Matomo

Encrypting patients' data across hospital networks | Cossack Labs
Case studies
Encrypting patients' data across hospital networks

Encrypting patients' data across hospital networks

FEB - MAY 2019 EHR exchange Cloud data security
Encrypting patients' data across hospital networks

Overview

Industry

  • Healthcare
  • EHR exchange

Technology stack

  • Google Cloud Platform (KMS, GKE, Redis, VerneMQ)
  • iOS
  • server-side Swift

Regulations

  • GDPR
  • ISO 27001, ISO 27002
  • Dutch Act on the Medical Treatment Agreement (WGBO)

Challenges

[01]

Extensive technology stack

GoClinic system operates within extensive technology stack, supports numerous mobile apps, cloud backend and databases. Data protection should be consistent and easily maintained across all infrastructure components.

[02]

Legacy hospital networks

Legacy hospital networks require careful integration, isolation of patients' data, and providing fully fledged data lifecycle and it's security.

[03]

Customer's data isolation and insider risks

Cryptographic engine should be closely tied with platform-specific security controls. The security solution should prevent abuse and misuse from hospitals staff and “curious patients”.

Technology requirements

Technology requirements

Compliance to healthcare regulations

Correspondence of security architecture and chosen security controls to the risk profile and healthcare regulations.

End-to-end encryption of medical data

End-to-end encryption of medical data from hospital networks to patients devices while preserving the usability of GoClinic mobile apps and making patients' lives less stressful.

Strong cryptography

Soundness of cryptographic protocol and key management procedures (including QR code-based key exchange) to prevent access to sensitive data without required keys.

Solution

Security advisory, security architecture assessment and risk modelling:

Cryptographic audit:

Results and outcomes

GoClinic team acquired a basis for company-wide and product-specific security policy, solid security foundation and development plan for improving their system.

Sustainability of security architecture, deep integration of security controls and defined security roadmap allowed GoClinic team to target not only private hospitals, but also governmental healthcare companies, and provided a clear advantage over their competitors.


Up next

Got a challenge that's still standing?

Let’s start a conversation.

Start a conversation

Get whitepaper

Apply for the position

Our team will review your resume and provide feedback
within 5 business days

Thank you!
We’ve received your request and will respond soon.
Your resume has been sent!
Our team will review your resume and provide feedback
within 5 business days