Video: HIPAA Compliance for Healthcare IT | Duration: 1600s | Summary: HIPAA Compliance for Healthcare IT | Chapters: Welcome and Introduction (0s), HIPAA Security Updates (401.781s), Network Visualization Tools (625.7710599999999s), Concluding HIPAA Compliance (1270.7910000000002s)
Transcript for "HIPAA Compliance for Healthcare IT":
Welcome, everyone. Thank you for joining us today. I'm Kristine from IP Fabric, and I'm here with my colleague, Zach Brown, one of our solution architects, to walk you through how network assurance plays a critical role in HIPAA compliance. Zach, please introduce yourself for our audience today. Good afternoon, everyone. Oh, nice to meet you. My name is Zach Brown, and I am a solutions architect with IP Fabric. I'm based out of Charlotte, North Carolina. I'd like to thank you all for attending, and I really appreciate your time this afternoon. And, hopefully, after the, webinar here, you'll have some value to take back with you about compliance. Sure thing. And just to point out, there are some docs and there is a q and a, so feel free to make use of those resources. They should be available for you, and feel free to leave us any questions as we go. So I'm gonna set a little bit of context, and then we will be demoing how IP Fabric actually helps you deliver the evidence you need for HIPAA compliance. But let's start with a kind of vision of what we're working with. Right? So in 2025, digital health care is the norm. From telehealth to virtual nursing or real time imaging needs, care is now seamlessly connected. Right? And AI is becoming more embedded in our clinical workflows, diagnostics, and patient interactions, all aiming to boost satisfaction and improve health outcomes. But of course, like any digital evolution, this does bring risk. Every digital touch point is a potential vulnerability. And while it might be seen as your background utility, the IT network is actually the backbone of this modern health care. It's what's behind those shiny apps in your doctor's iPad. Right? So disruptions here, as Zach knows all too well, can delay procedures, overload staff, and, of course, expose sensitive highly valuable electronic personal health information. So these systems must be secured to protect the data they carry. Personal health data must trust traverse networks to be usable. Right? And that makes the network a very important attack surface for your business. So to kick off and get you guys all involved in this webinar, we want to start with a poll. And first, we are going to ask you. You should see the poll pop up in the poll tab. What is your biggest challenge when it comes to, HIPAA technical safeguards? What are you struggling with? What do you want answered? We'd love to know so we can share those results and and know how to help you best as well. Alright. So I do want to just underpin also how critical the criticality of these networks that IT staff are managing in health care. The network becomes a mission critical system when it comes to remote device monitoring, incentive things, quick access to health records, access to patient data, all these things I've listed here. And this demands continuous connectivity. And IT teams need to balance this performance and availability with security. But it's rarely, rarely simple. Health care networks are notoriously complex. We're talking about multi vendor environments, a mix of cloud and on prem networks, legacy platforms that you can't just easily replace, and an explosion of third party tools and bring your own device policies that make everything all the more complex to handle. And security and performance, we need them to coexist in this balanced way. So with health care teams trying to play this balancing act to live a care quickly and protect the infrastructure that makes digitally delivered health care possible, it's not an easy task when resources are limited and visibility is fragmented. Actually, 41% of health care IT professionals believe that their organizations allocate insufficient financial resources to make their cyber security strategy effective. This is from the proof point survey. We'd love to know if you agree. Feel free to leave it in the chat. And it's in this kind of environment that network misconfigurations, segmentation gaps, and unpatched systems become scary ticking time bombs, which brings us to the topic at hand, compliance. So compliance not just as a checkbox exercise to pass the next audit, although you definitely need to do that, but as a framework for securing the critical infrastructure that underpins your business all the time. Because if health care systems go down, this impact will ripple across society. And in The US, HIPAA is the cornerstone of that protection. Right? It doesn't exist in a vacuum. It intersects with internal policy. It intersects with NIST two and other security frameworks that you might be using and the evolving needs of electronic health personal information exchange. And at the heart of all these regulations, it's the same message. There are systems that handle sensitive patient data. And today, we'll focus on HIPAA in that network context and how you can bring net your network into compliance proactively with everyday audits, not just when you're scrambling to meet the audit deadline. Alright. So what's changed about HIPAA in 2025? Why why now? Right? Because in that once again, a mid twenty twenty five report on the state of cybersecurity in health care from fortified health care security said that in 2024, 92% of health care organizations reported cyber attacks and nearly 70% for patient care impacted by these. I I wouldn't wanna be a victim of that, breach, certainly not. So what did we do in response? Right? So in January 2025, there was an announcement by the US Department of Health and Human Services that proposes updates and a modernization to the HIPAA security rule. I personally think this is much needed since the last big overhaul was in 2013, and we certainly know technology and the landscape has changed since then. The proposal of the the notice of proposed rulemaking as it's called, so this is not quite in HIPAA yet, but this is just a proposal, marks a significant modernization in terms of documentation, testing, and oversight across the health care sector. And we are likely to see this finalized and actually put into practice in HIPAA end of this year, probably beginning of next year maybe, and there'll be around a twenty four month implementation period. So if you're starting now, you have probably a year and a half to get your act together when it comes to these new rules. But considering we know how bureaucracy works, it doesn't mean that the threats aren't there. Right? It's like, protect yourself now even though you have a year and a half to do it. And we certainly we we discussed the complexity of these environments. It's not gonna be a quick exercise. So I have picked out here just three, significant changes or updates, a sample from a proposed strengthened security rule that was, you know, very much in response to new breaches that we're seeing and new, health care outages that we're seeing. Like, for example, the change health care attack, last year in 2024 impacted nearly a hundred and nineteen million Americans. Their data was left unprotected when attackers gained access to the network using compromised credentials for server. So it's a very, you know, real issue. So these updates focus squarely on infrastructure security itself And they include things like I've mentioned the following on the slide. Maintaining accurate asset inventories, creating and maintaining network maps to show how electronic personal information flows through the network, implementing authentication controls based on system sensitivity, encryption of the sensitive data at rest and in transit, and there's a spotlight on segmentation and even macro segmentation if you're there. But segmentation as a way to separate your more sensitive and non sensitive systems. And the message is clear. Infrastructure and visibility and control are not optional. These are based on expectations And we should definitely note that tier four penalties for HIPAA, which include willful neglect, so just ignoring that these rules are going to change, can be in the millions of dollars per violation per year. So definitely not something to be ignored if you're concerned about the balance sheet. And we are going to show you based on those three examples that I mentioned, and there's plenty more in the HIPAA fact sheet which you can access online. But based on those just three examples that are relevant super relevant to the IT network, we're gonna show you how network assurance can deliver the evidence you need to prove that your security posture is as you need it to be. So as Zach, prepared to demonstrate some of this for us, let's ask our audience one more poll question. So poll number two, let's see if we have it up. So okay. Yeah. How confident are you today into your current visibility into systems that handle electronic personal health information? And don't worry. We won't disclose if you are not sure or not confident and you know that visibility gaps are a convert. We will not share that. Before we move on to the demo, let's share the results of the first poll. Okay. So 40% for keeping up with evolving requirements. Yes. They are changing over time. We've got a couple of votes for proving compliance consistently and then coordinating across teams and tools. Yes. Having that one language that you're speaking to security and network teams through is very, very challenging. I agree. Alright. So I'm going to stop sharing and let Zach take over for our demo. Alright, everyone. You should be able to see my screen here as I jump into the demonstration. But as Kristine mentioned earlier, at IP Fabric, we really specialize in inventory and asset management. So as I start this demonstration, I just wanted to show you after IP Fabric's discovery process is completed, here is where we'll have your full network device inventory. So aligning with those HIPAA compliance, keeping it as accurate, accountancy of all of your assets. Now once I have my assets discovered, what's some of the residuals with IP Fabric? What's some of those benefits that we get that align to our HIPAA needs? And as Kristine brought out, it's those network maps or network diagrams. And here at IP Fabric, IP Fabric, once that discovery process is run, we have, your device configurations and how they're connected. IP Fabric can create these dynamic diagrams. So as I just show you these diagrams, I have some cloud infrastructure as well as some different sites here. And as I zoom in, you may notice some interconnections with different routing protocols there. And as I scroll down, IP Fabric even gives me a look into my layer two. Now just to show you some of the value of these diagrams in IP Fabric and how they can help you achieve HIPAA compliance, They are fully dynamic and filterable. So just as an example, if I wanted to take a more in-depth look at one of my VLANs, let's say VLAN three thirty three and how I'm set up from a spanning tree perspective, I turn on my filter here and click submit. Now within IP Fabric, as I zoom in, I'm able to see which switches my root, root bridge as well as the states of the ports, which ones are in a blocking and forwarding state, as well as which way my traffic is allowed to flow. So, Zach, what I'm seeing here sorry. If I can ask one question. What I'm seeing here is that this is not merely just taking the box of providing evidence to your security team that they need for HIPAA compliance, but it's actually providing the user a really deep understanding of the holistic state of the network so they can rectify anything that's not in compliance very quickly too. Right? Absolutely. And we're bringing all that together here in IP Fabric just to show you how we get a little more holistic look of our network. If I right click on this firewall here, click explore, just as one quick example, I'm able to see the exact device I'm using as well as what the software version. So really able to match up my, attack vectors and any weaknesses in my infrastructure here. Now also on top of our diagrams and the value that our diagram screen, we also have a path lookup feature that corresponds right to our diagrams. So with our, path lookup feature, we are able to monitor end to end how traffic flows in our network. So if you take a peek at the screen here, I am simulating some traffic across one of my sites over an MPLS link to a remote site in Prague. The IP fabric can help you verify, each step along the path. So as I click my first device here and click explore, I'm able to see exactly how my packet is moving from source to destination in the Packet Logic decision table in the middle. Now as I scroll here and click explore on my firewall as a part of this path, I'm able to get even more robust information. So once this packet gets to the firewall, I'm able to see my NAT, my route, as well as my access control policy that may or may not be blocking my traffic. So really great for verifying your paths, making sure you understand what your assets can talk to and where they lie in the infrastructure. Now with our path lookup feature, IP fabric really helps customers secure their data in transit. Now what do I mean by that? Well, if you take a peek here at this traffic flow, this is an on prem environment. And I have a firewall here in red, which is illuminating something that's blocking my traffic, my access control policy. But if I take a look at this similar path lookup here, and I am simulating traffic from one host across another site, this time into AWS infrastructure. Now if you notice here, this firewall is in green. And as I right click on it and click explore, I'm able to verify my encrypted paths. So protocols like VXLAN, MPLS, or in this instance, IPSec. I'm able to see exactly when my IPsec tunnel starts to terminate as well as the IP addressing used for the tunnel, as well as verifying I'm using secure protocols. So I'm not opening myself up to additional attack vectors. Also, when I can fabric yes. Alright. If I wanted to share that information very quickly with my colleagues, what are some different ways that I could share that info? Absolutely. So all of this information, is fully exportable. So for an example, I can export my configuration straight to a JSON file. And once I have it, here downloaded in JSON, I can easily share that with my colleagues or into, API or my automation strategy for securing and automating my compliance and making my audit. It's real easy when they come around. Amazing. I love that efficiency win, and that also addresses one of the poll questions we had earlier where people mentioned, you know, bridging that gap between teams, getting rid of some friction there would be helpful. Absolutely. Absolutely. We definitely try to bridge those gaps here at IP Fabric, and we also try to make this information very easy to have at your fingertips. So just as an example here, when it comes to your data in transit, we have full IPsec tunnel status. So we can troubleshoot if our tunnels might be down as an example, or, also, are we using those approved algorithms for communication to make sure that we're secure? So our intent checks in IP Fabric also help you achieve that HIPAA compliance as well. Sounds good. And with IP Fabric IP Fabric digital twin capabilities, it allows you to simulate traffic between any two endpoints. So this is really great for segmentation. What it allows you to do is assure or confirm that your traffic is segmented so you can have a consistent approach to managing your network as well as making sure there's no unwanted communication between VLANs, Sunnest, or VRFs. As an example of that, under technology tables, our technology tables display all the discovery information in nice tables, nice new tables that are easily digestible. But just as an example here, if I take one of my switches and look at how many VLANs total they have, if I click on one of these and I can confirm, I have five VLANs on this switch, which really is great for helping me visualize if I have any VLAN sprawl at a layer two, which sites these VLANs belong to. And if I start seeing them in other sites, gives me an opportunity to confirm my segmentation and assure I'm connected as I intended to be. Also, same for the layer three, we're able to look at each VRF. So if we have VRFs that we only expect to be communicating a device with certain devices, we're able to see that here in IP Fabric. With a few clicks, we're able to see exactly where all those devices lie, where they should be communicating, and even down to a serial number low a serial number level as well. Now one thing that's really nice about IP Fabric specifically when it comes to segmentation and bad bad verification is once again, if you take a look at our intent checks, and as I scroll down to the performance verifications, if I take a look at end to end path verifications, here is where I have the ability to say my paths that are of interest to me and confirm if they are flowing as I intended to. And if they're not, I can get a intention in red saying, hey. Something here in this path has changed, before, since the previous snapshot, it may require some investigation. So we're able to save the paths that are critical to us and see if our passing and failing as we intended. So we're skipping part that past that manic process of get trying to gather this data from all different teams and pulling out the pen and paper, mapping that all through. We're just running a snapshot every day or multiple multiple times a day on that sensitive part of our network that's underpinning the health care infrastructure that needs to be HIPAA compliant. We're delivered this data all this data you just spoke about, normalized, available, accessible daily. Exactly. Well said, Kristine. Thank you. And on our dashboards as well, we're able to see even some of our interface statuses as well, some of our hardware, and the black milestones as well. So we're able to get ahead of that hardware life cycle, really plan for those, additions as well down the road to make sure that we don't have any weak spots in our security as well. Sounds good. Alright. So as we wrap up the demo portion, I can tell you just briefly, we do, have results in, and it looks like no one in the second poll was fully confident that they knew, exactly, the full visibility of where they, electronic personal health data lives. We did get some somewhat confidence and, not confidence though. So I just wanted to share that as as we wrap up here, Zach. Something like IT Shop, we could certainly raise the levels on that, I imagine. Absolutely. And one thing I forgot to add, Kristine, as well and just wanted to share as well that IP fabric does allow for customization of the platform to align with your HIPAA needs. So as an example here, just show you briefly, I have a sample dashboard for this compliance, and I have my exact, notifications from my special publication there where I need to have my content checks to align with that compliance. So If someone could actually do it for me. Compliance as well. So I could create this new security rule. Exactly. And these widgets and tabs can be specific to your environment. So not just generic checks for as you understand your specific needs, with IP Fabric, we have a custom dashboard so that all of your team can have the clarity of being HIPAA compliant all from our, single source of truth user interface. Sounds good. So we do have a couple of questions in the q and a, Zach. I wonder if we could tackle them, just really briefly for our audience. And, guys, we do have plenty of places that you can go for more information. You can search certainly reach out to the team. You can, ask a question now. So we do still have a few minutes for questions, and we, have those docs available for you. You can also get a personalized demo. There is a button above, our heads here that you can ask. And if you want specific information now and you really wanna get in touch with the team, we do recommend, just, emailing us. You can email our colleague, matt at matt angelo. That email is in the chat now, and he will make sure that you get in touch with who you need to speak with. So, Zach, do you have some answers for the those those q and a questions? So it looks like the first question, how does IP Fabric help detect lateral movement paths that could expose PHI during a breach? Well, we touched on it a little bit in our demonstration book. With IP Fabric, you have the ability to run end to end app monitoring for every IP address and or endpoint in your network. So with that, you can test every device, every IP address to see what all they have access to so you can simulate where potential lateral movement could be damaging to you and then Mhmm. Fortify your network. Sounds good. I like that word, fortify, keeping it strong and secure. We have one more question. One more question here. What happens when the network snapshot shows drift or deviation? Do you alert into existing SIM or SOAR? That's a good question. And at IP Fabric, we do have the capability of taking our data and integrating it with a SIM like Splunk or a source system. So in the platform itself, we do have the ability to compare via snapshots, changes between configurations or points in time. And then once those changes have been validated, we can then push them over to a SIM for full, aggregation of what's going on in your network to really patch together, all of your systems so you can have a complete look at your network. Alright. Alright. Sounds good. Yeah. Alright, guys. Well, we can give you, another minute or so for q and a. If you do not, if you do have more questions, please leave them now. Otherwise, please reach out to our team. You're more than welcome. We also want to highlight that we have a compliance ebook, a compliance hub, and a specific HIPAA compliance solution brief available for you in the docs, that are linked in the doc section, and that has more in-depth information on everything we spoke about today, taking you through our exact security use cases so you can get more information. So I think that's us for today. I will share what some of those resources look like, and I will say thank you very much. And thank you all for your time and for attending. Bye bye.