IT Service Desk Supervisor
First Choice Health
First Choice Health is a managed care services provider that distributes their array of healthcare products and services to over one million people in the United States. An innovative alternative to traditional healthcare, the First Choice network helps to reduce costs whilst maintaining quality and convenience.
As an American healthcare services provider First Choice Health has a duty of care to ensure that the sensitive electronic health records (EHR) of their customers are secured in compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
To meet HIPAA compliance, covered entities need to address key vulnerabilities such as the security risks associated with portable storage devices including USB flash drives, mobile devices, and portable hard drives.
Unrestricted access to USB ports facilitates the unauthorized copying of data to removable media and the use of portable storage devices which could be infected with malicious software.
For the healthcare industry as a whole, insider threats pose a significant risk; Verizon’s 2018 Protected Health Information Data Breach Report (PHIDBR) found that 58% of data breaches in the healthcare industry involved insiders.
To protect against this prominent threat First Choice Health knew that they needed endpoint data loss prevention software with USB control features.
As a technical safeguard AccessPatrol provides several key protections against portable storage devices:
In addition to meeting their USB security requirements, AccessPatrol provides First Choice Health with an easy-to-use interface where they can effortlessly adjust their removable media policies on an as-needed basis. This flexibility was essential for keeping data safe without interrupting the efficiency of patient care.
“The user-friendly interface meant we were able to get the software up-and-running extremely quickly. It worked perfectly and provided all of the functionality we were looking for while also helping us comply with HIPAA.”
When implementing AccessPatrol, First Choice Health blocked access to all portable storage devices that were not specifically on their Allow List.
This combined with AccessPatrol’s USB activity reports gave them the ability to closely monitor and control how sensitive EHRs were stored and transferred by their employees. Daily USB activity reports were automatically provided to designated staff members so they could audit the logs for suspicious activity.
With AccessPatrol’s granular USB control policies it was simple to provide exceptions to those that needed it, such as providing photographers from their HR team with read-only access when their cameras were plugged into their computers.
“With AccessPatrol, we’re certain we’re meeting today’s cybersecurity standards whilst maintaining immediate, reliant access to patient records so we can keep delivering a high-quality service to our clients.”