HIPAA Requirements for Complete Cloud Security

18
STORYBOARD S

Transcript of HIPAA Requirements for Complete Cloud Security

Page 1: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

Rich Campagna
suggest removing this slide - think we can talk through this in the next slide
Page 2: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

8%of healthcare orgs

had cloud apps deployed in 2014

37%of healthcare orgs

had cloud apps deployed in 2015

cloud adoption is rising fast

Bitglass Cloud Adoption Report

Page 3: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

the traditional approach to

security is inadequate

Page 4: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

native security features can’t be relied upon:the data blind spot

components

usage/consumption

data

application

services

servers & storage

network

layer

data

application

infrastructure

owner

enterprise

Page 5: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

security must evolve to

protect data outside the

firewall

cloud:attack on SaaS

vendor risks sensitive data

access:uncontrolled access from any device

network:data breach - exfiltration & Shadow IT

mobile:lost device with sensitive data

5

Page 6: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

HIPAA technical safeguards for cloud

■ access control

○ granular context-based controls over access to both managed and unmanaged devices

○ secure identity/authentication

■ transmission security

○ end-to-end encryption

■ audit and visibility

■ data integrity

Page 7: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

access controlsthe new data reality requires a new security architecture

■ cross-device, cross-platform agentless data protection

■ granular DLP for data at rest and in motion

■ contextual access control

Page 8: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

controlling access from unmanaged mobile devices

■ secure mobile devices without invasive profiles or certificates; support multiple affiliations

■ protect data in “unwrappable” native apps like mail, contacts, calendar

■ selectively wipe corporate data

■ enforce device security policies

■ full data control and visibility for IT

Page 9: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

identitycentralized identity management is key to securing data

■ cloud app identity management should maintain the best practices of on-prem identity

■ SSO enables cross-app visibility into suspicious access activity

■ contextual multi-factor authentication mitigates risk

Page 10: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

transmission securityend-to-end protection

■ cloud data doesn’t exist only “in the cloud”

■ a complete solution must provide visibility and control over data in the cloud

■ solution must also protect data on end-user devices

■ leverage contextual access controls

Page 11: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

audit and visibility

■ detailed logging for compliance and audit.

■ identify PHI data at rest and external sharing

■ easily modify sharing permissions and quarantine files for review

■ detect and be alerted instantly of suspicious behavior

Page 12: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

data integrity

■ secure the data in the cloud - where you

have versioning and control over

permissions

■ apply granular DLP to sensitive data with

spectrum of actions from watermarking to

encryption.

Page 13: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

CASB: a better approach to cloud security

identity

discovery

data-centric security

mobile

Page 14: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

secure office 365

+ byod

challenge

■ Inadequate native O365 security■ Controlled access from managed & unmanaged

devices■ Limit external sharing

■ Interoperable with existing infrastructure, e.g. Bluecoat, ADFS

solution

■ Real-time inline DLP on any device (Citadel)■ Contextual access control on managed &

unmanaged devices (Omni)■ API control in the cloud■ Discover data breach & Shadow IT

fortune 50 healthcare provider

Page 15: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

HIPAA compliant

mobility

challenge:

■ Existing solution, AT&T Toggle, was obsolete■ HIPAA-compliant BYOD■ Migration path to Office 365

solution:

■ Agentless deployment ■ Usability, transparency & privacy

■ DLP of PII, PCI & PHI

■ Selective wipe; device PIN & encryption

■ Improved mobility for care providers

majorUS hospital system

Page 16: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

our mission

total data

protectionest. jan 2013

100+ customers

tier 1 VCs

Page 18: HIPAA Requirements for Complete Cloud Security

STORYBOARDS

bitglass.com@bitglass