

Healthcare institutions are required to secure Protected Health Information (PHI) in both electronic and paper form. With providers automating record systems to improve patient care, this information exists on a diverse set of computer systems, with unique access, control and data transmission requirements. Sensitive information must also be shared securely with a variety of cooperating providers, payers and clearinghouses. To protect patient privacy, prevent ID theft, maintain reputation and avoid audits due to inadvertent disclosures and patient complaints, HIPAA-covered entities must discover system vulnerabilities, mitigate risks and demonstrate compliance.
Assurity River offers a comprehensive set of security services to help healthcare institutions achieve HIPAA compliance, target security spending where it is most effective and address PHI security needs on a continuing basis:
HIPAA Compliance Gap Analysis – We offer a rapid gap analysis to assess your current security program, identify risks and compare your existing environment and practices to HIPAA requirements. This gap analysis will focus your security improvement efforts on areas with significant compliance issues and will help you prioritize efforts to cost-effectively improve PHI compliance and security.
Risk Analysis – Assurity River provides comprehensive security analysis services to identify risks in all of the security areas covered by HIPAA, including IT security, physical security and business continuity. We can perform an all-inclusive analysis or focus on specific areas that warrant attention based on your gap analysis or specific concerns. Our risk analysis services leverage a certified security team and leading analysis tools to quickly identify security risks, recommend resolution and provide management or board-level visibility of risks and recommended improvement steps.
Security Improvement – We offer project management and implementation services for the projects you need to undertake to improve information security. We provide services for application security review, access control standards, policy improvement, business continuity plan development, and incident response, as well as customized projects based on your needs.
Security Leadership – Assurity River can also provide the leadership you need for your security management and improvement efforts. A skilled security professional on our staff will work with all areas of your organization to identify compliance and security gaps, and to perform a comprehensive analysis of human, technical and physical risks to PHI security. We will form and lead an effective security management team, and we will provide project management for your organization’s security improvement projects.
Business Continuity Planning – Healthcare organizations need to have a business continuity plan that provides timely recovery of services after emergencies that may result from a wide range of human, technical, and natural threats. Our business continuity planning service will lead your efforts to develop or improve the plans that recover both IT operations and the entire business.
Managed Security Services – Assurity River provides a full suite of managed security services to assist you in addressing complex, escalating security threats without the need to continually expand your IT staff and extend your coverage hours. The 24x7x365 services of our security experts will let you concentrate on healthcare IT systems while we manage your security systems.