CyberArk Case Studies Healthfirst Implements Zero Trust with CyberArk Identity Security Platform
Edit This Case Study Record
CyberArk Logo

Healthfirst Implements Zero Trust with CyberArk Identity Security Platform

CyberArk
Platform as a Service (PaaS) - Application Development Platforms
Sensors - Temperature Sensors
Healthcare & Hospitals
National Security & Defense
Cybersecurity
Tamper Detection
Cybersecurity Services
Healthfirst, the largest not-for-profit health insurer in New York State, faced a significant challenge in evolving its cybersecurity operations. With a rapidly growing member base of 1.8 million and an increasingly complex healthcare landscape, the organization needed a robust cybersecurity program. Healthfirst holds a comprehensive database of member-related information, including enrollment, billing, customer care, payments, processing claims, and health data. The protection of these highly sensitive healthcare records and identities of members and staff was paramount. The organization had adopted a cloud-first strategy, with approximately 70% of systems and applications now cloud-based and 10,000 endpoints, 70% of which are remote. This required a sophisticated and robust security solution. The organization aimed to transform the industry by digitally enabling its members, which included heavy investment in digital apps, virtual community-based offices, and mobile solutions.
Read More
Healthfirst is the largest not-for-profit health insurer in New York State, offering high-quality, affordable plans to fit every life stage. These include Medicaid, Medicare Advantage, long-term care, qualified health, and individual and small group plans. Healthfirst’s unique advantage is its member-first approach, partnering closely on shared goals with its broad network of providers. The organization is a pioneer of the value-based care model, where hospitals and physicians are paid based on patient outcomes. Healthfirst has an annual revenue of US$14 billion and employs 5,000 staff.
Read More
Healthfirst turned to CyberArk, a market leader in identity security, to secure its digital transformation. The insurer had already deployed a range of CyberArk products, including Privileged Access Manager and Vendor Privileged Access Manager. The organization decided to adopt additional technologies from CyberArk to further enhance its security. Healthfirst migrated several legacy secrets management apps to Conjur, a CyberArk product, due to its seamless integration with developer workflows and ability to handle a large volume of secrets. Healthfirst also implemented an education and adoption program alongside the CyberArk solution to help staff understand the risk and impact of modern cyberattacks. The company deployed CyberArk Identity to provide staff with secure access to business resources using single sign-on and multi-factor authentication (MFA). The objective was to make it as hard as possible to break into systems, software, and development chains from inside the system, as it is from outside on the internet.
Read More
The partnership with CyberArk has been instrumental in helping Healthfirst build an effective privileged access management and Identity Security program. The CyberArk solutions are integrated across several areas of privileged access management and identity protection, allowing Healthfirst to control security more efficiently and cost-effectively than when it had multiple tools performing similar functions. This has driven significant operational efficiencies in the company. The company's staff have also been educated about the value of security and the risks of modern cyberattacks, leading to a change in mindset and understanding of the importance of security for the business.
Protection of Personal Health Information (PHI) for 1.8 million members
Reduction in security costs with solutions like federated identity control
Removal of the need for expensive security software licensing
Download PDF Version
test test