Find White Papers
Home
About Us
List Your Papers
    
> Blue Lane > The Challenge of Securing Hard to Patch Servers in Health Care Environments

The Challenge of Securing Hard to Patch Servers in Health Care Environments

White Paper Published By: Blue Lane

The healthcare industry has benefited from the breakneck pace of digitization - spanning everything from payments to patient records to X-ray film - but it has also been increasingly exposed to greater risk. Efforts to increase healthcare provider productivity via increased digitization and system interconnectivity have to be counterbalanced against the growing concerns for patient privacy and a backdrop of increasing liability.



Tags : 
healthcare, health care, patient privacy, privacy, patch management, patch, patch server, hipaa

Blue Lane
Published:  Oct 01, 2007
Type:  White Paper
Length:  8 pages

W H I T E PA P E R
The Challenge of Securing Hard to Patch Servers in Health Care EnvironmentsWhite Paper The Challenge of Securing Hard to Patch Servers in Health Care Environments
Overview
The healthcare industry has benefited from the breakneck pace of digitization -spanning everything from payments to patient records to X-ray film- but it has also been increasingly exposed to greater risk. Efforts to increase healthcare provider productivity via increased digitization and system interconnectivity have to be counterbalanced against the growing concerns for patient privacy and a backdrop of increasing liability.
In the wake of these concerns, a number of regulations have emerged for IT professionals in the healthcare industry to navigate. Beyond the standard set of IT security concerns that most IT departments must confront, many of the systems utilized in healthcare not only require special vulnerability management efforts but also fall under the auspices of the US Food and Drug Administration (FDA), An inline patch mimics the which complicates things further. Another pain point specific to the industry is the corrective action of the proliferation of embedded systems or medical devices that operate with their own security patch for network- unique set of security challenges.accessible vulnerabilities, no matter how complex, To manage these challenges, IT professionals in the healthcare industry turn to to address the vulnerability the typical array of security solutions used by their counterparts across other at the root cause. industries. Network intrusion prevention systems (IPS) are utilized to segment and defend the network. Patch management tools are used to quickly roll out security patches. Unfortunately, perimeter-oriented network IPS require ongoing operational resources, from constant tuning to the management of "noise" due to false alarms. Security patches may mitigate vulnerabilities but are resource intensive to install, require time to test and validate, and may introduce new risks and problems.
Blue Lane's patch protection gateway, PatchPointT, provides inline vulnerability remediation for server operating systems, databases, enterprise applications and medical devices, offering instant application protection with zero footprint, zero PatchPoint utilizes inline downtime, and zero tuning. PatchPoint utilizes inline patches that are functionally patches that are functionally equivalent to software security patches. An inline patch mimics the corrective action equivalent to software of the security patch for network-accessible vulnerabilities, no matter how complex, security patches. to address the vulnerability at the root cause.
Regulatory Compliance
Unlike other industries that may experience inconveniences or financial losses that stem from security events, healthcare organizations in the United States are directed by several federal initiatives that mandate the implementation of rigorous security and privacy controls. The most widely publicized initiative of recent years is the Health Insurance Portability and Accountability Act (HIPAA). If the healthcare organization also happens to be a public company then additional efforts must be devoted to IT security in order to achieve Sarbanes-Oxley (SOX) compliance. Additionally, the Food and Drug Administration and its policies also require the attention of IT professionals because usage (and security) of most medical devices falls under the guidance of the FDA. Below is a brief synopsis of each initiative and its impact on healthcare providers:
. HIPAA is perhaps the most widely recognized regulation that directly impacts healthcare providers. The standards are meant to improve the efficiency and effectiveness of the nation's health care system by encouraging the use of electronic
Blue Lane 2White Paper The Challenge of Securing Hard to Patch Servers in Health Care Environments
data interchange in the US health care system. There are two sets of standards stemming from HIPAA: Privacy standards that seek to protect patient data from improper disclosure or use and security standards that safeguard patient data from unauthorized access. The security portion is further subdivided into three safeguard standards: administrative, technical and physical. Among the key applicable HIPAA standards that pertain to the patching challenges mentioned ab... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search