SlideShare une entreprise Scribd logo
1  sur  2
Télécharger pour lire hors ligne
Case Study

                                                           Situation:
                                                           Like all healthcare provider organizations,
                                                           the company needed to find technologies
                                                           and methodologies to comply with IT security
                                                           requirements of HIPAA.
As a healthcare provider, our customer
needed to find ways to comply with the
IT security provisions of the Healthcare                   Solution:
Information Portability and Accountability                 The company licensed Policy Commander® to
Act (HIPAA). The company selected                          assist with HIPAA compliance through automated
Policy Commander® from New Boundary                        security configuration management.
Technologies to manage its Windows
security configurations and automate                        Quote:
compliance.                                                “Policy Commander gives us an incredible level
                                                           of control over the security state of Windows
Background:                                                systems used by our remote and internal staff.
With an eye toward meeting HIPAA data security             With Policy Commander, we’ve been able to
requirements, the company evaluated its IT                 establish a self-monitoring and self-correcting
operations and environment to find the right                security environment that often exceeds the HIPAA
technologies and processes that would help them            requirements.”
succeed. By leveraging the automated enforcement
functionality of Policy Commander, the company
created a sustainable compliance environment that
requires minimal administrator intervention.             Solution:
                                                         To achieve HIPAA Security Rule compliance, the
Challenge:                                               company first set out to convert the broad HIPAA IT
Because securing electronic patient health information   security requirements into specific organizational
(EPHI) is a key component of HIPAA compliance, the       rules and policies. New Boundary Technologies
company needed to find ways to secure all Windows         made this much easier by providing a HIPAA security
systems that could access that information. This task    configuration guide and HIPAA security policy library.
was complicated by the fact that the organization has    The customer’s IT department then translated those
users across the country that require remote access      requirements, leveraging the HIPAA security policy
to the network. In order to make those systems HIPAA     library, into enforceable Windows security policies that
compliant, the company decided to utilize the growing    create secure Windows configurations.
practice of security configuration management.
                                                         Result:
Environment:                                             The company is currently using Policy Commander
The organization has a widely distributed network        to achieve compliance on hundreds of remote
environment that encompasses a central office and         systems and 80 internal systems. According to their
hundreds of remote offices across the U.S. This           IT department, Policy Commander gives them the
includes approximately 600 remote users that use         flexibility they need to manage security configurations
virtual private networks to connect with the main        to their exact specifications.
corporate network. In addition, the company has
dozens of nodes within their corporate network that
need to be locked down since they contain or have
access to EPHI.
“One of the more important aspects of Policy                                  The company’s IT administrators also appreciate
                                                                                        pa
Commander is the visibility it gives us into the                              the level of integration between Policy Commander
                                                                                           i
configuration states of the Windows systems in our                             and Active Directory. “One of the great things about
                                                                                          D
environment. That combined with the ability to force                          Policy Commander is that it pulls the Active Directory
                                                                                           ma
compliance with the automated policy enforcement                              structure just the way it is. Setting up the Active
                                                                                             t th
feature gives us an unprecedented level of control                            Directory in Policy Commander is really fast and
                                                                                               ol
that we really need for HIPAA compliance.”                                    easy. I don’t need to modify it in any way. I just import
                                                                                                ee
                                                                              it and use it.”
According to the customer, becoming HIPAA
compliant involved some major changes in their                                In addition to using Policy Commander to support
                                                                                                ng
network and desktop administration. “One of the first                          compliance efforts, the company also uses Prism
                                                                                                 s, t
items on our HIPAA compliance agenda was to get                               Suite™ to distribute software applications to remote
                                                                                                  es
users to their appropriate level of user rights. That                         users. The company says there are some key
                                                                                                    ys
meant taking away administrative rights to all users.                         advantages to using both Policy Commander and
                                                                                                      bo
But with HIPAA as a driving factor, IT needs a high                           Prism Suite. “We like that Prism Suite and Policy
                                                                                                       th
level of control over the computers we support, and                           Commander have a common client, and the two
that’s what Policy Commander gives us.”                                       products working in tandem give us a really powerful
                                                                              but easy to use configuration management solution.”
Another key feature that the customer touts is the
Policy Editor. “We really like having the ability to                          NOTE: This case study is based on information
create our own policies and customize the NIST and                            provided by a current New Boundary Technologies®
NSA security policies to fit our environment. If you                           customer that licenses Policy Commander® and
define and architect your policies well to begin with,                         Prism Suite™. By request of the customer, we have
you can basically set up your environment and forget                          not identified the company.
it. You don’t have to worry about computers drifting
out of compliance or users making unauthorized
changes that can affect the outcome of an audit.”




NEW BOUNDARY
                                                                          ®
          T    E    C     H     N     O     L    O      G     I   E   S



New Boundary Technologies®
1300 Godward Street NE, Suite 3100
Minneapolis, MN 55413
Tel. 612.379.3805 / Toll-free 800.747.4487
Fax 612.378.3818
www.newboundary.com
info@newboundary.com
                                                                              Prism Suite is a trademark and Policy Commander is a registered trademark of New
                                                                              Boundary Technologies, Inc. All other brands and product names are trademarks or
© 2007 New Boundary Technologies, Inc. All rights reserved.                   registered trademarks of their respective companies.

Contenu connexe

En vedette

Quedarse embarazada trucos
Quedarse embarazada trucosQuedarse embarazada trucos
Quedarse embarazada trucosSebastián
 
Gestión por competencias en la administración pública
Gestión por competencias en la administración públicaGestión por competencias en la administración pública
Gestión por competencias en la administración públicambformacion
 
Oggi in consegna a All Nippon Airways (ANA) il primo Boeing 787 Dreamliner
Oggi in consegna a All Nippon Airways (ANA) il primo Boeing 787 DreamlinerOggi in consegna a All Nippon Airways (ANA) il primo Boeing 787 Dreamliner
Oggi in consegna a All Nippon Airways (ANA) il primo Boeing 787 DreamlinerLeonardo
 
Motores de búsqueda cuadro
Motores de búsqueda cuadroMotores de búsqueda cuadro
Motores de búsqueda cuadrotkmmellisa
 
Partes de una computadora
Partes de una computadoraPartes de una computadora
Partes de una computadoraCynthia Rmzz
 
Uma Narrativa de Lucélia-SP: o Avanço do Capital no Oeste do Estado de São Pa...
Uma Narrativa de Lucélia-SP: o Avanço do Capital no Oeste do Estado de São Pa...Uma Narrativa de Lucélia-SP: o Avanço do Capital no Oeste do Estado de São Pa...
Uma Narrativa de Lucélia-SP: o Avanço do Capital no Oeste do Estado de São Pa...alinehasegawa
 

En vedette (8)

Quedarse embarazada trucos
Quedarse embarazada trucosQuedarse embarazada trucos
Quedarse embarazada trucos
 
Gestión por competencias en la administración pública
Gestión por competencias en la administración públicaGestión por competencias en la administración pública
Gestión por competencias en la administración pública
 
Oggi in consegna a All Nippon Airways (ANA) il primo Boeing 787 Dreamliner
Oggi in consegna a All Nippon Airways (ANA) il primo Boeing 787 DreamlinerOggi in consegna a All Nippon Airways (ANA) il primo Boeing 787 Dreamliner
Oggi in consegna a All Nippon Airways (ANA) il primo Boeing 787 Dreamliner
 
Cyclassics 2013 pdf
Cyclassics 2013 pdfCyclassics 2013 pdf
Cyclassics 2013 pdf
 
Motores de búsqueda cuadro
Motores de búsqueda cuadroMotores de búsqueda cuadro
Motores de búsqueda cuadro
 
Partes de una computadora
Partes de una computadoraPartes de una computadora
Partes de una computadora
 
Balancete
BalanceteBalancete
Balancete
 
Uma Narrativa de Lucélia-SP: o Avanço do Capital no Oeste do Estado de São Pa...
Uma Narrativa de Lucélia-SP: o Avanço do Capital no Oeste do Estado de São Pa...Uma Narrativa de Lucélia-SP: o Avanço do Capital no Oeste do Estado de São Pa...
Uma Narrativa de Lucélia-SP: o Avanço do Capital no Oeste do Estado de São Pa...
 

Dernier

Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024The Digital Insurer
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfOrbitshub
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Victor Rentea
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Victor Rentea
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024The Digital Insurer
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 

Dernier (20)

Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 

IT HIPAA Compliance

  • 1. Case Study Situation: Like all healthcare provider organizations, the company needed to find technologies and methodologies to comply with IT security requirements of HIPAA. As a healthcare provider, our customer needed to find ways to comply with the IT security provisions of the Healthcare Solution: Information Portability and Accountability The company licensed Policy Commander® to Act (HIPAA). The company selected assist with HIPAA compliance through automated Policy Commander® from New Boundary security configuration management. Technologies to manage its Windows security configurations and automate Quote: compliance. “Policy Commander gives us an incredible level of control over the security state of Windows Background: systems used by our remote and internal staff. With an eye toward meeting HIPAA data security With Policy Commander, we’ve been able to requirements, the company evaluated its IT establish a self-monitoring and self-correcting operations and environment to find the right security environment that often exceeds the HIPAA technologies and processes that would help them requirements.” succeed. By leveraging the automated enforcement functionality of Policy Commander, the company created a sustainable compliance environment that requires minimal administrator intervention. Solution: To achieve HIPAA Security Rule compliance, the Challenge: company first set out to convert the broad HIPAA IT Because securing electronic patient health information security requirements into specific organizational (EPHI) is a key component of HIPAA compliance, the rules and policies. New Boundary Technologies company needed to find ways to secure all Windows made this much easier by providing a HIPAA security systems that could access that information. This task configuration guide and HIPAA security policy library. was complicated by the fact that the organization has The customer’s IT department then translated those users across the country that require remote access requirements, leveraging the HIPAA security policy to the network. In order to make those systems HIPAA library, into enforceable Windows security policies that compliant, the company decided to utilize the growing create secure Windows configurations. practice of security configuration management. Result: Environment: The company is currently using Policy Commander The organization has a widely distributed network to achieve compliance on hundreds of remote environment that encompasses a central office and systems and 80 internal systems. According to their hundreds of remote offices across the U.S. This IT department, Policy Commander gives them the includes approximately 600 remote users that use flexibility they need to manage security configurations virtual private networks to connect with the main to their exact specifications. corporate network. In addition, the company has dozens of nodes within their corporate network that need to be locked down since they contain or have access to EPHI.
  • 2. “One of the more important aspects of Policy The company’s IT administrators also appreciate pa Commander is the visibility it gives us into the the level of integration between Policy Commander i configuration states of the Windows systems in our and Active Directory. “One of the great things about D environment. That combined with the ability to force Policy Commander is that it pulls the Active Directory ma compliance with the automated policy enforcement structure just the way it is. Setting up the Active t th feature gives us an unprecedented level of control Directory in Policy Commander is really fast and ol that we really need for HIPAA compliance.” easy. I don’t need to modify it in any way. I just import ee it and use it.” According to the customer, becoming HIPAA compliant involved some major changes in their In addition to using Policy Commander to support ng network and desktop administration. “One of the first compliance efforts, the company also uses Prism s, t items on our HIPAA compliance agenda was to get Suite™ to distribute software applications to remote es users to their appropriate level of user rights. That users. The company says there are some key ys meant taking away administrative rights to all users. advantages to using both Policy Commander and bo But with HIPAA as a driving factor, IT needs a high Prism Suite. “We like that Prism Suite and Policy th level of control over the computers we support, and Commander have a common client, and the two that’s what Policy Commander gives us.” products working in tandem give us a really powerful but easy to use configuration management solution.” Another key feature that the customer touts is the Policy Editor. “We really like having the ability to NOTE: This case study is based on information create our own policies and customize the NIST and provided by a current New Boundary Technologies® NSA security policies to fit our environment. If you customer that licenses Policy Commander® and define and architect your policies well to begin with, Prism Suite™. By request of the customer, we have you can basically set up your environment and forget not identified the company. it. You don’t have to worry about computers drifting out of compliance or users making unauthorized changes that can affect the outcome of an audit.” NEW BOUNDARY ® T E C H N O L O G I E S New Boundary Technologies® 1300 Godward Street NE, Suite 3100 Minneapolis, MN 55413 Tel. 612.379.3805 / Toll-free 800.747.4487 Fax 612.378.3818 www.newboundary.com info@newboundary.com Prism Suite is a trademark and Policy Commander is a registered trademark of New Boundary Technologies, Inc. All other brands and product names are trademarks or © 2007 New Boundary Technologies, Inc. All rights reserved. registered trademarks of their respective companies.