Splunk for HIPAA
The old way: IT data barriers lead to avoidable HIPAA violations.
The Health Information Portability and Accountability Act (HIPAA) of 2003 authorized the Department of Health and Human Services to define new rules to ensure the security of IT systems and privacy of electronic protected health information (EPHI). The security and privacy rules include highly explicit requirements for audit trail collection, review and automated monitoring. This has led healthcare providers and insurance carriers to implement costly security event management systems. However, after several years of HIPAA compliance, organizations are beginning to realize that the ability to rapidly search IT data to support incident investigation requirements and to quickly respond to patient complaints is of far more significance in proving compliance and avoiding violations. Yet this remains a slow, and manual process.
The new way: IT Search across all data closes compliance gaps.
Splunk indexes and lets you search across all of your IT data so that you can instantly assess reports of EPHI leakage as well as meet all of HIPAA's explicit log collection and monitoring requirements. For the first time you can instantly retrieve all accesses to a specific file on a massive file server or a particular patient's data in a billing or care management system. You have complete visibility from the network and filesystem to database, application and web self-service tier into all transmission and access to EPHI.
