Company Profile
- Company
- Large Enterprise Healthcare Company
- Size
- Large Enterprise
- Industry
- Healthcare
A large enterprise healthcare organization uses PKZIP and SecureZIP to protect data as it moves over IP, and has maintained PCI DSS compliance on that basis for three to five years. Healthcare records and card data sit in the same estate here, so the same transfers fall under both HIPAA and PCI DSS. Knowing where sensitive data is stored is what the organization credits for its confidence in both.
Background
This case study of a large enterprise healthcare company is based on a December 2021 survey of PKWARE customers by TechValidate, a third-party research service. The profiled company asked to have their name blinded to protect their confidentiality.
The source is a December 2021 TechValidate survey and the organization is not named. Its answers describe a position held over several years rather than a single deployment, which is the useful signal here, because PCI DSS is reassessed annually and an approach that survives repeated assessment has been tested by more than one auditor.
Challenges
The business challenges that led the profiled company to evaluate and ultimately select PKWARE included experiencing issues with:
- Other data compliance mandates (i.e., GDPR, CCPA, etc.)
The surveyed organization has found it moderately easy to achieve or maintain PCI DSS compliance year over year.
They must also comply with HIPPA regulations.
With the addition of PKWARE solutions, we know where all our sensitive data is stored and are confident that it is protected and compliant with PCI DSS guidelines.
Finding PCI DSS moderately easy is an unusual answer and worth examining. Most organizations report the opposite, and the difference generally comes down to whether the locations of the data are known before the assessment begins. An organization that can state where cardholder data resides spends the audit demonstrating controls. One that cannot spends it searching, and every system it finds late becomes a finding.
Our Approach
PKWARE specifically helps this organization achieve and/or maintain PCI DSS compliance by protecting data being transferred over IP.
Use Cases
The surveyed company utilizes the following to achieve and/or maintain PCI DSS compliance:
- PKZIP
- SecureZIP
Protecting data in transit over IP addresses the exposure that file transfer creates. A file leaving a protected system is only as safe as the channel carrying it unless the file itself is encrypted, and healthcare organizations move files constantly between claims systems, clearinghouses, providers and payers. Encrypting at the file level means the protection survives every hop, including the ones the organization does not operate and cannot inspect.
Results
PKWARE specifically helps this organization achieve and/or maintain PCI DSS compliance by protecting data being transferred over IP.
The surveyed organization has worked with PKWARE solutions to maintain PCI DSS compliance for 3 – 5 years.
The surveyed organization is confident that their current cybersecurity setup can scale with company growth and can adapt to fit the updates involved in future PCI DSS updates.
Confidence that the setup will absorb future PCI DSS revisions is a claim about method rather than about the current version of the standard. Controls tied to specific systems have to be revisited whenever either the standard or the estate changes, and both change regularly. Protection applied to the data itself travels with the data, which is why successive revisions tend to require less rework than a control mapped to infrastructure.
