NAVEX > Case Studies > Major Health Information Network Connects To Better Information Security

Major Health Information Network Connects To Better Information Security

NAVEX Logo
Company Size
1,000+
Region
  • America
Country
  • United States
Product
  • NAVEX IRM
Tech Stack
  • GRC Platform
Implementation Scale
  • Enterprise-wide Deployment
Impact Metrics
  • Cost Savings
  • Digital Expertise
  • Productivity Improvements
Technology Category
  • Application Infrastructure & Middleware - Data Exchange & Integration
Applicable Industries
  • Healthcare & Hospitals
Applicable Functions
  • Business Operation
Use Cases
  • Regulatory Compliance Monitoring
  • Remote Asset Management
Services
  • System Integration
About The Customer
The customer is the nation’s largest health information network. It processes a significant amount of data, often involving personally identifiable information (PII). The company has to comply with a range of regulations and industry standards, including the Health Information Portability and Accountability Act (HIPAA), Electronic Healthcare Network Accreditation Commission (EHNAC), Sarbanes-Oxley (SOX), Payment Card Industry Data Security Standards (PCI DSS), and the International Organization for Standards (ISO). The company's Information Security department was viewed as a cost center and had difficulty securing funding and justifying budget requests without clear insight into IT and information security risks.
The Challenge
The nation’s largest health information network faced significant challenges in managing information security, particularly due to the sensitive nature of the data it processed. The company had to comply with a range of regulations and industry standards, including HIPAA, EHNAC, SOX, PCI DSS, and ISO. The complexity of these compliance requirements was compounded by the company’s lack of visibility into current and pressing risks, making it difficult to provide data or metrics to inform management decisions. Additionally, the company’s Information Security department struggled to secure funding, as it was viewed as a cost center and had difficulty justifying budget requests without clear insight into IT and information security risks.
The Solution
The health information network selected NAVEX’s governance, risk management, compliance (GRC) platform, NAVEX IRM, for its capabilities in integrated risk management (IRM). NAVEX IRM enabled the company to gain a comprehensive view of their business and operations from a risk perspective, connecting individual risk disciplines and managing them in one centralized program. The company utilized NAVEX IRM’s centralized compliance library, which houses all compliance activities, regulations, industry standards, and best practice frameworks. The company’s controls were also linked in the central location, enabling one control to satisfy compliance with multiple requirements. NAVEX IRM provided access to risk data and metrics that were easy to share with management in reports and dashboards. This data informed Information Security’s operations, allowing them to review a list of risks for a proposed project and then prioritize funding for remediation efforts.
Operational Impact
  • Compliance that was complex and time-consuming became easier and more productive.
  • Visibility into risk management that was non-existent before came into view and is now measurable and reportable.
  • NAVEX IRM increased collaboration efforts and streamlined communications, which were significant pain points when information was shared using e-mails and spreadsheets.
  • Time saved using NAVEX IRM has opened doors for Information Security to take on additional responsibilities—internal auditing, business continuity, and operational risk management—without adding staff.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.