Technical Security Recommendations for ABC Healthcare IT Infrastructures
ABC Healthcare has been facing a multitude of challenges ranging from the security of the IT infrastructures to the compliance of regulatory policies. In the United States, the lawmakers are increasing putting more restrictive in the regulatory environment because there have been more attacks in the healthcare environment, damaging the organizational information systems and using worms and virus to gain access to non-authorized sensitive data. The issues are making the stakeholders of ABC Healthcare demand for more flexible access to their information systems. Moreover, increasing regulatory pressures within the healthcare environment with regards to the management of the information systems has made ABC Healthcare to decide to implement more prudent information systems security. The goal of ABC Healthcare is to implement good information systems to abide by regulatory policies of HIPPA and SOX (Sarbanes-Oxley). Typically, both SOX and HIPAA mandate healthcare organizations to have good systems as well as good administration and control that will prevent threats to the system and allow a continuity of business operations.
The objective of this project is to provide technical recommendations for ABC Healthcare that will assist them implementing effective security systems to protect their information systems and abide by the SOX and HIPAA regulatory policies.
1. Technical Recommendations for Security Requirements and System Design
A protection of ABC Healthcare of network and information systems are very critical to comply with the SOX and HIPAA regulatory policies. The study recommends that ABC Healthcare should use the internal LAN (Local Area Network) using the private IP (internet protocol) to segregate from the untrusted network using the firewall to filter untrusted network. ABC Health should use three GIAC networks to connect to the internet and remote entities such as partners, customers, suppliers, and employees. ABC Healthcare should use the server-based network that allows all users having access to the network resources. Moreover, the server-based network allows users to share data and easy backup of data. In the server-based system, users have one username and password that allow them to log into the server to share the data over the network resources. Typically, server operating system will assist ABC Healthcare to handle a load of multiple users who are having access to the server-based resources. The benefit of the server-based model is its ability to manage all printers and other hardware. The system is also scalable because it can be adjusted based on an increase in the load system.
The hardware to design the network-based network infrastructures for the ABC Healthcare is as follows:
Operating system: 64 bit Windows Server 2012 R2. Moreover, the Microsoft Net Framework should be installed.
Language: English
Memory: 8 G Ram
Processor: 2 CPU Sockets with a minimum of quad core. Server class processor with @1.8GHz minimum.
Hard Disk Storage: System Drive (C:) that requires available 20GB. Install Drive will require available 80GB.
Network Interface Card: Minimum of 10/100BASE-T that supports the TCP/IP in a Microsoft Windows networking environment.
The configuration of the systems will assist the company to establish the effective network systems. However, an integration of different security systems is essential to assist the company to enhance confidentiality and integrity of the network systems.
Electronic Medical Records: The company will also need to develop the EMR (Electronic Medical Records) database to store patient and provider's information.
The study recommends different security systems for the internet and network securities that should be used to prevent, deter, detect and correct eventual security violations during the transmission of information. Application of computer security is also needed to protect the company hardware, software, data and another information system.
The integration of the SSL (Secure Socket Layer) is the first security protocol to secure the network systems and provide security between TCP and applications. The company website header should start with HTTPS, which combines HTTP with SSL to achieve a secure communication between a Web server and a Web browser.
Encryption technique is another security measure recommended for ABC healthcare. In the network system, the TCP/IP is a set of communication protocol over the internet that defines the route communication. Since information can be hijacked by a third party over the internet, the study recommends the integration of the encryption system that allows data to be unreadable by a non-authorized individual. When the encryption software is installed in the network system, all data transferred over the network systems will be changed to nonsense texts, and only an authorized person with a decrypted key will be able to read the data. The strategy will prevent illegal activities such as eavesdropping, and information hijacking from the server.
An access control is another security method for the...
Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.
Get Started Now