Netwrix > Case Studies > Landspitali University Hospital Secures Medical Research and Data Protected by GDPR and Icelandic Privacy Law

Landspitali University Hospital Secures Medical Research and Data Protected by GDPR and Icelandic Privacy Law

Netwrix Logo
Applicable Industries
  • Healthcare & Hospitals
  • National Security & Defense
Applicable Functions
  • Product Research & Development
Use Cases
  • Smart Campus
  • Tamper Detection
Services
  • System Integration
  • Training
About The Customer
Landspitali, the National University Hospital of Iceland, is the country’s leading hospital and the largest workplace in healthcare, with around 6,000 employees. Landspitali serves three main roles: service to patients, teaching and training of clinical staff, and scientific research. The hospital offers diverse clinical services in outpatient clinics, day patient units, inpatient wards, critical care units, clinical laboratories, and other divisions. The hospital is committed to ensuring the security and privacy of its patients' and employees' data, in compliance with GDPR and Icelandic privacy laws.
The Challenge
Landspitali University Hospital was faced with the challenge of improving the security of patients’ and employees’ Personally Identifiable Information (PII) and Protected Health Information (PHI) to comply with the General Data Protection Regulation (GDPR) and the Icelandic Data Protection Act. This included ensuring that only authorized staff could access this data. The hospital also needed to secure other sensitive information, such as contracts, medical devices, and research documents, which was crucial for retaining the hospital’s research licenses and ensuring uninterrupted patient care. The hospital had to control 8,500 user objects daily, and the auditing process was time-consuming, taking up to 59 hours per audit.
The Solution
The hospital chose Netwrix Auditor as their solution. The system administrator at Landspitali, Auður Ester Guðlaugsdóttir, praised the system for its smooth operation and comprehensive audit data. The solution ensured the security of sensitive files, allowing the IT department to carefully audit activity that might involve sensitive data, including the personal data of patients or employees. The IT department could review daily activity across the IT infrastructure and also receive alerts about actions that could put data at risk. Netwrix Auditor also streamlined privilege attestations, enabling the IT team to provide accurate reports on access rights in less than an hour, a significant reduction from the previous 60 hours. The solution also enhanced control over Active Directory, providing visibility into what happens across Active Directory, which is at the heart of the hospital’s IT infrastructure.
Operational Impact
  • The implementation of Netwrix Auditor has brought about significant operational improvements for Landspitali University Hospital. The solution has ensured the security of sensitive information, enabling strong data access governance. It has also improved control over critical changes in Active Directory. The IT department is now able to spot anomalies in time to protect data from being compromised. They are also notified about changes to the membership of critical groups like Domain Admins, critical computer accounts, OUs, etc., so they can take action quickly to prevent security breaches or system disruptions. This has not only improved the hospital's data security but also its compliance with GDPR and Icelandic privacy laws.
Quantitative Benefit
  • 8,500 user objects controlled daily
  • 59 hours saved per audit
  • Reports on access rights provided in less than an hour, down from 60 hours

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.