mcafee solutions for healthcare - ingram micro brief mcafee solutions for healthcare 4. protecting...

4
Security is an Important Part of Your Health Information Systems Electronic health information systems (HIS) promise to reduce operational expenses, increase productivity, and improve care quality. Security must be considered when implementing an HIS. Providers need be sure that their security matches their new electronic environment. It is no longer enough to install anti-virus and assume that health information and systems will remain secure. Increasing Risks (and Penalties) for Healthcare Organizations In February 2009, the Health Information Technology for Economic and Clinical Health (HITECH) Act increased penalties for North American healthcare providers guilty of data breach. It provided for: Stronger powers of enforcement by state Attorneys General Increased monetary penalties for breaches Mandatory disclosure requirements for data breaches Required compliance audit within 12 months McAfee Solutions for Healthcare Noninvasive protection for patient care In the rapidly changing healthcare industry, doctors and other staff want greater flexibility to use new technology in the workplace. But increased flexibility also means increased risks, including data loss, vulnerability to malware, and violation of the HIPAA Privacy Rule. McAfee healthcare solutions address this need, enabling you to protect access to sensitive data, meet regulatory requirements such as HIPAA and PCI, and achieve the efficiencies necessary for success in a highly competitive industry. Balancing flexibility and data protection has been a particularly difficult goal for the healthcare. On the one hand, the penalties for data breaches are increasing dramatically, while FDA regulations restrict changes to medical devices. On the other hand, doctors and other healthcare providers are eager for faster access to information, which helps them provide better care to patients. To achieve the promised benefits without increasing risk, McAfee recommends that healthcare organizations deploy an optimized security architecture. McAfee’s optimized security architecture provides protection against emerging threats while enabling healthcare providers to utilize the latest technologies. McAfee provides this protection while reducing the security footprint (or overhead), not only facilitating the free flow of secure information, but also reducing IT resources required to implement and maintain secure access. With McAfee, healthcare organizations reduce the cost of security and minimize their risks, and doctors gain efficiencies and improve their ability to deliver excellent care. Test Results Referrals @ Billing Diagnosis ? ? Centralized Management Securing protected health information at rest Securing protected health information in motion Protecting critical infrastructure Securing medical devices Managing risk and vulnerability Industry Brief

Upload: tranliem

Post on 11-Mar-2018

213 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: McAfee Solutions for Healthcare - Ingram Micro Brief McAfee Solutions for Healthcare 4. Protecting Critical Infrastructure Risk: Disruption to clinical services and billing can occur

Security is an Important Part of Your Health Information Systems

Electronic health information systems (HIS) promise to reduce operational expenses, increase productivity, and improve care quality. Security must be considered when implementing an HIS. Providers need be sure that their security matches their new electronic environment. It is no longer enough to install anti-virus and assume that health information and systems will remain secure.

Increasing Risks (and Penalties) for Healthcare OrganizationsIn February 2009, the Health Information Technology for Economic and Clinical Health (HITECH) Act increased penalties for North American healthcare providers guilty of data breach. It provided for:•Stronger powers of enforcement by

state Attorneys General• Increased monetary penalties

for breaches•Mandatory disclosure requirements

for data breaches•Required compliance audit within 12 months

McAfee Solutions for HealthcareNoninvasive protection for patient care

Intherapidlychanginghealthcareindustry,doctorsandotherstaffwantgreaterflexibilitytousenewtechnologyintheworkplace.Butincreasedflexibilityalsomeansincreasedrisks,includingdataloss,vulnerabilitytomalware,andviolationoftheHIPAAPrivacyRule.McAfeehealthcaresolutionsaddressthisneed,enablingyoutoprotectaccesstosensitivedata,meetregulatoryrequirementssuchasHIPAAandPCI,andachievetheefficienciesnecessaryforsuccessinahighlycompetitiveindustry.

Balancingflexibilityanddataprotectionhasbeenaparticularlydifficultgoalforthehealthcare.Ontheonehand,thepenaltiesfordatabreachesareincreasingdramatically,whileFDAregulationsrestrictchangestomedicaldevices.Ontheotherhand,doctorsandotherhealthcareprovidersareeagerforfasteraccesstoinformation,whichhelpsthemprovidebettercaretopatients.Toachievethepromisedbenefitswithoutincreasingrisk,McAfeerecommendsthathealthcareorganizationsdeployanoptimizedsecurityarchitecture.

McAfee’soptimizedsecurityarchitectureprovidesprotectionagainstemergingthreatswhileenablinghealthcareproviderstoutilizethelatesttechnologies.McAfeeprovidesthisprotectionwhilereducingthesecurityfootprint(oroverhead),notonlyfacilitatingthefreeflowofsecureinformation,butalsoreducingITresourcesrequiredtoimplementandmaintainsecureaccess.WithMcAfee,healthcareorganizationsreducethecostofsecurityandminimizetheirrisks,anddoctorsgainefficienciesandimprovetheirabilitytodeliverexcellentcare.

Test Results

Referrals

@

Billing

Diagnosis

?

?

Centralized Management

Securing protectedhealth information

at rest

Securing protectedhealth information

in motion

Protecting criticalinfrastructure

Securing medicaldevices

Managing risk and vulnerability

Industry Brief

Page 2: McAfee Solutions for Healthcare - Ingram Micro Brief McAfee Solutions for Healthcare 4. Protecting Critical Infrastructure Risk: Disruption to clinical services and billing can occur

Industry Brief McAfee Solutions for Healthcare

McAfeesolutionsforhealthcareprovidersshareacentralizedsecuritymanagementplatformtoreducethemaintenanceburdenforsecurityandregulatorycompliance.Thecentralizedsecuritymanagementplatformenablesdatasecurity,networksecurity,policymanagement,monitoring,auditing,andthereportingrequiredforPCIandHIPAAcompliance.

1. Securing Protected Health Information at Rest Risk: Theuseoflaptopsandmobiledevicesincreasestheriskthatprotectedhealthinformation(PHI)willbeaccessedbyunauthorizedindividuals.AlostorstolendevicewithunencrypteddataconstitutesabreachifthedeviceissecuredwithonlysimplepasswordprotectionandcontainsanyunsecuredPHI.

McAfee solution: Protectsdeviceswitheasy-to-manage,low-footprintencryptionthatmeetsHIPAA/HITECHencryptionlevels,minimizingthepossibilityofdatalossandthesubsequentneedtosendbreachnotifications.

• Full-disk encryption—Securespatientdataonlaptopsandcomputers•Mobile device encryption—Encryptsdata(includingclassifiedmail)onmobilephones• File/folder encryption—Automaticallyencryptsfilescopiedfromaserver•Removable media encryption—AutomaticallyencryptsdatacopiedtoUSBdrives•Virtual disk encryption—Supportsvirtualenvironments•Device control—LimitswhichUSBdevicescanbeattachedtoacomputer

2. Securing Protected Health Information in Motion Risk:Transmissionofprotectedhealthinformationacrossanetworkthroughunprotectedemailorotherelectronicfiletransfersincreasesriskofdatabreach.

McAfee solution: Transparentlyencryptsdatatransmissionandmonitorspatientinformationtopreventinadvertentormalicioustransmissionviaemail,instantmessenger,printing,web,etc.,whetherbystafformalware.

•Network data-loss prevention—Transparentlyanalyzesthenetworktopreventloss•Host data-loss prevention—BlocksPHIdatafrombeingsentbyacomputer•Encryption of emails—EnsuresPHIinformationisalwaysencryptedintransit•McAfee eBusiness Server—Encryptsandcompressesinformationbetweenservers

3. Securing Medical DevicesRisk: Malwarecandisruptnotonlycomputersbutotherhealthcaredevices.Becauseoftheiroperatingsystems,MRImachines,heartratemonitors,andtabletcomputersarealsosusceptibletomalwarethatspreadsacrossanetwork.

McAfee solution: ProtectsmedicaldevicessuchasmedicaltabletPCsandotherthinclientdevicesalongwithMRI-CADscanners.Preventsattackswithlow-footprintintegritycheckingandisincorporatedintomoreandmorevendors’premarketapprovedbuilds

•Application whitelisting—Preventsinstallationofunwantedprograms•Change control—Managessoftwareinstallationandupgradesandpreventsunapprovedchanges• “Gold master” comparison—Checksthatdeviceshavenotbeenmodified•Vulnerability scanning—Identifiessystemsatriskandcorrelatesthreatstorisks

Test Results

Referrals

@

Diagnosis

Page 3: McAfee Solutions for Healthcare - Ingram Micro Brief McAfee Solutions for Healthcare 4. Protecting Critical Infrastructure Risk: Disruption to clinical services and billing can occur

Industry Brief McAfee Solutions for Healthcare

4. Protecting Critical InfrastructureRisk: DisruptiontoclinicalservicesandbillingcanoccurifpoorprotectionallowsexternalattackstodisruptcriticalinfrastructureorcompromisePHI.Damagetoreputationcanalsooccur.

McAfee solution: Utilizesreal-timeglobalthreatintelligencetostayaheadofchangingthreats,helpingyouavertsystemdowntimeandunauthorizedaccessofPHI.

•Anti-virus and anti-spyware—Includesmalwaredetectionandremoval•Host intrusion prevention—Includesvulnerabilityprotectionandapplicationblocking•Application whitelisting—Allowsonlyapprovedapplicationstorunonaprotecteddevice•Change control—Managessoftwareinstallationandupgradesandpreventsunapprovedchanges• Firewall—Providesdefensefromnetwork-basedattacks•Network IPS—Providesnetwork-basedmalwareprotection•Email and web security—Protectsagainstspamandmalwareaswellasoutbounddataloss•Vulnerability scanning—Identifiessystemsatriskandcorrelatesthreatstorisks

5. Risk and Vulnerability ManagementRisk:Thisdifficultyoftrackingvulnerabledevicesandthelocationofprotectedhealthinformationincreasesthepotentialofadatabreachandpossibilityofwillfulinfringementpenalties.

McAfee solution: Providesdatadiscoveryandvulnerabilitymanagementtoidentify,prioritize,andmitigatetherisksassociatedwithexternalandinternalthreatsanddatatheft.

•Data discovery—ScansaccessibledevicesforsensitiveinformationsuchasPHI•Vulnerability scanning—Identifiessystemsatriskandcorrelatesthreatstorisks•McAfee Policy Auditor—AutomatesprocessesforinternalandexternalITaudits•McAfee Remediation Manager—Automatesremediationofpolicynoncompliance•McAfee Risk Advisor—Proactivelycorrelatesthreats,vulnerabilities,andcountermeasures•Vulnerability and risk assessment services—Providesexpertisetohelpyouassessyourrisks

Optimized Security Architecture—The Value We Offer Organizations Like YoursNooneisbetterpositionedthanMcAfeetorelentlesslytacklethreatsfromeveryangleandhelpyousafeguardyourpatients,users,networks,andbillingsystems.McAfeesolutions,technologies,andaward-winningglobalresearchteamcoverthefullspectrum—theendpoint,thenetwork,thegateway,theInternet,andallpointsinbetween.

McAfee enables you to move from reactive to optimized—and in the process, reduce risk and cost.

Multilayered security connects processes and intelligence across systems and networks.McAfee’sintegratedapproachaccomplishesmorethananysingleelementalone,enablingITtofulfillbusinessrequirementsmoreefficientlywhilerespondingtothreatsswiftlyandeffectively.

Billing

?

?

Page 4: McAfee Solutions for Healthcare - Ingram Micro Brief McAfee Solutions for Healthcare 4. Protecting Critical Infrastructure Risk: Disruption to clinical services and billing can occur

McAfee and/or other noted McAfee related products contained herein are registered trademarks or trademarks of McAfee, Inc., and/or its affiliates in the U.S. and/or other countries. McAfee Red in connection with security is distinctive of McAfee brand products. Any other non-McAfee related products, registered and/or unregistered trademarks contained herein is only by reference and are the sole property of their respective owners. © 2009 McAfee, Inc. All rights reserved. 7192brf_sol-healthcare_1009_ETMG

McAfee, Inc. 3965 Freedom Circle Santa Clara, CA 95054 888 847 8766 www.mcafee.com

Compliance is integrated into your security process. WithMcAfee,complianceandtheabilitytoprovecompliancearebuiltrightintoyoureverydaysecurityprocesses,sothatreportingandauditingissimplyanoutputoftheworkyourITteamalreadydoes.

McAfee Global Threat Intelligence offers a predictive approach to new threats. Abetterunderstandingofthethreathorizoniscriticaltomovingfromreactivetoproactive.

McAfee’s centralized platform manages your entire security portfolio. Toefficientlymanageallsecurityprocesses,theITorganizationneedsvisibilityacrosssystemsandnetworks,regardlessofwherethosesystemsandnetworksarelocated.

Throughourbroadsolutions,centralizedmanagement,integratedcompliance,andGlobalThreatIntelligence,McAfeeenablesyoutomoreeffectivelyprotectyourpatients,staff,systems,anddata.

About McAfeeMcAfee,Inc.,headquarteredinSantaClara,California,istheworld’slargestdedicatedsecuritytechnologycompany.McAfeeisrelentlesslycommittedtotacklingtheworld’stoughestsecuritychallenges.Thecompanydeliversproactiveandprovensolutionsandservicesthathelpsecuresystemsandnetworksaroundtheworld,allowinguserstosafelyconnecttotheInternet,browseandshopthewebmoresecurely.Backedbyanaward-winningresearchteam,McAfeecreatesinnovativeproductsthatempowerhomeusers,businesses,thepublicsectorandserviceprovidersbyenablingthemtoprovecompliancewithregulations,protectdata,preventdisruptions,identifyvulnerabilities,andcontinuouslymonitorandimprovetheirsecurity.http://www.mcafee.com.

Industry Brief McAfee Solutions for Healthcare