SCENARIO: A local government agency responsible for administering Medicaid and other healthcare initiatives needed to ensure compliance with required federal security regulations.

This agency develops eligibility, service coverage, and payment policies for a major city’s healthcare financing programs and ensures that area healthcare programs take full advantage of federal funding for services for the indigent and uninsured. The agency also manages other healthcare services and analyzes existing healthcare financing policies to ensure that they are promoting efficient, effective, and economical care.

Wilson Consulting Group’s (WCG) task was to review, verify, and test the security controls (management, operational, and technical) of the Electronic Protected Health Information (EPHI) system and other related systems in this city. WCG also had to ensure compliance with the Health Insurance Portability and Accountability Act (HIPAA) Security Remediation/Compliance Program.

WCG’s Strategy: To help the agency achieve the required HIPAA security compliance posture, WCG conducted comprehensive system tests in accordance with federal and local health department security requirements. WCG tested and implemented security controls as documented in the HIPAA compliance standards to determine the extent to which the controls were being implemented correctly, operating as intended, and producing the desired outcome.

In short, we worked to ensure the system security requirements were achieved. To do this WCG employed a variety of information gathering and assessment methods (e.g., interviewing, inspecting, studying, vulnerability assessment and penetration testing).

In conducting vulnerability assessment tests WCG was careful not to affect system availability or alter configuration or data on the tested devices. Penetration tests were conducted through the public Internet. WCG provided the agency with the IP addresses from which the tests were to be conducted and gave sufficient advance notice. All tests were performed in compliance with departmental, federal and international guidelines and coordinated with the agency.

The tests and services performed included:

Based upon prescribed government guidance and industry best practices, WCG recommended alternative approaches to remedy identified deficiencies. Alternatives were presented with respect to projected suitability to the objective, effectiveness, efficiency, initial cost, long-term maintenance and support requirements.

The remediation process and final deliverables were guided by, but not limited to, the following:

WCG confirmed the:

WCG RESULTS: WCG successfully examined, evaluated, documented, and prepared security remediation/compliance tests, procedures, and approvals for complex multi-tiered records management applications within the agency’s environment. WCG provided deliverables on time, on budget, and to the HIPAA specifications, thus enabling the agency to achieve the required HIPAA security compliance posture.

WCG Results

WCG successfully examined, evaluated, documented, and prepared security remediation/compliance tests, procedures, and approvals for complex multi-tiered records management applications within the agency’s environment.

WCG provided deliverables on time, on budget, and to the HIPAA specifications, thus enabling the agency to achieve the required HIPAA security compliance posture.

Get Started Now
huniversity1

Other Track Record(s) You May be Interested In.

huniversity-ser

Howard University – School of Social Work: Case History

WCG developed a budget to support the system improvements and implementation...

huniversity-ser

Jamaican Government Security Solution

WCG exceeded all of the ministry’s requirements for improving the security of its IT system...

huniversity-ser

Power and Utilities Industry

WCG can help your company meet these security challenges and regulatory hurdles...

huniversity-ser

Local Government Medical Agency Case History

WCG provided deliverables on time, on budget, and to the HIPAA specifications, thus enabling...

huniversity-ser

The African Market Case History

WCG effectively assisted government agenciesand businesses in Sub-Saharan Africa to overcome...

huniversity-ser

Federal Agency Case History

WCG successfully prepared certification, procedures and approvals for the complex multi-tiered...

huniversity-ser

Financial Services Provider Case History

WCG helped the organization rectify all risks based on the findings of the vulnerability ...

huniversity-ser

Federal Agency Case History 2

WCG Reviewed, updated, and developed information security guidelines...

huniversity-ser

GDPR Case History

As GDPR was fast approaching, the company needed to see if their processes were aligned with regulations...

huniversity-ser

GLBA Case History

A private research university needed to create its GLBA program...

huniversity-ser

Cyber security Assessment Case History

Cyber-attacks damage an institution’s reputation, disrupt the operation of a business...