NET ACCESS HIPAA COMPLIANT FLEXCloud



Similar documents
MANAGED EXCHANGE SOLUTIONS Secure, Scalable and Compliant Hosted Environments

NET ACCESS VOICE PRIVATE CLOUD

Leveraging Dedicated Servers and Dedicated Private Cloud for HIPAA Security and Compliance

H.I.P.A.A. Compliance Made Easy Products and Services

Barracuda Backup for Managed Services Providers Barracuda makes it easy and profitable. White Paper

Enterprise Architecture Review Checklist

Product Overview and Functional Specification

FUJITSU Backup as a Service Rapid Recovery Appliance

5 Essential Benefits of Hybrid Cloud Backup

itg CloudBase is a suite of fully managed Hybrid & Private Cloud Services ready to support your business onwards and upwards into the future.

The Production Cloud

CHIS, Inc. Privacy General Guidelines

custom hosting for how you do business

A Guide to. Cloud Services for production workloads

ABOUT NODE4. node4.co.uk

ICAB5238B Build a highly secure firewall

Solutions for Health Insurance Portability and Accountability Act (HIPAA) Compliance

Security Administration R77

StoneFly SCVM TM for ESXi

Implementing Multi-Tenanted Storage for Service Providers with Cloudian HyperStore. The Challenge SOLUTION GUIDE

nwstor Storage Security Solution 1. Executive Summary 2. Need for Data Security 3. Solution: nwstor isav Storage Security Appliances 4.

Cloud Assurance: Ensuring Security and Compliance for your IT Environment

Appendix C to DIR Contract Number DIR-TSO-2736 SunGard Availability Services Discount Level: 25% Managed Data Center Services - Cloud Hosting

The School IT Challenge. Introducing Systemax Stack As A Service. Top 12 School IT Challenges

Configuring and Deploying a Private Cloud

Achieving PCI-Compliance through Cyberoam

Check Point taps the power of virtualization to simplify security for private clouds

VMware VDR and Cloud Storage: A Winning Backup/DR Combination

Vyatta Network OS for Network Virtualization

Hosted SharePoint: Questions every provider should answer

EARTHLINK BUSINESS. Simplify the Complex

Backup Exec Private Cloud Services. Planning and Deployment Guide

Enterprise Cloud Solutions

Appendix E to DIR Contract Number DIR-TSO-2736 CLOUD SERVICES CONTENT (ENTERPRISE CLOUD & PRIVATE CLOUD)

NETWORK ACCESS CONTROL AND CLOUD SECURITY. Tran Song Dat Phuc SeoulTech 2015

Solution Overview. Business Continuity with ReadyNAS

Overview of Cloud Computing and Cloud Computing s Use in Government Justin Heyman CGCIO, Information Technology Specialist, Township of Franklin

Healthcare Security and HIPAA Compliance with A10

Unified Security Anywhere HIPAA COMPLIANCE ACHIEVING HIPAA COMPLIANCE WITH MASERGY PROFESSIONAL SERVICES

Requirements Checklist for Choosing a Cloud Backup and Recovery Service Provider

Computing: Public, Private, and Hybrid. You ve heard a lot lately about Cloud Computing even that there are different kinds of Clouds.

Securing Virtualization with Check Point and Consolidation with Virtualized Security

Effective End-to-End Cloud Security

Secure Cloud Computing Concepts Supporting Big Data in Healthcare. Ryan D. Pehrson Director, Solutions & Architecture Integrated Data Storage, LLC

Information Technology Solutions. Managed IT Services

CA ARCserve Replication and High Availability Deployment Options for Hyper-V

Protezione dei dati. Luca Bin. EMEA Sales Engineer Version 6.1 July 2015

ICANWK406A Install, configure and test network security

Clinical Trials in the Cloud: A New Paradigm?

VMware vcloud Air Security TECHNICAL WHITE PAPER

UNIFIED THREAT MANAGEMENT SOLUTIONS AND NEXT-GENERATION FIREWALLS ADMINISTRATION TOOLS NETWORK SECURITY I ENDPOINT SECURITY I DATA SECURITY

Keyfort Cloud Services (KCS)

Hyper-V Network Virtualization Gateways - Fundamental Building Blocks of the Private Cloud

Effective Storage Management for Cloud Computing

Microsoft Azure. White Paper Security, Privacy, and Compliance in

Lecture 02a Cloud Computing I

Radware ADC-VX Solution. The Agility of Virtual; The Predictability of Physical

Product Factsheet MANAGED SECURITY SERVICES - FIREWALLS - FACT SHEET

המרכז ללימודי חוץ המכללה האקדמית ספיר. ד.נ חוף אשקלון טל' פקס בשיתוף עם מכללת הנגב ע"ש ספיר

VMware vcloud Networking and Security Overview

Simplify Your Network Security with All-In-One Unified Threat Management

How To Protect Your Cloud From Attack

How To Create A Large Enterprise Cloud Storage System From A Large Server (Cisco Mds 9000) Family 2 (Cio) 2 (Mds) 2) (Cisa) 2-Year-Old (Cica) 2.5

Logicalis Enterprise Cloud Frequently Asked Questions

Infrastructure as a Service (IaaS) Dancik International and Peak 10

Enabling Storage Services in Virtualized Cloud Environments

GoodData Corporation Security White Paper

BlueArc unified network storage systems 7th TF-Storage Meeting. Scale Bigger, Store Smarter, Accelerate Everything

Backup, Recovery & Archiving. Choosing a data protection strategy that best suits your IT requirements and business needs.

Comprehensive Agentless Cloud Backup and Recovery Software for the Enterprise

Configuring and Deploying a Private Cloud 20247C; 5 days

security in the cloud White Paper Series

KEMP LoadMaster. Enabling Hybrid Cloud Solutions in Microsoft Azure

SMS. Cloud Computing. Systems Management Specialists. Grupo SMS option 3 for sales

Contents UNIFIED COMPUTING DATA SHEET. Virtual Data Centre Support.

OmniCube. SimpliVity OmniCube and Multi Federation ROBO Reference Architecture. White Paper. Authors: Bob Gropman

PCI Requirements Coverage Summary Table

Clavister InSight TM. Protecting Values

City of Coral Gables

"Charting the Course... Implementing Citrix NetScaler 11 for App and Desktop Solutions CNS-207 Course Summary

John Essner, CISO Office of Information Technology State of New Jersey

SOLUTION BRIEF Citrix Cloud Solutions Citrix Cloud Solution for Disaster Recovery

Transcription:

Page 0 2015 SOLUTION BRIEF NET ACCESS HIPAA COMPLIANT FLEXCloud A Managed Infrastructure Solution that Meets the Regulatory Demands of the Health Care Industry NET ACCESS LLC 9 Wing Drive Cedar Knolls, NJ 07927 www.nac.net

Page 1 Table of Contents 1. Introduction... 2 2. Net Access Managed Services Solution Process Flow... 3 3. FLEX Services Solution Components... 4 4. Use Case & Solution Overview... 5 5. Solution Diagram... 6 6. HIPPA Regulations and Safeguards... 7

Page 2 1. Introduction For 20-plus years, Net Access has been passionate about finding smarter, better ways to solve our clients technology challenges. Leveraging our portfolio of enterprise data center services - including cloud, colocation, networking and managed services - we re able to craft a multi- technology thinking infrastructure that s flexible enough to change on-the-fly to optimize speed, efficiency and reliability. These managed solutions takes full advantage of our next-generation data centers, our knowledgeable and tenured staff and our 24/7/365 Network Operations Center. We believe that this attention to detail and dedication is why businesses that rely on their critical IT infrastructure also rely on Net Access. Federal regulations regarding the protection of patient health information are growing in number and in scope. As these regulations have increased in complexity, health industry entities have had to allocate more time and financial resources to securing their IT infrastructure and data, at the expense of their primary business of providing quality health services. Often times this involves hiring expensive IT experts to design, implement, and migrate existing infrastructure and data, as well as adding ongoing maintenance and management costs of these systems. Unfortunately, creating and maintaining an entirely new support staff to ensure regulatory compliance simply isn t ideal for most companies. To assist health industry customers in tackling this problem, Net Access has tailored its FLEXCloud solution into a HIPAA-compliant offering. Net Access s data centers and cloud infrastructure have both been audited by third-party CPAs to ascertain that both specifically meet HIPAA regulatory requirements. This catered solution takes into account all HIPAA provisions, including Security Rule specifications for administrative, physical, and technical safeguarding of Protected Health Information (PHI). A comprehensive Breach Rule policy has also been developed by Net Access, as well as standardized Business Associate Agreements (BAAs) for customer convenience. When combined, all elements of Net Access HIPAA compliant FLEXCloud provide for a simplified, cost-efficient solution to the ever growing regulatory demands of the health care industry. All of our managed infrastructure solutions use an OPEX price model. This converts capital expenditure cost into a manageable monthly fee, providing easier budgeting due to a consistent spend. Without high upfront costs for additional hardware or additional staff, customers can enact upgrades and expansions quickly and easily. By reducing CAPEX for infrastructure, our clients can reinvest into what matters most: the core business.

Page 3 2. Net Access Managed Services Solution Process Flow Consultation and Design Net Access Engineers will meet with the customer in a collaborative session to define the requirements and review the proposed solution. A dedicated engineer provides consultation and planning to ensure that the deployment of the solution meets the client s deadlines, expectations, and functionality. Net Access strives to ensure all customers are provided a service that is the right fit for them. Some environments are small and static and some environments are large and need to scale. Net Access engineers can design a solution based on a number of needs. Implementation Net Access will perform a cooperative test and turn up of the design, working with the customer to verify all components meet their requirements, expectations, and security concerns. A dedicated Managed Services Engineer is available during this process to make any necessary adjustments and ensure that the client is satisfied. Net Access will also work with third party integrators or vendors that will be involved in the deployment of the solution to simplify the process. Ongoing Management and Support Managed services are fully maintained by Net Access and monitored by our Network Operation Center 24/7/365. Ongoing support of hardware and software in the proposed solution is provided by Net Access and our technical staff. All of our solutions include proactive updates, hardware replacement, configuration assistance, and security auditing.

Page 4 3. FLEX Services Solution Components The following FLEX Services are utilized in the solutions outlined in this document: FLEXSecurity Managed Firewall Dedicated next generation firewall with options for Remote Access, Site-to-Site VPN, and High Availability. Security features can include full UTM (unified threat management) - deep packet inspection intrusion detection, and advanced screening and filtering for URL, Web, Email, SPAM, and viruses. Available as a virtualized or hardware appliance. FLEXServer Rapidly deployed, securely hosted dedicated servers that can be connected to the Internet, other Net Access FLEX services or a client s existing network infrastructure to create a true hybrid solution. Net Access provides maintenance of the physical hardware, the supply of power, the network connectivity and provisions any purchased upgrades of the hardware. FLEXVirtualDC Our virtualized enterprise data center offering. Available as a dedicated or multi-tenant solution, FLEXVirtualDC allows clients to deploy, adjust and expand Virtual Machines (VM) on-demand using committed pool of compute, memory, storage and bandwidth resources via a self-service web portal. FLEXBackup Shared, dedicated or combined cloud backup and recovery solution that is securely hosted in a Net Access data center. FLEXBackup can be deployed as a complement to existing on-site office infrastructure, existing infrastructure within a Net Access data center or combined with any of our other FLEXServices. Advanced options include AES-256 encryption, deduplication, and numerous replication, restoration and recovery options. FLEXLoadBalancer - Virtual or hardware appliance solutions designed to evenly distribute web traffic over multiple servers. Features GSLB enabling multi-site failover, location based application balancing, and even IPv6 to IPv4 conversion. FLEXStorage Managed SAN and NAS storage infrastructures that can be either shared, dedicated or mixed, and support both file and block protocols natively including NFS, CIFS, SFTP and iscsi.

Page 5 4. Use Case & Solution Overview CUSTOMER PROFILE: A leading developer of a custom mobile application for doctor and patient collaboration on the impacts of newly introduced drugs. The application allows for the logging of prescription medication intake and tracks its impact, including side effects, over time. CUSTOMER REQUIREMENTS: Virtual server development and production environments Highly available and secure web services infrastructure Secure daily backups Secure communications between office(s) and virtual environment HIPAA compliance NET ACCESS PROPOSED SOLUTION COMPONENTS: Net Access recommended a HIPAA compliant FLEXCloud solution, which included the following FLEX services: FLEXServer FLEXVirtualDC FLEXLoadBalancer FLEXSecurity Firewall FLEXBackup FLEXStorage The proposal also included management by Net Access of all networking devices, storage units, and backups to improve compliance consistency by means of a single IT support staff. SOLUTION HIGHLIGHTS: FLEXVirtualDC provides a simplified web interface front-end to the virtual cloud environment, fallowing for rapid provisioning of FLEXServer and FLEXStorage hardware resources. The virtual cloud environment allows for the segregation of multiple networks and VM groups, creating independent development and production environments, with the former being accessible only over encrypted VPNs from remote office(s), and the latter accessible by the public Internet. The virtual environment is highly available, configured across multiple FLEXServers and backed by resilient FLEXStorage SAN components. The production environment web services will be highly available and secure, incorporating FLEXLoadBalancer features to evenly distribute load across virtual machines, and FLEXSecurity Firewall to restrict access with granular rulesets. FLEXSecurity Firewall, offered with high availability options, will also act as a highly available encrypted VPN tunnel termination point. FLEXBackup will be configured with daily scheduled incremental backup jobs, backed up postencryption at Net Access remote data center to provide recovery means. Communications between the virtual environment and remote client office(s) will be secured via encrypted VPN connections, and encrypted backups are to be stored at a remote data center on a daily basis.

Page 6 5. Solution Diagram

Page 7 6. HIPPA Regulations and Safeguards All proposed FLEXCloud components account for HIPAA regulations regarding the safeguarding of patient data (table below), or Protected Health Information (PHI). The solution aims to simplify and isolate management domains by providing a single management interface to the client, leaving remaining management responsibilities to Net Access IT support staff. With this isolation, Net Access can more efficiently adhere to key elements of HIPAA regulations as they pertain to provided solutions. Safeguard Administrative HIPAA Safeguards Scope Clearly define HIPAA compliant services for which administrative security, training, and contingency efforts must be addressed or implemented Clearly define HIPAA compliant services for which business associate agreements (BAAs) must be made between Net Access and clients Physical Clearly define HIPAA compliant services for which management and maintenance of facility access and contingency efforts must be addressed or implemented Clearly define Net Access IT support staff management access requirements and policies Technical Clearly define HIPAA compliant services for which Net Access IT support staff management access control efforts must be addressed or implemented Clearly define HIPAA compliant services for which logging and audit efforts must be addressed or implemented Clearly define HIPAA compliant services for which authentication mechanism efforts are addressed or implemented Clearly define HIPAA compliant services for which secure transmissions of data efforts are addressed or implemented A Net Access BAA template is to be made available to client to be used with or without modification. Client modifications are subject to Net Access Sales and management review.