
- Identity access management (IAM),
- Privileged access management (PAM),
- Privileged Identity Management (PIM),
- Data loss prevention (DLP),
- Mobile Device Management (MDM),
- Email Security and Cloud Security.
Protecting information and infrastructure is paramount for patient safety.
HIPAA/HITECH regulations require Healthcare organizations to implement security policies, and systems to keep patient health information safe and to ensure confidentiality, integrity, and availability. It is also required to monitor changes and validate the configurations and associated policies.
"The acute care facility wanted to secure its environment, monitor the network 24x7x365, stop any threats, ensure, and be able to demonstrate HIPAA security implementation specification compliance on demand."
Solution
HIPAA/HITECH regulations require Healthcare organizations to implement security policies, and systems to keep patient health information safe and to ensure confidentiality, integrity, and availability. It is also required to monitor changes and validate the configurations and associated policies.
Several security implementation specifications under HIPAA/HITECH require organizations to implement safeguard measures, to name a few.
- §164.308 (a) (5) (ii) (B) - Antivirus and Malware software
- §164.308 (a) (1) (ii) (D) - Capture, review, and storage of all logs and events
- §164.312 (a) (1) - Unique User Identification
- §164.308(a)(3)(ii)(B) - Role-based access to sensitive information
- §164.308 (a) (5) (ii) - Monitoring for unauthorized access, failed login attempts, password policy
- §164.312(a)(2)(iv) - Encryption of data at rest and in motion
- §164.310(d)(1) - List of all assets with location and data storage
- § 164.312(b)- Limiting use of the internet and downloading of software
- § 164.308(a)(7) - Conducting tabletop exercises.
- § 164.316(b) - Evidence of following the security policies
Working with the acute care facility’s IT security team Fortuna Cysec was able to assess the implemented solutions, find gaps in the implementations, bring best practices and discuss with the team.
Using TheFense product was able to implement a single platform integrating with their existing systems bringing all of the data from various security systems. In addition, deployed Asset Management system which operated as a primary source of truth for all security systems.Network Detection and Response (NDR).
TheFense system was able to streamline all the events and alerts from various systems and perform Alert Correlation and Alert Prioritization. In addition to implementing TheFense platform, Fortuna Cysec added the 24x7x365 Manage and Detect Services from its SOC2 Type2 compliant and redundant Security Operation Center (SOC).
Current Status
Fortuna Cysec was not only able to ensure HIPAA/ HITECH regulatory compliance by closing the gaps in the corrective action plan, but it was also able to manage the systems, configure the industry best practices & security policies of the organization, and monitor the events and alerts 24x7x365.
Fortuna Cysec now maintains on an ongoing basis the systems and blocks new threats by ingesting threat intelligence, hunting for threats, and performing faster threat detection and response with effective incident management.
Fortuna Cysec was able to reduce the operational budget by 40% providing more coverage and performing all the SOC activities 24x7x365.
TheFense platform which is a managed platform with 24X7X365 Managed Detection and Response provides the acute care facility with one single platform with the security tools that form a cohesive, interconnected, interactive, configurable, dynamic cybersecurity platform with various modules and also eliminates the need for extensive and skilled in-house resources. This helps protect sensitive data from cyber threats and reduces the costs of purchasing various security tools. Also, it is able to clearly demonstrate compliance with HIPAA/HITECH and cyber insurance requirements.