Headquartered in Lake Forest, California, Apria Healthcare is one of the nation’s leading providers of home respiratory services and certain medical equipment, including oxygen therapy, inhalation therapies, sleep apnea treatment, enteral nutrition, and negative pressure wound therapy. Apria operates approximately 300 locations throughout the United States and serves nearly 2 million patients each year.
Cloud Access Security Broker (CASB) – Confidently adopt cloud applications and services without sacrificing security.
Data Loss Prevention (DLP) – Consistently discover, monitor, and protect sensitive data across every network, cloud, endpoint, email and user.
Next Gen Secure Web Gateway (SWG) – The foundation for SSE web and cloud inline security providing threat and data protection.
Accelerated adoption of cloud services
Faster information sharing to deliver better patient care
Better protection of personal data
Healthcare organizations balance protecting large amounts of personal and medical data with the need for quick access and easy movement by and to care providers, insurers, partners, and other affiliates. Apria Healthcare wanted to simultaneously embrace cloud across its organization to enable these initiatives and ensure that patients’ personally identifiable information (PII) stays protected.
Apria Healthcare explored ways to integrate the cloud into everyday processes and architecture. “The IT leadership team made a decision that we were going to be a cloud-first and mobility-first organization to support business strategies,” says Jerry Sto. Tomas, Chief Information Security Officer at Apria Healthcare.
“As an industry with strict privacy and security regulations, we needed to implement increased cybersecurity measures to mitigate risk in the cloud. A robust Data Loss Prevention (DLP) strategy was a critical part of our security program.”
The cloud may be changing how Apria delivers healthcare, but the sensitivity of health information hasn’t changed. HIPAA requires healthcare organizations to safeguard the confidentiality, availability, and integrity of protected health information (PHI). Apria needed a modern data protection solution in place to identify PHI, eliminate access by unauthorized individuals, and to identify and control the flow of PHI in and out of cloud applications.
As an industry with strict privacy and security regulations, we needed to implement increased cybersecurity measures to mitigate risk in the cloud. A robust DLP strategy was a critical part of our security program.
“We have an IT security staff of 12 people,” explains Tomas, “so we have to rely on partners to help us augment our security. To prevent data loss, combat evolving threats, and enforce data security policies across our internal, cloud, and web environment, we implemented Netskope.”
Netskope extends Apria’s data protection policies to the cloud, ensuring that PHI and other sensitive data is not stored or shared with unauthorized individuals. “As we embraced the cloud, we needed to make sure that cloud services were secure. We want to share PHI within the organization but make sure we aren’t sharing it outside,” says Sto. Tomas. “We migrated our on-premises DLP policies to Netskope to increase visibility and scope of policy enforcement to the cloud and mobile devices. Now we can prevent PHI data from leaking to unsanctioned services and third parties.”
Sto. Tomas adds: “With Netskope, Apria has implemented cloud and web DLP policy enforcement without placing a burden on personnel, while also providing employees and patients the assurance that their personal information is in safe hands.”
Looking forward, Apria will continue to use Netskope to address cloud and web risk, enforce security policies, and to comply with regulation.
With Netskope, Apria has implemented cloud and web DLP policy enforcement without placing a burden on personnel, while also providing employees and patients the assurance that their personal information is in safe hands.
Apria has approximately 300 locations as well as mobile drivers and remote employees. Its mobility solution combines Mobile Device Management (MDM) to manage iOS devices and Netskope to secure access and improve visibility. “When we first rolled out Netskope we learned that hundreds of cloud applications were being accessed by our users and gained insight into the who, what, where context by device,” says Sto. Tomas.
Using MDM and Netskope, Apria can apply granular DLP policies based on device type, classify devices as managed or unmanaged, and block unauthorized devices from accessing information.
Identity-as-a-service plays a key role in cloud security. Sto. Tomas explains, “At Apria we use Okta to manage identities. Once users sign in through Okta for cloud service access, Netskope governs the usage of the services.”
Apria uses Netskope to enable advanced security of its web environment in addition to visibility and control for its SaaS applications. “With Netskope, we have an integrated proxy for cloud and web along with a unified policy engine to simplify our security program and streamline administration and operations” says Sto. Tomas. Using Netskope in this way saves Apria time by avoiding redundant DLP and threat protection configuration and the need to switch between tools. Unlike its legacy web proxy that overwhelmed security analysts with high volumes of log data, Netskope synthesizes web and cloud activity to what security teams need to focus on most, significantly cutting costs.
“I need to continue to be an enabler for the business” Sto. Tomas explains, “Netskope makes our cloud strategy possible from a security, performance, and privacy perspective.”