HIPAA Tip: Zero Trust Architecture
Remember when your mom said “don’t talk to strangers”? This goes way beyond that.
Zero Trust Architecture is a security framework based on “never trust, always verify.” Not like the old days when users and devices inside the network were considered safe. Zero Trust assumes no implicit trust based on network location, focusing on protecting individual resources rather than network segments.
Some of the best practices for Zero Trust implementation include:
- Identifying critical assets: systems and applications containing ePHI and sensitive data.
- Map data flows: understand how patient data moves through the network in your organization (between EMRs, billing and third-party systems).
- Micro-segmentation: divide networks into small zones to maintain separate access for separate parts of the network.
Examples of Zero Trust Solutions:
- Multi-Factor Authentication (MFA): utilizing multiple layers of authentication for users adds more layers of security.
- Endpoint Detection and Response (EDR): a cybersecurity solution that continuously monitors end-user devices in real-time to detect, investigate and mitigate advanced threats.
- Identity and Access Management (IAM): technology tools for verifying user identity (either human or machine) and allowing only the appropriate access to resources at the right time.
NIST Special Publication 800-207 explains the components of a Zero Trust Architecture (ZTA), threats associated with the ZTA and steps that can be taken to further secure an organization’s environment.
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.