下载PDF
NAVEX > 实例探究 > Major Health Information Network Connects To Better Information Security
NAVEX Logo

Major Health Information Network Connects To Better Information Security

技术
  • 应用基础设施与中间件 - 数据交换与集成
适用行业
  • 医疗保健和医院
适用功能
  • 商业运营
用例
  • 监管合规监控
  • 远程资产管理
服务
  • 系统集成
挑战
The nation’s largest health information network faced significant challenges in managing information security, particularly due to the sensitive nature of the data it processed. The company had to comply with a range of regulations and industry standards, including HIPAA, EHNAC, SOX, PCI DSS, and ISO. The complexity of these compliance requirements was compounded by the company’s lack of visibility into current and pressing risks, making it difficult to provide data or metrics to inform management decisions. Additionally, the company’s Information Security department struggled to secure funding, as it was viewed as a cost center and had difficulty justifying budget requests without clear insight into IT and information security risks.
关于客户
The customer is the nation’s largest health information network. It processes a significant amount of data, often involving personally identifiable information (PII). The company has to comply with a range of regulations and industry standards, including the Health Information Portability and Accountability Act (HIPAA), Electronic Healthcare Network Accreditation Commission (EHNAC), Sarbanes-Oxley (SOX), Payment Card Industry Data Security Standards (PCI DSS), and the International Organization for Standards (ISO). The company's Information Security department was viewed as a cost center and had difficulty securing funding and justifying budget requests without clear insight into IT and information security risks.
解决方案
The health information network selected NAVEX’s governance, risk management, compliance (GRC) platform, NAVEX IRM, for its capabilities in integrated risk management (IRM). NAVEX IRM enabled the company to gain a comprehensive view of their business and operations from a risk perspective, connecting individual risk disciplines and managing them in one centralized program. The company utilized NAVEX IRM’s centralized compliance library, which houses all compliance activities, regulations, industry standards, and best practice frameworks. The company’s controls were also linked in the central location, enabling one control to satisfy compliance with multiple requirements. NAVEX IRM provided access to risk data and metrics that were easy to share with management in reports and dashboards. This data informed Information Security’s operations, allowing them to review a list of risks for a proposed project and then prioritize funding for remediation efforts.
运营影响
  • Compliance that was complex and time-consuming became easier and more productive.
  • Visibility into risk management that was non-existent before came into view and is now measurable and reportable.
  • NAVEX IRM increased collaboration efforts and streamlined communications, which were significant pain points when information was shared using e-mails and spreadsheets.

相关案例.

联系我们

欢迎与我们交流!

* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 IoT ONE 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 IoT ONE 的任何营销电子邮件。
提交

Thank you for your message!
We will contact you soon.