THREE COLOCATION MYTHS HEALTHCARE PROVIDERS SHOULD LEAVE BEHIND. Exploring Security, Compliance, and Performance in Healthcare IT

Similar documents
How Managed Service Providers Can Meet Market Growth with Maximum Uptime

ENABLING SECURE CLOUD CONNECTIVITY. Create a Successful Cloud Strategy with Reliable Connectivity Solutions

CONSIDERATIONS BEFORE MOVING TO THE CLOUD

The Windstream Enterprise Advantage for Healthcare

You Might Know Us As. Copyright 2016 TierPoint, LLC. All rights reserved.

Cloud for Government: A Transformative Digital Tool to Better Serve Communities

IT your way - Hybrid IT FAQs

UPS system failure. Cyber crime (DDoS ) Accidential/human error. Water, heat or CRAC failure. W eather related. Generator failure

Cloud-Based Data Security

Cloud Communications for Healthcare

10 Cloud Myths Demystified

EXECUTIVE REPORT. 4 Critical Steps Financial Firms Must Take for IT Uptime, Security, and Connectivity

presents Embracing the Cloud with Confidence COLOCATION

locuz.com SOC Services

IaaS Buyer s Checklist.

Choosing the Right Cloud. ebook

Cloud & Managed Server Hosting for Healthcare Professionals

INTO THE CLOUD WHAT YOU NEED TO KNOW ABOUT ADOPTION AND ENSURING COMPLIANCE

Peer Collaboration The Next Best Practice for Third Party Risk Management

Data center interconnect for the enterprise hybrid cloud

Healthcare IT Modernization and the Adoption of Hybrid Cloud

DeMystifying Data Breaches and Information Security Compliance

HITRUST ON THE CLOUD. Navigating Healthcare Compliance

6 Tips to Find the Right Colocation Center for You

Watson Developer Cloud Security Overview

Trend Report. Network Security: What IT Decision Makers Really Think

Physical Rack Level Security: Restricting and Monitoring Access at the Rack. Mike Fahy Business Development Manager, EAS Southco, Inc.

YOUR CONDUIT TO THE CLOUD

PONEMON INSTITUTE RESEARCH REPORT 2018 STUDY ON GLOBAL MEGATRENDS IN CYBERSECURITY

Ensuring business continuity with comprehensive and cost-effective disaster recovery service.

Fact sheet FRANKFURT DATA CENTRE CAMPUS. Connect, transact and grow

POWERING NETWORK RESILIENCY WITH UPS LIFECYCLE MANAGEMENT

Cloud Computing: Making the Right Choice for Your Organization

ISACA GEEK WEEK SECURITY MANAGEMENT TO ENTERPRISE RISK MANAGEMENT USING THE ISO FRAMEWORK AUGUST 19, 2015

10 Cloud Myths Demystified

Best Practices in Securing a Multicloud World

Integrated Cloud Environment Security White Paper

WITH ACTIVEWATCH EXPERT BACKED, DETECTION AND THREAT RESPONSE BENEFITS HOW THREAT MANAGER WORKS SOLUTION OVERVIEW:

Why Enterprises Need to Optimize Their Data Centers

Village Software. Security Assessment Report

IBM Security Services Overview

Global Headquarters: 5 Speen Street Framingham, MA USA P F

HIPAA Compliance is not a Cybersecurity Strategy

Moving Workloads to the Public Cloud? Don t Forget About Security.

Data Center Checklist

SIEMLESS THREAT MANAGEMENT

Protecting vital data with NIST Framework

2018 HIPAA One All Rights Reserved. Beyond HIPAA Compliance to Certification

The Cost of Denial-of-Services Attacks

Fundamental Shift: A LOOK INSIDE THE RISING ROLE OF IT IN PHYSICAL ACCESS CONTROL

The communications, media, and entertainment industry and the cloud.

Cybersecurity The Evolving Landscape

Security and Privacy Governance Program Guidelines

Shaping the Cloud for the Healthcare Industry

THE IMPACT OF SECURITY ON APPLICATION DEVELOPMENT. August prevoty.com. August 2015

Protecting Your Cloud

IBM Global Technology Services Provide around-the-clock expertise and protect against Internet threats.

A Checklist for Compliance in the Cloud 1. A Checklist for Compliance in the Cloud

Enabling the Always-On Enterprise

Service. Sentry Cyber Security Gain protection against sophisticated and persistent security threats through our layered cyber defense solution

AMS6, Amstel Business Park Campus. Highly connected, Energy efficient data centre. Duivendrechtse kade 80A 1096 AH Amsterdam Netherlands

Healthcare in the Public Cloud DIY vs. Managed Services

As Enterprise Mobility Usage Escalates, So Does Security Risk

Enabling Hybrid Cloud Transformation

Introduction to AWS GoldBase

HITRUST CSF Assurance Program HITRUST, Frisco, TX. All Rights Reserved.

Case Study. Medical Information Records, LLC. Medical Software Company Relies on Azure to Improve Scalability, Cut Costs & Ensure Compliance

CONTINUOUS COMPLIANCE. Your next cloud compliance audit could be your last. With LayerV s Continuous Compliance Service you re covered

Understanding As-a-service: Teradata IntelliCloud

Top Priority for Hybrid IT

EXPRESSROUTE STRATEGY & CONNECTIVITY WORKSHOP

CLOUD COMPUTING WHAT HEALTH CARE INTERNAL AUDITORS NEED TO KNOW GABRIELA MERINO DIRECTOR BUSINESS ADVISORY SERVICES

AUTOTASK ENDPOINT BACKUP (AEB) SECURITY ARCHITECTURE GUIDE

Custom hybrid IT solutions that meet your security, price, and performance needs. Trusted advisors since 1996.

Business Continuity & Disaster Recovery

CYBER SECURITY WORKSHOP NOVEMBER 2, Anurag Sharma [CISA, CISSP, CRISC] Principal Cyber & Information Security Services

Data Center E-Book

Whitepaper. 10 Reasons to Move to the Cloud

Managed Services Rely on us to manage your business services

Locking Down the Cloud Security is Not a Myth

TRUE SECURITY-AS-A-SERVICE

WHITE PAPER. Solutions OnDemand Hosting Overview

HITRUST Common Security Framework - Are you prepared?

Introduction. Deployment Models. IBM Watson on the IBM Cloud Security Overview

2016 Survey: A Pulse on Mobility in Healthcare

to Enhance Your Cyber Security Needs

DATA CENTER COLOCATION BUILD VS. BUY

White Paper Server. Five Reasons for Choosing SUSE Manager

HITRUST CSF: One Framework

BYTEGRIDR. 6 Considerations for Selecting the Right Colocation Provider. Copyright ByteGrid All Rights Reserved.

COLOCATION 1/4 RACK RACK COLD AISLE CONTAINEMENT PRIVATE CAGE PRIVATE SUITE FLEXIBLE PRICING OPTIONS

Data Sheet The PCI DSS

Modern Database Architectures Demand Modern Data Security Measures

10 Considerations for a Cloud Procurement. March 2017

The Need For A New IT Security Architecture: Global Study On The Risk Of Outdated Technologies

A High-Performing Cloud Begins with a Strong Foundation. A solution guide for IBM Cloud bare metal servers

TREND REPORT. Ethernet, MPLS and SD-WAN: What Decision Makers Really Think

Checklist for Applying ISO 27000, PCI DSS v2 & NIST to Address HIPAA & HITECH Mandates. Ali Pabrai, MSEE, CISSP (ISSAP, ISSMP)

WHITE PAPER HYBRID CLOUD: FLEXIBLE, SCALABLE, AND COST-EFFICIENT UK: US: HK:

Written Statement of. Timothy J. Scott Chief Security Officer The Dow Chemical Company

Transcription:

THREE COLOCATION MYTHS HEALTHCARE PROVIDERS SHOULD LEAVE BEHIND Exploring Security, Compliance, and Performance in Healthcare IT

According to a recent Spiceworks survey of IT professionals working in the healthcare field, the average healthcare organization stores well over 1 PB of data and it s a complex mix of structured and unstructured data. Respondents say 46% of their healthcare data is stored off premises, whether at a physical location the organization owns or manages, a physical location owned by a third party (colocation), a hosted/cloud location, or a hybrid cloud. And over the next three years, that number is set to increase, with respondents expecting that more than half (52%) of their healthcare data will be stored off premises. Despite this growing use of off-premises data storage, many myths about colocation persist, particularly for healthcare IT. Have you heard any of these before? Colocation is not secure enough for healthcare IT. Colocation won t meet the compliance requirements we have in healthcare. Colocation wouldn t provide the performance we need. Drawing on the knowledge and experiences of IT pros currently working in the healthcare sector, this white paper explores and explodes these three common myths associated with using colocation in healthcare IT. 52%: Expected use of off-premises data storage by 2020 2

MYTH #1: Colocation is not secure enough for healthcare IT. When healthcare IT pros are evaluating data storage solutions and services, security is obviously a key concern. According to the Spiceworks survey, nearly a third (31%) are looking for solutions that will improve the security posture of the organization. Today s IT pros are concerned about all the usual suspects hacking, malware (especially ransomware), DDoS attacks, and other potential causes of data breach, downtime, or both. IT pros are also concerned about the potential of losing control of security by moving data off premises. 3

What keeps me up at night? Security and data breaches. Healthcare IT pro Security is always a big concern when moving your data off-premises, but 34% of survey respondents actually reported security and compliance issues with their on-premises data storage solutions. Colocation solutions can improve your security posture by providing more security expertise and sophisticated controls than what many IT organizations have in-house. 34%: Percentage of healthcare IT pros facing security/compliance issues with on-premises storage IT Pro Tips Look for a colocation facility that provides: Industry-leading systems security Physical security controls, such as: video surveillance perimeter fencing double mantrap entries access controlled by biometric scanners and card readers locking cages cabinets with multiple access control options 24x7 in-house security presence comprised of highly trained personnel 4

MYTH #2: Colocation won t meet the compliance requirements we have in healthcare. Nearly one-third (31%) of surveyed healthcare IT pros are rightly concerned with compliance when evaluating data storage solutions and services, including colocation solutions. They re concerned that the solutions will not provide the level of compliance support required by the specific government, industry, and organizational regulations they must adhere to. 5

However, once again, 34% of healthcare IT pros report that security and compliance are actually a challenge with their existing on premises data storage solution. Colocation providers can help alleviate these situations, as many providers specialize in meeting specific regulatory and industry compliance standards, including HIPAA and HITECH. The right colocation provider can effectively reduce the compliance burden for the IT organization as well as facilitate any required audit activities. My biggest concerns are issues related to HIPAA. Healthcare IT pro IT Pro Tips Look for a colocation provider with compliance certification for: SOC 1 Type 2 and SOC 2 Type 2: Standards issued by the American Institute of Certified Public Accountants (AICPA), which address corporate controls for service providers, including security and environmental compliance PCI DSS: The comprehensive set of security controls and processes created by the PCI Security Standards Council for merchants and service providers that store, process, or transmit customer payment card data ISO/IEC 27001:2013: One of the most stringent certifications for information security controls HIPAA and HITECH: Control guidance based on the requirements of the HIPAA Security Rule and the Health Information Technology for Economic and Clinical Health Act 6

MYTH #3: Colocation wouldn t provide the performance we need. Due to the critical nature of the data they deal with, performance is a top priority for healthcare IT pros. The lion s share of surveyed IT pros 91% say that performance and latency are either critical or very important when it comes to mission-critical internal workloads. For just over a quarter (26%) of respondents, performance and reliability are the top factors when evaluating data solutions, beating out security and compliance. 7

I lose sleep over maintaining performance levels for all users. Healthcare IT pro IT pros have particular concerns around performance and uptime when it comes to colocation. But the bigger problem is that outdated on premises technology is holding many healthcare organizations back. Nearly 70% of surveyed healthcare IT pros report that availability and bandwidth issues are a top pain point with their existing on premises storage solutions. Almost half (46%) report technical challenges of other kinds. Nearly 70%: Percentage of healthcare IT pros citing availability/bandwidth issues with on-premises storage Unfortunately, capital costs and space constraints make onsite infrastructure upgrades unrealistic for many healthcare organizations. Colocation providers can offer a high-performance alternative, with 100% uptime SLAs to ensure data is available at all times, and access to network and cloud providers to help build out a holistic hybrid IT solution. In addition, by saving money on space and power, organizations can funnel more funds toward new equipment for other workloads. IT Pro Tips Look for a colocation provider that can deliver: Standard uptime SLAs Interconnections to major network providers Interconnections to major cloud providers 8

COLOCATION WITH CORESITE CoreSite s colocation offerings help IT pros in healthcare bust these myths by solving their existing security, compliance, and performance challenges. CoreSite colocation solutions provide: High levels of systems and facility security, including multiple layers of physical security and 24x7x365 coverage by trained security guards Compliance certifications for SOC 1 Type 2 and SOC 2 Type 2, PCI DSS, ISO 27001, and HIPAA for all CoreSite data centers, with compliance examinations conducted by Schellman & Company, Inc., an independent, licensed CPA firm, Qualified Security Assessor, and accredited ISO 27001 certification body High reliability backed by a 100% uptime SLA, as well as high bandwidth and low latency. CoreSite provides access to hundreds of network and cloud providers, and provides direct connectivity to leading cloud providers such as AWS, Microsoft Azure, Google, and IBM Bluemix CoreSite operates 20+ data centers in major communication markets across the US. Colocation with CoreSite offers economies of scale on space and power, resulting in lower total cost of ownership than in-house data center systems. You can draw additional benefit from secure, direct connections to network, cloud, and IT service providers that inhabit the same environment. With flexible scalability as well as built-in security and reliability, CoreSite enables infrastructure upgrades that produce a system focused on high performance. CoreSite provides data center solutions to meet even the most stringent of healthcare requirements. 9

CONCLUSION For many healthcare organizations, colocation is a data storage option well worth investigating. And the value of colocation only increases as data volumes grow a situation that can otherwise strain existing on premises data center infrastructure, bogging down performance, exhausting security resources, and hindering compliance efforts. CoreSite s colocation offerings are flexible enough to meet the needs of a wide range of organizations, yet robust enough to meet even the most stringent requirements a healthcare organization can face. LEARN MORE BY VISITING CORESITE ABOUT THE SURVEY CoreSite commissioned Spiceworks to conduct a survey in May 2017. This survey targeted IT decision-makers, including IT directors, IT managers, and other IT staff who work in the healthcare industry, to understand current perceptions and practices around data storage. Survey results included responses from approximately 150 participants in the US who work at healthcare companies with 100 or more employees, including hospitals, healthcare systems, ambulatory companies, extended care facilities, and other healthcare organizations. 10