DEFINITION:
Health Insurance Portability and Accountability Act (HIPAA) regulations require organizations to enforce security controls that promote the confidentiality, integrity and availability of all personal health information.
CHALLENGE:
HIPAA standards require organizations to use risk-based methods for protecting all health information. HIPAA specifies compliance guidelines for achieving a minimum security baseline in areas covering administrative and technical safeguards. HIPAA applies to any organization that processes, stores or manages personal health information electronically not just healthcare entities.
SOLUTION:
Qualys® is ideal for healthcare institutions, insurance companies, and other organizations looking to achieve and prove HIPAA compliance quickly and cost-effectively. Qualys' flagship solution, QualysGuard®, provides organizations and auditors with an automated, on demand system to assess and reduce network security risks for protecting electronic health information. QualysGuard allows users to create HIPAA-specific reports to measure and document ongoing security compliance efforts.
| Key HIPAA Guidelines | QualysGuard Capabilities |
|---|---|
| Evaluation: Perform periodic technical evaluations | QualysGuard provides automated network security audits that determine an organization's security posture on an ongoing basis. |
| Risk Analysis: Conduct accurate and thorough assessment of potential threats and vulnerabilities | QualysGuard delivers the industry's most accurate network security audits with the largest database of vulnerability checks. |
| Risk Management: Implement security measures to reduce risks and vulnerabilities | With QualysGuard, companies can prioritize remediation efforts and manage risk based on asset value and key compliance objectives. |
| Security Management Process: Implement policies and procedures to prevent, detect, and correct security violations | QualysGuard's remediation workflow feature includes a highly automated ticketing system for tracking, eliminating and verifying security vulnerabilities. A ticketing module is available for easy integration with existing ticketing systems. |
| Information System Review: Implement procedures to regularly review records of information system activity | QualysGuard gives organizations the ability to run scheduled security audits and receive fully secure audit reports that include trend analysis, risk exposure, and remediation status. |
