Intelligent Control for Healthcare Organizations
 |
The
healthcare industry is facing unique challenges when it comes to LAN
security. With patient privacy being a high priority, the Health
Insurance Portability and Accountability Act of 1996 (HIPAA) places a
number of requirements on access controls and in the handling of
patient information, with a direct impact on the operation of the LAN
and resources and applications connected to it. |
Healthcare
organizations must evaluate solutions that will provide them with
complete intelligent control of users and applications. The chosen
product should be simple to use, manage, and deploy. In addition to a
product that is scalable and cost-effective, hospitals, clinics, and
other healthcare organizations should focus on a holistic solution.
Key features of Intelligent Control of users and applications
- complete Network Admission Control (NAC) - user
authentication, role derivation, and host posture assessment to ensure
only valid users and devices enter the LAN
- improved application performance - Layer 7
identification, prioritization, and treatment of applications to
protect assets and put business needs first
- complete user control - identity- and role-based policies to control access to applications and other resources
- faster troubleshooting - username, device, application, and resource tied together to accelerate incident response
- simplified compliance and audit trail - full documentation of
all policies, as well as all LAN activities, tied to username and
resource to speed audits
Key projects ConSentry can help address
- Enable guest/patient Internet access without compromising other hospital LAN resources
- Ensure medical equipment maintenance contractors can access only the appropriate machines and not the entire LAN
- Control network access granted to IP-aware medical devices without requiring a client
- Protect access to patient health records for compliance with HIPAA
- Enable
role-based provisioning, so medical staff can share PCs but gain access
only to the corporate data appropriate to their role
- Leverage and extend the life of existing
network infrastructure (i.e., no switch upgrade to 802.1X) for Network
Admission Control (NAC)
- Ensure only compliant devices get on the LAN, with host posture check
|