| |
Security
audit for an Financial
Company
The
company is one of
the most successful
financial service
providers in the USA
, offering financial
services and other
Insurance services
to USA based clients.
They have offices
at four locations
across the USA and
have centralized IT
operations. The company
has considered e-commerce
as a major driver
for business as well
as a way to offer
better services to
their clients. They
have installed dedicated
e-commerce infrastructure
and deployed several
applications to cater
to their business
needs.
Our
challenge was to architect
client's network Infrastructure
to ensure secure business
transactions on the
Internet and Intranet.
The scope of the project
included review of
the network infrastructure,
network level vulnerabilities,
system level vulnerabilities,
application level
(Web Servers) vulnerabilities,
incident handling
and change management.
Exuberant had to recommend
the necessary changes
on network infrastructure
and had to provide
a roadmap considering
certificate management
and disaster recovery
requirements.
Exuberant
carried out security
audit on various extranet
applications deployment,
which included authentication,
authorization and
password controls.
We deployed network
infrastructure and
conducted security
audit, which included
Nokia IP440 firewalls
running Checkpoint
FW-1/VPN-1 and Cisco
7200 series routers.
Security audit was
carried out on Web
Server and Application
Server operating systems
like Solaris and Windows
NT and on Web servers
like iPlanet and IIS
Web Servers.
- Assessment
of critical system
and network vulnerabilities.
- Recommendations
on fixing the vulnerability
of different operating
systems and network
equipments.
- Sharing
of best practices
across operating
systems and network
infrastructure.
- Suggestions
for improving the
current security
policy with respect
to the areas audited.
Healthcare
regulatory
Exuberant
has provided a broad
spectrum of healthcare
consulting services
focusing on regulatory
compliance in the
payer and provider
markets. Health Care
Company engaged Exuberant
Expertise in its efforts
to comply with the
U.S. Health Insurance
Portability and Accountability
Act (HIPAA).
The
Challenge
Health
Care Company across
States, a for-profit
mutual insurance company,
offers its clients
the largest network
of doctors, hospitals,
and other healthcare
providers available
in the state. With
more than 1,000 employees,
advanced technology,
and a strong commitment
to excellent service,
the company processes
approximately 5 Million
healthcare claims
and pays out more
than $50 million in
medical expenses each
year.
Under
the HIPAA, the U.S.
Secretary of Health
and Human Services
is authorized to promulgate
regulations necessary
to achieve several
goals of administrative
simplification within
the healthcare industry.
The goals include
developing electronic
standards for healthcare
transactions, ensuring
the security of healthcare
data and systems,
and protecting the
privacy of personal
health information.
In light of these
developments, Health
Care Company recognized
the need for assistance
to achieve its goals
of regulatory compliance,
understanding and
interpreting HIPAA
regulations, and educating
the entire organization
on HIPAA and its impact.
Exuberant noted expertise
in healthcare consulting
coupled with its understanding
of the new HIPAA regulation
and its effect on
healthcare organizations,
was precisely the
medicine the insurer
was looking for.
The
Strategy
Exuberant
mandate was to conduct
a HIPAA impact assessment
and gap analysis that
would take into account
the insurer's applications,
systems, vendors,
and partners. Prior
to the assessment,
Exuberant developed
and conducted multiple
educational programs
for company executives
and senior management.
Exuberant put together
an impressive consulting
team that included
experts in claims
processing, transaction
and codes sets, national
identifiers, security,
privacy, and technical
training. In their
analysis, the team
would examine the
cost of resources,
opportunities, risks,
and other significant
budgetary impacts.
Technology:
Consulting Assignment
The
Results
Exuberant
conducted a gap analysis
and developed an impact
report for the business
areas of the company.
Business areas examined
included claims (medical,
pharmacy); corporate
accounts administration,
including re-insurance,
membership, and billing;
customer service;
marketing, underwriting;
utilization management
(case management),
provider contracting;
provider credentialing;
security administration
policies and procedures
and infrastructure
components and compliance.
A similar gap analysis
was provided for the
company's hardware
and software.
|
|