Situation:
Your team represents the IT leadership of a large healthcare organization that is preparing to purchase a smaller hospital group consisting of:
2 Metro hospitals (1 is a learning hospital, which means students are in scope)
3 Rural hospitals
2 Shared data centers (located within 5 miles of each other)
25 Physician practices
1 Lab
1 Coordinated business office
Your objective is to evaluate the sites prior to purchase from a risk and compliance standpoint, with a focus on access controls at both the logical and physical standpoint. Part of the agreement allows for your organization to thoroughly test the systems, which includes:
1 Electronic medical record (EMR) system
2 Mobile applications (1 has the ability to accept credit card payments)
5 External websites (1 has the ability to accept credit card payments)
3 Cloud based systems (1 Infrastructure as a service, 2 Software as a service)
Internet connectivity is not shared between the physician practices and main hospital locations
75 Patient care applications (25 developed internally)
500 Patient care devices