Identity and access management — the new challenges for healthcareMany countries have introduced or are introducing legislation to ensure the security and privacy of health information. Complying with these new rules can be a costly headache if done manually or using inadequate tools. We describe a more rational approach, focusing on the specfic example of the United States HIPAA requirements and terminology (see box). Among the stated goals of HIPAA are an improvement of the health insurance and health care industries in terms of protection of health information and cost reduction through administrative simplification. The Security and Privacy Rules are designed to make sure that patient health information is not misused. As more and more health information is now available in electronic format, it is critical to control access to systems and applications containing that information. Covered Entities are required to implement technical safeguards and security measures in order to restrict access to users and patients on a need-to-know basis. These technical safeguards can be very time-consuming and even ineffective if you restrict yourself to out-of-the-box security provided by application or server vendors. Individually configuring each such data repository — and workstation — so that they comply with the Security and Privacy Rules is not a good solution. The best way is to implement a global Identity and Access Management (IAM) solution that will help to protect access to PHI at the enterprise level. The three Ps of I&AM for regulatory complianceImplementing an IAM solution to ensure regulatory compliance involves the whole CE, and goes beyond simple technology considerations. Indeed, the implementation phase of the product itself is usually quite fast, thanks to automated deployment tools. What consumes time in a project are the organizational and human aspects, as well as the inventory of applications, data stores and workflows that concern Protected Health Information.
Evidian IAM solutions can help Covered Entities implement the requirements of the Security Rule in a cost-effective and coherent manner:
|
NHS trusts...
See the NHS resource center for specific information on how Enterprise SSO and IAM can improve security while reducing costs.
Unfamiliar terms?
|
||||||||