Increase security posture to comply with HIPAA
To gain a thorough understanding of the healthcare organization's IT infrastructure and operational processes, we conducted an extensive technology assessment. This involved collecting data and interviewing the executive team. After completing our information gathering, we analyzed our results and produced a report. The report indicated that the nonprofit's most significant challenge was the urgent need to strengthen their cybersecurity measures to maintain HIPAA compliance. Following discussions about the report and the client's priorities, we developed and implemented a plan of action. The initial step was to transition them from their provider's hosted email service to their own Microsoft 365 Nonprofit Tenant for email, file storage, and collaboration. We then integrated Proofpoint email security to provide antivirus/spam protection, email encryption, and archiving in order to comply with HIPAA requirements for personal identifiable information (PII) protection. Following this, we migrated their data to SharePoint and Teams, reducing their dependency on traditional on-premises file servers and allowing for increased flexibility in remote work while remaining HIPAA compliant. Once we completed the migration to the Microsoft ecosystem, we concentrated on "hardening" their IT environment, which included implementing Duo multi-factor authentication for securing Microsoft 365 logins. Additionally, we set up Skykick Backups to regularly capture and store copies of their entire Microsoft 365 organization up to six times daily with unlimited retention. This was crucial, as Microsoft does not provide sufficient direct backup solutions.