Regulations are put in place for a reason: the data you keep is sensitive. Within certain environments, it is extremely important to know how to navigate so as not to mistakenly expose information that has no business being shared. This month, we thought it would be a good time to talk about how to navigate these highly-regulated environments to ensure success and security.
Healthcare
We’ll start with healthcare, as it is the most prevalent. Healthcare data is protected, and that protection is regulated, and all for good reason. This information is the most personal information an individual has and it has no business being in possession of anyone but the provider, the insurer, and the patient. The most well-known regulation for healthcare in the United States is called the Health Insurance Portability and Accountability Act (HIPAA). It was developed to keep personal health data and personally identifiable information (PII) secure. This was necessary as there have been new systems implemented to transfer health and insurance information between healthcare providers and insurers.
Healthcare information isn’t all handled the same. There are many organizations that oversee different parts of the healthcare process. The Center for Medicare/Medicaid services focuses on patient care, while the Occupational Safety and Health Administration (OSHA) focuses on the safety of workers. This is just the cap of a mountain of data. With so many regulatory agencies thumbing around it can be difficult to ascertain which practices are the best practices, and which strategies work to keep every party from having their sensitive information compromised.
For the healthcare providers it can be pretty difficult to do, since they are for-profit businesses and need to keep certain information ready to facilitate solid operational integrity, as well as to ensure that rising costs aren’t sinking their practice. So many providers are constantly revisiting the best ways to stay compliant, while transforming their policies around the existing standards of data protection. This creates a lot of headaches and toiling over policy. One of the best ways to navigate this arena is to set defined practices that work to mitigate redundancy.
Financial Services
Another industry that is highly regulated is the financial services industry. Today, there are a lot of financial organizations looking to information technology to speed up and secure operations, cut costs, and manage their businesses more accurately. A few years back, Congress rolled back one of the most stringent regulations: the Dodd-Frank Act, but it still has some teeth. There are currently three other regulations that financial services companies need to consider: Gramm-Leach-Bliley Act (GLBA), the Sarbanes-Oxley Act (SOx), and the Payment Card Index (PCI DSS). Some larger organizations will still need to adhere to Dodd-Frank, but smaller banks and other lending institutions that were often hamstrung by the Dodd-Frank regulations, are now able to operate free from its oversight. Here is how each work in regards to data security:
- GLBA – Financial services organizations need to identify, adjust, and test their data protections systems to ensure that customer information isn’t being misused or misallocated.
- SOx – Works to require accurate and responsible accounting, and puts an onus on large businesses to increase the transparency of profits.
- PCI DSS – Functions to protect cardholder data, and provide strong controls, reporting, and testing of payment card systems.
The major regulators in the United States are the Federal Trade Commission (FTC), the Consumer Financial Protection Bureau (CFPB), and the Securities and Exchange Commission (SEC). They often step in and levy fines when it’s called for, but they typically hold fast or take advisory roles in matters of data security as it could be looked on as above their mandate. Their function is mostly to keep trade, practices, and markets fair and efficient, not really to protect personal information. Unless threats to that activity are directly coming from identified threat actors, the financial regulators won’t take a proactive approach.
Despite the lack of proactive oversight, most financial entities typically keep their practices to a certain standard. The standards outlined by the Federal Financial Institutions Examination Council handbook or FFIEC-IT. With a dedication to keeping financial services technology the secure product it needs to be, FFIEC-IT booklets outline what is expected to keep a compliant and secure financial services IT infrastructure. By visiting the FFIEC-IT website you can view all the information anyone would need to know to keep their IT infrastructure, network, security practices, and reporting at a level commensurate with the expectations of financial services customers and regulators.
Planning Out Your Business’ Security
All security standards tend to follow the same general principles. Most will talk about the need for concise reporting and constant assessment. This actually works in the service provider’s favor as they can outline a strategy that will work for the many types of organizational oversight that they function under. By creating a static security management plan (SMP), an organization sets up a workflow that will outline the steps everyone has to take to guide them. This can be done the old fashioned way with a checklist on a clipboard, but the best way many organizations we’ve researched accomplish this is by using an electronic spreadsheet to work in some degree of automation. This also provides the visibility to quickly translate and compile information into any reports that you are mandated to provide regulators.
The Security Management Plan should include:
- An organizational security mission statement.
- A static hierarchy of authority with the organization’s reporting structure.
- Identification of areas that need to be secured.
- A general outline of individual duties and activities under the SMP.
- The static documentation system that has to be used to keep things compliant.
- An organizational training program or interface to keep staff up-to-date on shifts in the SMP.
- A roadmap on how to incorporate liaison sites.
- A top-to-bottom security organizational chart.
- A copy of SMP evaluations and a plan for improvement, if needed.
Once you have a dedicated SMP in place, you can go about applying it to every facet of your organization. This is a time consuming task as everything your business has to keep secure should have a line item in the spreadsheet, but once it’s done it will be much easier to ascertain where your organization is on a certain tactic, and how resources should be deployed to ensure that compliance is maintained.
A big part of staying compliant is to put in practice quality assessment tools. Sometimes your organization’s security and practices will work in concert, and sometimes they will conflict. Ensuring that your reference materials are current, consolidated into an easy-to-decipher format, and reported properly will provide you with a much more manageable time managing the assessment and validation systems you’ll need to prove compliance to regulators.
At ExcalTech, we are experts in designing, implementing, and supporting any business’ compliance strategies. Our technicians understand the importance of both the security and privacy of data, and that it needs to be available when called for. Call us today to have a conversation about what you need to do to stay compliant with the regulatory requirements your business falls under at (833) 392-2583.