4-page Case Study - Posted 7/5/2007
Views: 1359
Rate This Evidence:
Healthcare Institution Improves Protection and Saves Money with IT Security Solution
Minnesota-based Allina Hospitals & Clinics is a large network of hospitals and other healthcare facilities. The organization’s employees use a computer-based patient data system that provides updated medical records and other important patient information. The workstations associated with this system which is used by thousands of employees, were not well-protected against spyware, viruses, and similar threats. The security solution in place at Allina did not integrate well with the organization’s IT environment, and administrators could not easily determine which updates and patches had been installed. Early this year, Allina deployed Microsoft® Forefront™ Client Security, which helps protect IT systems against security threats. Allina now has better system security, simplified administration, and improved visibility into its environment. The solution's automated features have helped Allina reduce IT costs and customer downtime.
Situation
Allina Hospitals & Clinics is a system of hospitals, clinics, and other healthcare services located in Minnesota and Wisconsin. Based in Minneapolis, Minnesota, Allina currently has more than 22,500 employees, who work in the organization’s 11 hospitals, 65 health clinics, and other facilities.
About 18,000 of these employees, including physicians and volunteers, regularly use computers at nearly 100 different Allina locations to access the electronic medical record (EMR) system. The EMR system captures important medical information during patient registration or treatment. Using strict security privileges, doctors and nurses can use the system at workstations or at patients’ bedsides to access up-to-date data. Medical coders and patient-billing employees can also use the system. “A doctor can use a computer to retrieve a patient’s complete medical history through this system,” says Brad Myrvold, Desktop Manager, Allina Hospitals & Clinics.
 |
With Forefront, we have the luxury of being proactive, rather than reactive, about security threats. |
 |
|
Brad Myrvold Desktop Manager, Allina Hospitals & Clinics |
|
|
Making sure the EMR system is secure from outside threats is critical, particularly because the healthcare industry has stringent data protection laws and requirements. “As a healthcare institution, we can be held liable for lost or stolen patient data,” says Myrvold. “It’s very important that we secure the system.”
However, the computers used for the Allina EMR system were susceptible to security threats. “Malware and spyware have been big problems,” admits Myrvold. “In the past, those would generate enough traffic to prevent the overall system from working well for some of the T1-connected sites. As a result, doctors and nurses wouldn’t be able to retrieve patient information at certain times.”
The Allina IT department, located in Minneapolis, has 321 employees who are in charge of managing 887 server computers and all 24,000 personal computers in the company. The IT infrastructure is standardized on the Windows Server® 2003 Enterprise Edition operating system. Allina also uses Microsoft® Exchange Server 2003 to manage e-mail messaging, as well as the Active Directory® service and Group Policy to assign policies and apply updates across the entire network. Allina IT administrators also use Windows Server Update Services to provide software updates to the corporate computers. Nearly all of the organization’s personal computers run the Windows® XP Professional operating system.
To protect the IT environment, Allina had been using a set of security software tools to manage security threats. However, that software proved to be unreliable. “First of all, that solution was not aware of our Active Directory service, which was problematic for us,” says Andrew Julian, Operating Systems Programmer, Allina Hospitals & Clinics. “That made it difficult for us to determine which updates and patches we had installed.” Additionally, the solution lacked any reliable reporting capabilities. “That made it hard for us to manage the overall system,” adds Myrvold. Other problems occurred when the solution tried to scan the system for the presence of viruses. “The virus signatures, or fingerprints, that the solution scanned for were very large files and consumed an unacceptable amount of network resources to deliver,” says Julian. “In fact, in some cases the solution slowed the entire network trying to download those signatures to the point of making the network unusable.”
Because it needed to resolve these issues and provide better security and more comprehensive IT management capabilities, Allina decided to implement a new security solution.
Solution
In early 2006, Myrvold and several of his IT colleagues at Allina heard about Microsoft Forefront™ Client Security, a solution that helps protect computers and server operating systems against threats such as spyware, viruses, worms, and malware. Allina was attracted to the product’s ability to provide centralized management capabilities, as well as its tight integration with Windows®-based IT environments. In addition, Myrvold and the Allina team were interested in taking advantage of the solution’s automated updates and systems reporting features.
 |
We need to make sure our doctors and nurses can easily access patient records without having to worry about malware, spyware, or viruses. Forefront Client Security gives us that ability. |
 |
|
Andrew Julian Lead Operating Systems Programmer, Allina Hospitals & Clinics |
|
|
Allina began deploying Forefront Client Security in January 2007, rolling the product out to thousands of its computers. All 24,000 client machines at Allina are protected by Forefront Client Security. As part of the deployment, Allina also installed Microsoft Operations Manager 2005, which helps the company monitor and manage computers on its network that use Forefront.
“We have close to 200 core applications in addition to our EMR system,” says Myrvold. “We were concerned that we might not be able to update all of those before deployment. However, the rollout was very smooth, and it only took a few days to deliver Forefront to this first set of computers.”
Benefits
With Forefront Client Security, Allina Hospitals & Clinics now has much better protection for its critical IT systems than it had before. The solution integrates tightly with the organization’s existing Microsoft products, simplifies system administration, and helps improve visibility into its IT environment. Because Forefront automates tasks, it also helps Allina reduce IT costs.
Better Protection
Forefront Client Security offers Allina end-to-end protection from spyware, viruses, and other security threats through regularly scheduled scanning. The result is much better protection than Allina had with its previous security solution. “We need to make sure our doctors and nurses can easily access patient records without having to worry about malware, spyware, or viruses. Forefront Client Security gives us that ability,” says Myrvold.
Integration with Existing Infrastructure
Tight integration with the Allina Windows®-based IT environment is another advantage of Forefront Client Security. “It’s integrated with our Active Directory service and other Microsoft technologies, whereas our previous solution was not,” states Julian. “That makes the overall security of the IT infrastructure easier to manage. With this environment, everything is smoother and we have much greater control than before.”
Simplified Administration
Forefront also provides Allina IT administrators with a central management server and features such as the ability to define a single policy to manage protection settings on multiple computers. The central management console is used for administrative tasks such as configuring, updating, and alerting. “The way the product works takes a lot of the guesswork out of administration,” says Myrvold. “That simplifies our jobs and allows us to concentrate on other IT areas.”
Improved System Visibility
The solution also has reporting capabilities that give Allina administrators better visibility into the IT environment. For example, Forefront produces detailed security reports and summarizes them in a dashboard viewing format, helping to increase control over threats. “Because of the reporting features, we’re much more confident about security,” says Myrvold. “We can see what’s missing on the network, or which systems need updating. We have much greater insight and understanding of the infrastructure.” Additionally, the ability to report on a global level and then drill down to the device level when needing to isolate issues is an essential tool to managing the Allina environment. “The ability to see the history of a device has proven to be a plus in understanding the trends of our user base,” adds Myrvold.
Cost Savings
Because Forefront uses automated features that provide security-threat analysis from multiple data sources, Allina IT employees have fewer manual, time-consuming tasks to focus on. “Before we deployed this solution, we would have to spend a lot of time ensuring patch management on all our networks, for example,” says Julian. “However, Forefront automates much of that process. We’ve been able to save the equivalent of one full-time employee’s time by using this solution. We estimate a total cost avoidance of two full-time staff as a result of the spyware, malware and virus protection being fully distributed to all of the Allina Hospitals & Clinics desktop computers.
Ultimately, Allina has improved its ability to stay ahead of security challenges by deploying Forefront Client Security. “With Forefront,” says Myrvold, “we can be more proactive, rather than reactive, about security threats.”
Microsoft Forefront Product Portfolio
The Microsoft® Forefront™ comprehensive line of business security products provides greater protection and control through integration with your existing IT infrastructure and through simplified deployment, management, and analysis. Forefront is a comprehensive solution that helps provide protection for the client operating system, application servers, and the network edge.
For more information about the Forefront product portfolio, go to:
www.microsoft.com/forefront
For More Information
For more information about Microsoft products and services, call the Microsoft Sales Information Center at (800) 426-9400. In Canada, call the Microsoft Canada Information Centre at (877) 568-2495. Customers who are deaf or hard-of-hearing can reach Microsoft text telephone (TTY/TDD) services at (800) 892-5234 in the United States or (905) 568-9641 in Canada. Outside the 50 United States and Canada, please contact your local Microsoft subsidiary. To access information using the World Wide Web, go to:
www.microsoft.com
For more information about Allina Hospitals & Clinics products and services, call (612) 262-5000 or visit the Web site at:
www.allina.com
This case study is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS SUMMARY.
Document published April 2007