Organizations receiving healthcare data as part of the New York State Health Home program must create a System Security Plan (SSP) that proves they are properly protecting Medicaid Confidential Data (MCD).
BestSelf’s Health Home program has over 2,400 patients, and they need to protect the data of each. NYS DOH requirements include receiving a third-party risk assessment and a subsequent comprehensive security audit.
To meet the new compliance regulations and keep up with the evolving threat landscape, BestSelf needed to take a proactive approach and find a way to implement these controls efficiently.
To satisfy NYS compliance requirements, including the National Institute of Standards and Technology (NIST) framework, the team knew comprehensive vulnerability management and 24x7 security operations center (SOC) capabilities were necessities.
Approach
The first step was to assess what data they receive from the State and where that data was stored in order to establish their information system boundary. With an understanding of the boundary, and knowledge of how they operate internally and share data, BestSelf was able to develop an effective security approach.
They chose to advance its overall organization-wide security posture rather than only focusing on the narrower scope of the NYS DOH requirements.
“We considered our entire organization, rather than just securing our Health Home data." Kevin Wiese CIO at BestSelf said. "We decided to deploy these controls organization-wide because it felt wise and prudent to do so. It was to our benefit to accelerate planned enhancements to our security program.”
Next, they determined whether they could manage these processes internally through their 15-person IT team or if outsourcing to a third-party SOC would be more feasible. Their team has a wide breadth of experience, but it was clear that they couldn’t support 24x7 security operations without outside help.
BestSelf put together a checklist of services they’d require of a third-party vendor and began the search for a security partner to augment their internal capabilities.