|
M & R’s security practice consists of a team of technology experts with vast experience
with all levels of security: analyzing, implementing, monitoring, compliance with
healthcare laws and regulations, and recommending training for our healthcare clients.
Our Security Assessment Service examines the administrative, technical and physical security
controls that a healthcare client uses to protect its computing environment. The
resulting report provides a solid basis for designing and implementing cost effective
information security controls.
Our healthcare team of experts analyzes and
recommends according to best practices and correlation with the laws.
STEP 1: Security Enterprise Risk Assessment
Our Information Security Risk Baseline Assessment provides the cornerstone of a healthcare client’s information security risk management program. The assessment will identify potential risks and vulnerabilities.
HIPAA Security standards have been designed to be "scalable." The standards are technology-independent in order to address the individual circumstances of healthcare entities, and to allow for inevitable changes in technology.
Our Security Assessment is broken down in three phases.
Phase 1: Systems Assessment
A complete assessment is conducted on the network, wireless environment, systems, applications, operating systems and manual operations.
Deliverables:
- Narrative analysis of proposed or existing network and wireless requirements
- Graphical layout of the proposed and/or existing network
- Summary of concerns and/or recommendations for the network configuration
- Summary of recommendations for application software and operation systems
- Summary of recommendations of improving manual operations (paper reduction, automate processes, scheduling, etc.)
- Summary of HIPAA compliance and/or issues
Phase 2
An assessment is conducted on the current security policies.
Deliverables:
- Summary of current information services security policies and procedures
- Summary of concerns and/or recommendations
Phase 3: Gap Analysis
A complete Security and HIPAA Gap Analysis is conducted.
Deliverables:
- Summary of current HIPAA status with recommendations towards compliance and addressable matters
- Assessment and summary of the current status of information security measures and clearly defining steps to a secure environment
- Review and summary of the current security policies, controls and procedures and identify the inefficiencies
- Summary of recommendations based on current best practices relative to your organization
STEP 2: Planning and Implementation
Phase 1: Planning
Firewall, VPN, Network
Our experts will configure security policies, firewall and network devices. We work with organizations to implement the best VPN practices.
Wireless Security
Our wireless security team works with organizations to bring out several possible solutions in maintaining and securing a wireless network using the latest technologies and protocols such as WAP, Bluetooth, and 802.11b.
AntiVirus
Our Security experts review and assess your virus protection practices—including network topology, architecture, environment and organizational structure—to determine anti-virus implications.
Our engineers help map virus alert reporting structure to your organizational needs, ensuring the right people receive virus alerts at the right time.
PKI/Encryption
Our Security experts can help implement an appropriate PKI solution for your environment. We help in defining policies, procedures and appropriate technologies including vendor products and encryption standards to be used.
Additionally, our Security experts can suggest appropriate encryption technologies and implement it in your environment. We help you define and design an appropriate encryption policy for your environment.
Our Security experts can provide you with training to your staff regarding the appropriate use of encryption and PKI and the related products as needed.
STEP 3: Managing and Monitoring Services
M & R offers various options of monitored and managed services and supports a wide range of devices, software and tools to meet the needs of any organization.
Firewalls and VPN
Intrusion Detection
Vulnerability Protection
AntiVirus
PKI/Encryption
URL Content Filtering
Security Patches and Updates
Attack and Penetration
Back
|