Project Hosts | Top Healthcare Cybersecurity Solution Company 2018
Healthcare Tech Outlook
>> Security >> Project Hosts

Project Hosts
Ushering Secure Cloud Transformation to Healthcare

Project Hosts: Ushering Secure Cloud Transformation to Healthcare

 Erez Avidan-Antonir, VP of Business Development, Project Hosts
There is no denying that the healthcare industry is particularly vulnerable to cyber attacks, due to the volume of sensitive information flowing within the industry. For instance, in 2015 alone, there were more than 100 million medical records compromised through various breaches according to a report by IBM. The concern within the industry about such breaches is the very reason the healthcare industry is one of the last industries to move to the cloud. Healthcare providers instead, have preferred that their workloads and data remain in their on-premises data centers, in the hopes of ensuring data security. But, the on-premises environment has failed to evolve with the threat landscape. The efficiency of security management in the cloud, offered by the likes of Google, AWS, and Microsoft, is indeed driving healthcare toward cloud adoption. Set against such a backdrop is Project Hosts, an Azure-based cloud services provider (CSP) that helps healthcare providers and payers migrate their data and workloads into a secure Azure cloud, while also providing compliance with regulatory standards such as HIPAA, HITRUST, FedRAMP, DoD IL 4/5, GDPR, and ISO 27001.

With over 15 years of experience in hosting and managed services expertise, Project Hosts is a recognized leader in delivering high performance, secure and compliant cloud-based solutions. The company’s HIPAA/HITRUST Azure Security Envelope extends Azure's built-in IaaS and PaaS security compliance to include all software and data running in the cloud, which ensures that electronic Personal Health Information (ePHI) is protected from unauthorized access or theft. The solution helps clients execute controls related to access, authentication, encryption, privacy, annual assessment, penetration testing, and required documentation.

Project Hosts offers two ways in which their clients can move to Azure. One way is to help them shift their on-premises apps, workloads, and data into their own Azure subscription. Project Hosts has extensive experience in hosting and managing Windows and Linux applications in Azure. The company provides the necessary services to deploy, secure, and manage the client’s applications with 24×7 monitoring, support, and ongoing maintenance. “In many cases, we offer hybrid-cloud integration services to on-premises environments, Office 365 and other cloud environments,” mentions Erez Avidan-Antonir, VP of Business Development at Project Hosts. The other way to move to Azure is to shift certain workloads into Project Hosts’ Azure Security Envelope, which is already certified for HIPAA and HITRUST compliance.

With over 15 years of experience in hosting and managed services expertise, Project Hosts is a recognized leader in delivering high performance, secure and compliant cloud-based solutions

In 2017, during the time of a natural disaster, a healthcare provider in the Caribbean had to move to the cloud and deploy a solution in a timely manner. The solution had to be both HIPAA and FISMA compliant as government agencies were involved in the project. The client also had to maintain a hybrid topology and to include integration with Office365 while supporting Remote Desktop Protocol (RDP) and Single-Sign-On (SSO) services. Project Hosts could meet the customer’s goals and respond quickly utilizing its Microsoft Azure Security Envelopes. “Project Hosts addresses the different market verticals, with different information security certification needs, through the deployment of Azure Security Envelopes, that allow us flexibility and agility when responding to customer needs” Avidan-Antonir notes.

Project Hosts looks forward to further scaling its services. "The healthcare industry has been targeted by cybercriminals for years. With a team of cloud-based cyber-security experts, Project Hosts sees the opportunity to help providers overcome the danger of threats by providing secured cloud solutions so that they have peace of mind when migrating to the cloud,” concludes Avidan-Antonir.

Top 10 Healthcare Cybersecurity Solution Companies - 2018

Company
Project Hosts

Management
Erez Avidan-Antonir, VP of Business Development, Project Hosts

Description
Azure-based cloud service provider, which helps healthcare organizations and payers to move to the cloud securely

Project Hosts News

How important it is to obtain an ATO?

Project Hosts It is not just important. It is imperative. It is mandatory. But it is hard to achieve!
We find that many of the Software as a Service (SaaS) providers still have difficulties to accept the fact that to sell to the government and DoD cloud application solutions and services, these solutions must be authorized by the government. In the realm of application development, securing an Authorization to Operate (ATO) is a prerequisite before an agency can deploy the application for its users.
ATO is defined as an official decision by an organization, explicitly accepting the associated risks to various facets of the business. This acceptance is based on the implementation of an agreed-upon set of security controls. For cloud services aligning with Joint Authorization Board (JAB) standards, there exists the possibility of obtaining a Provisional Authorization to Operate (P-ATO). This requires evidence of commitment from six agencies intending to use the cloud services. The JAB, consisting of CIOs from the General Services Administration (GSA), Department of Defense (DoD), and the Department of Homeland Security (DHS), may issue a P-ATO after reviewing the cloud service for government-wide application.
Components of ATO Package
An ATO package comprises essential documentation for the security control assessment, providing Authorizing Officials (AO) with the necessary information to make informed, risk-based decisions. Key components include the System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action and Milestones (POA&M). Additionally, agencies may opt to include a Risk Assessment Report (RAR) as part of the security authorization package.
The Six-Step ATO Process
1. Categorize the System: Classify the system within the client-agency organization based on potential adverse impacts, considering security objectives like confidentiality, integrity, and availability.
2. Select Baseline Security Controls: Choose relevant baseline security controls to evaluate their effectiveness in securing the application.
3. Implement Security Controls: Deploy selected security controls within the client’s enterprise architecture, focusing on custom code and configuration.
4. Assess Security Controls: Collaborate with the client’s cybersecurity team to evaluate the effectiveness of security controls, including penetration testing and a comprehensive review process.
5. Authorize Information System: Schedule and prioritize the system assessment, followed by a cross-functional team review of ATO documentation. Once approved, the AO signs the ATO memo.
6. Monitor Security Controls: Implement continuous monitoring of controls, addressing security notifications and updating relevant documentation.
Project Hosts’ GSS One platforms support SaaS providers and Cloud Solution Providers (CSPs) in two ways –
Our GSS One Azure has achieved three additional ATOs recently. This brings the total number of ATOs for our GSS One – Azure to thirty-four (34) and counting.
Our GSS One AWS has now achieved FedRAMP High “In-Process” status for an authorization by the FedRAMP Joint Authorization Board (JAB) and is ready to onboard SaaS providers on AWS.
Utilizing our innovative GSS One platform, and our FasTrack onboarding process, we are not only setting new efficiency standards in the industry, but also empowering Cloud SaaS providers and CSPs to excel in a competitive government market. This achievement reaffirms Project Hosts’ commitment to delivering Cloud Compliance as a Service solutions that meet the highest standards of confidentiality, integrity, availability, and security recognized by the U.S. government.