Safeguard protected health information (PHI) while maintaining operational efficiency with BOSSS comprehensive healthcare security platform.
HIPAA
Compliance Ready
HITRUST
Framework Support
SOC 2
Audit Ready
PHI
Data Protection
We understand the unique security challenges facing healthcare organizations.
Navigate the Security Rule, Privacy Rule, and Breach Notification requirements.
Protect PHI across EHRs, medical devices, and third-party systems.
Secure IoT devices, imaging equipment, and connected medical devices.
Manage BAA requirements and vendor security assessments.
Purpose-built solutions for healthcare security and compliance.
Complete HIPAA Security Rule control mapping and monitoring
Role-based access with continuous monitoring and auditing
Automated discovery and security assessment of medical devices
BAA tracking and ongoing vendor security monitoring
Automated breach detection and notification workflows
Healthcare-specific phishing simulations and training
Five situations a health system actually faces, from the bedside to the board report.
Kestrel Health System — a composite organization in the BOSSS demo environment
The situation
The EHR goes dark and the emergency department reverts to paper
A phishing email reaches a clinical workstation at an emergency-department nursing station. Two days later the attacker moves laterally and detonates ransomware, encrypting the CoreChart EHR production cluster and the PACS imaging file share. All three hospitals lose EHR access and the emergency department declares downtime, reverting to paper procedures.
Who is involved
Scenario timing
How BOSSS handles it
Mass-encryption behaviour is detected on the clinical workstation
Ransomware mass-encryption behavior on clinical workstation
Escalated to a full investigation case
Ransomware Clinical-Downtime Investigation
Clinical outage ticket opens and downtime is formally declared
Ransomware detection on clinical workstation — EHR downtime declared
Formal incident record covering the encrypted clinical estate
Ransomware Encryption of the EHR Production Cluster
Continuity and recovery plans drive the restore from the DR data center
EHR & Clinical Operations Ransomware Continuity Plan
Backup and segmentation weaknesses become a tracked POA&M
POA&M — Ransomware Backup/Segmentation Hardening
Clinical downtime procedure and board reporting close the loop
Q3 Board Security Report: Ransomware Incident
What this makes possible
What it touches
Entities
Kestrel Health System
3 hospitals affectedMerriston, OH
Locations
Kestrel Central Hospital Campus
Headquarters · flagship trauma centerMerriston, OH
Kestrel West Community Hospital
OfficeWestbrook, OH
Kestrel Riverside Hospital
OfficeRiverton, OH
Kestrel DR / Backup Data Center
Disaster Recovery Site · restore sourceFairhaven, OH
Applications
CoreChart EHR Production Cluster
EncryptedMerriston, OH
PACS Imaging File Share
EncryptedMerriston, OH
Clinical Workstation — ED Nursing Station
Initial compromiseMerriston, OH
Nightly EHR Backup
Restore sourceFairhaven, OH
Vendors
Cornerstone Clinical Systems
EHR platform — Business AssociateMadison, WI
Harbor Imaging Systems
PACS — Business AssociateBoston, MA
Aegis Endpoint Security
Endpoint detectionAustin, TX
Lumen Security Analytics
SIEMReston, VA
Data
EHR Clinical Record
Data set — ePHIMerriston, OH
Clinical Encounter Note
~14M encounter notesMerriston, OH
Diagnostic Imaging Study (DICOM)
~2.4M imaging studiesMerriston, OH
Medical Record Number (MRN)
~1.8M patient recordsMerriston, OH
Why BOSSS
Designed to protect patient data while streamlining HIPAA compliance across your organization.
Key Benefits:
See how BOSSS can help your organization achieve security and compliance goals.
We use strictly necessary cookies to run this site. With your permission we would also use analytics and marketing cookies, including session recording. Cookie Policy