Douglas County Hospital is a system of healthcare providers that includes Heartland Orthopedic Specialists, Alexandria Clinic and Osakis Clinic. This 127-bed, non-profit regional hospital and clinics located in Alexandria, MN includes 875 staff and 72 physicians and advanced practice professionals providing integrated health care services to the patients, families and communities they serve.
The hospital is heavily focused on customer care, and because of this, saw a need to keep the organization’s patient data as safe as possible. Its leadership understood that compliance is only a small part of risk management and that it needed to expand its thinking beyond the ordinary security measures. Heating and cooling systems, outside foliage and camera placements were just a few potential vulnerabilities the hospital was looking to measure vulnerabilities on.
So, Douglas County Hospital looked to SecurityStudio®.
SecurityStudio® was vital in helping the hospital mature its information security program. It provided an intensive independent review of the hospital’s security practices. To do so, it used the FISASCORE® assessment, a security rating system that measures internal, external, administrative and physical security controls. This assessment was the crucial first step in improving the hospital’s security program, as it indicated strengths, weaknesses and threats that could help determine where the focuses for improvement should lie.
“Our information security program and policies should be based on an independent and unbiased standard. This assessment is helpful as it gives us a foundation on which to mature our program, develop new policies and rework current practices,” Director of Information Security, Joyce Beck said.
“We wanted to understand our security position and its effectiveness. After the assessment we learned that strengthening logical segmentation protocols via restrictive VLAN would protect our overall network from unauthorized access in a more effective way. Systems such as heating, cooling and camera control were given limited access and could only communicate on their assigned VLAN networks,” IT Lead Ryan Engelbrecht added.
The implementation of the additional protocols through the assessment added an additional layer of security to the hospital’s overall security. On top of this, it shifted their focus from reactionary thinking to a proactive mindset with a systematic handling of their known vulnerabilities, and it guided the hospital on recommended lifecycles for its hardware and software.
“Asset management was one of the tools we utilized but not to its fullest potential. Improved documentation was implemented and additional methods for auditing and ensuring the necessary follow through were added. The assessment gave us an approach that was modest and a directive to keep it simple, by starting at square one and building this plan from the ground up. This made the process of managing our hardware less overwhelming and cumbersome,” Engelbrecht said.
The FISASCORE® security assessment not only pinpointed vulnerabilities for immediate improvement but also provided a roadmap for enhancing the overall security posture of Douglas County Hospital. Overall, this open, collaborative and mentoring approach is what made the difference to improving the hospital’s security position now and into the future.