Case Studies > Protecting Patient Data in the Cloud: A Healthcare Case Study

Protecting Patient Data in the Cloud: A Healthcare Case Study

Company Size
200-1,000
Region
  • America
Country
  • United States
Product
  • Catbird TrustZones
  • VMware vCNS
  • Catbird
Tech Stack
  • VMware
  • Catbird
  • Microsoft
Implementation Scale
  • Enterprise-wide Deployment
Impact Metrics
  • Customer Satisfaction
Technology Category
  • Application Infrastructure & Middleware - API Integration & Management
  • Cybersecurity & Privacy - Network Security
  • Cybersecurity & Privacy - Security Compliance
Applicable Industries
  • Healthcare & Hospitals
Applicable Functions
  • Facility Management
Services
  • Cloud Planning, Design & Implementation Services
  • Cybersecurity Services
  • System Integration
About The Customer
Jefferson Radiology is a private radiology company with 10 outpatient centers and provides radiology services to 8 hospitals. They rely heavily on technology to maintain a competitive advantage. Their environment is 90-percent virtual, spread across two data centers, and built with specific security considerations to ensure patient data protection and compliance with HIPAA and HITECH. In 2012, they began using Catbird for virtualization threat management to meet regulatory security requirements and prove compliance. Their data centers are based on VMware, with a mix of standard and distributed switches, integrating with VMware’s virtual network infrastructure for centralized management.
The Challenge
Jefferson Radiology needed to meet regulatory requirements to adequately protect patient data and prove HIPAA and HITECH compliance within their virtual data centers. The challenge was to maintain HIPAA compliance while adopting cloud solutions, ensuring that patient data is protected and compliant with HIPAA and HITECH. They struggled with expensive, manual processes to provide the evidence necessary to prove compliance and protect patient data. Additionally, they faced difficulties in managing and auditing their virtual environment, particularly with net flow visibility within the switches.
The Solution
Catbird enables segmentation with TrustZones, policy enforcement, and net flow visibility. With Catbird, Jefferson Radiology can strictly control access to patient data and mitigate any breach or policy violation. Catbird is a 100 percent software solution deployed on virtual and cloud infrastructure. It provides multiple security controls required for HIPAA compliance, maps those controls to the HIPAA framework, enforces HIPAA policy, provides real-time visibility to compliance status and net flow, and delivers audit-ready reports. Catbird integrates with VMware’s virtual network infrastructure, providing centralized management and net flow visibility into one console, validating what is being sent over the network.
Operational Impact
  • Catbird provides logical segmentation via TrustZones, allowing Jefferson Radiology to create logical groups of assets and enforce policies.
  • The solution offers perfect inventory of virtual assets, ensuring that all assets are accounted for and managed effectively.
  • Dynamic firewall control updates and enforcement of security policies with continuous monitoring, alerts, mitigation, and quarantine.
  • Security controls are mapped to compliance frameworks such as PCI, HIPAA, FISMA, and SOX, ensuring comprehensive compliance.
  • Catbird delivers proof of compliance with audit capabilities, real-time data flow, compliance graphics, and audit-ready reports.
Quantitative Benefit
  • Jefferson Radiology's environment is 90-percent virtual, spread across two data centers.
  • Catbird provides real-time visibility to compliance status and net flow, ensuring continuous monitoring and compliance.
  • The solution integrates with VMware’s virtual network infrastructure, providing centralized management and net flow visibility into one console.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.