Securing remote access at Genesis Health System

May 25, 2017
By Aaron Miri, Chief Information Officer, Imprivata

Genesis Health System is a 665-bed system based in Davenport, IA, that offers full continuum of care services in a 12-county region covering Eastern Iowa and Western Illinois. When the decision was made to move to virtual desktops, the IT team at Genesis also started to consider selecting and implementing a solution for two-factor authentication. Implementing such a solution would help to combat phishing attacks as well a support a larger, enterprise-wide security strategy.

“The best way for us to mitigate risk is two-factor authentication,” says Dave VanDerHeyden, Infrastructure Manager at Genesis. “Being able to verify someone’s identity via their credentials, if they were set up to use two-factor authentication, is a great step toward ensuring the security of our health system.” But VanDerHeyden and the team at Genesis needed to ensure that the two-factor authentication solution they put in place would be convenient for care providers and would support—not impede—established workflows.

The solution

After evaluating several two-factor authentication providers, Genesis selected Imprivata Confirm ID for Remote Access to help ensure secure but convenient access from outside the health system.

“Ultimately, whatever solution was selected will need to be used by our physician community,” says Dr. Anthony Carbone, CMIO at Genesis. “It had to be easy to use, it had to be reliable, and it had to be a solution that wouldn’t frustrate you while you were using it. Imprivata Confirm ID for Remote Access checked all of those boxes.”

Imprivata Confirm ID offers secure authentication methods, such as push token notification, that can be leveraged across various workflows within the health system. This enables Genesis to meet its IT security requirements with an authentication workflow that is seamless for end users.

Working with Imprivata

Genesis Health System knew Imprivata as a strategic IT partner before implementing Imprivata Confirm ID for Remote Access—they had already been using Imprivata OneSign for their single sign-on (SSO) needs.

Imprivata OneSign is an SSO and virtual desktop access platform that secures PHI; allows clinicians to focus more on patient care with fast, secure No Click Access to patient data; and enables healthcare organizations to leverage the full benefits of their EMR and virtualization technology investments.

“Continuing to build our partnership with Imprivata made us feel more comfortable,” says VanDerHeyden. “Because Imprivata OneSign and Imprivata Confirm ID are so tightly integrated, enrollment and management became much easier.”

Seeing the results

With Imprivata Confirm ID for Remote Access, Genesis Health System has bolstered their security strategy and helped to guard against phishing attacks. Perhaps the greatest benefit, though, is for clinicians, who are now able to securely access their desktops—and patient data—from anywhere. “Our physicians are able to access crucial patient information from wherever they happen to be,” says Carbone. “And, with two-factor authentication in place, we can be sure that the security of the data is maintained. It’s a win-win for everyone.”

Down the road

Now that Genesis is using Imprivata Confirm ID for Remote Access, they’ve started thinking about how they can add two-factor authentication to a broader set of users and workflows.

“We’re looking to implement two-factor authentication everywhere,” says VanDerHeyden. “And knowing that we would be able to work with a trusted partner for all of our two-factor authentication needs gives us confidence that we can continue to improve security across our enterprise.”