
Key takeaways
- To protect sensitive data, healthcare security leaders require a clear view of ownership for every element of their IT infrastructure.
- When relying on one or more hyperscale cloud providers, ownership can be murky, creating gaps that leave data exposed.
- Using dedicated infrastructure for key workloads can provide a clearer view of ownership and help organizations better protect data.
While healthcare CISOs develop strategies for blocking cyber threats and supporting new business initiatives, they are constantly thinking about ownership: Who is responsible for protecting each workload and the data it touches? How should internal and external teams divide up responsibilities for safeguarding protected healthcare information (PHI) in accordance with HIPAA standards?
It’s not easy to establish clear ownership, especially since healthcare organizations might be using multiple cloud platforms and third-party SaaS applications. Even within a tech stack for a single application, which layers should a cloud or infrastructure provider protect? Which layers are the responsibility of the healthcare organization?
Answering these questions is critical. Ambiguity could produce gaps that leave sensitive data exposed.
Meanwhile, the process of asking these questions will often prompt leadership teams to rethink infrastructure decisions. CISOs and their colleagues might determine that hyperscale cloud providers do not offer the requisite control—or performance—for some workloads while also charging for unneeded resource flexibility.
Not All Workloads Belong in the Cloud
Shared cloud environments work well for many types of workloads, especially those that have fluctuating demand. Still, not all healthcare workloads fit that mold. For example, core electronic health record (EHR) databases or long-term imaging archives are unlikely to need more resources at a moment’s notice. Similarly, the development and testing workloads run by healthtech companies don’t necessarily benefit from the cloud’s elasticity. And healthcare organizations definitely don’t benefit from paying extra to access that elasticity for non-bursting workloads.
Latency-sensitive workloads can also be a poor fit for shared cloud environments. Remote cardiac monitoring, telesurgery and robotic guidance systems, and critical care telehealth applications, for example, require extremely low latency. Allowing data to travel long distances from a patient’s bedside to a distant, centralized data center and back again will not deliver the best outcomes.
Healthcare organizations might also decide to keep some workloads that handle PHI out of the cloud. Though cloud providers offer an array of security capabilities, healthcare organizations often need to control more of the tech stack, including everything above the hardware.
Where do these workloads belong? Using dedicated, single-tenant infrastructure, available through an infrastructure provider, enables healthcare organizations to avoid the excessive costs and performance issues of running certain workloads in the cloud. Organizations can provision dedicated servers to match particular workload needs and run workloads at the edge to reduce latency. At the same time, they can retain full control over the tech stack above the physical hardware.
Establishing a Shared-Responsibility Model
Using dedicated infrastructure can help clearly define responsibilities for protecting apps and data while maintaining compliance. Employing a shared-responsibility model explicitly divides roles between the infrastructure provider and the healthcare organization.
With the shared-responsibility model, the provider controls the bare metal infrastructure layer, overseeing physical, environmental, and network controls. The provider can also provide SOC 2 Type II reports to help healthcare organizations with their HIPAA risk assessment and audit preparation.
The healthcare organization is responsible for application security, access controls, and data encryption. The organization owns the HIPAA compliance program and all safeguards above the infrastructure.
With this approach, there is less chance of a responsibility gap. Healthcare teams know what they need to control and what they can leave to the infrastructure provider.
Implementing a Hybrid Architecture
For many healthcare organizations, dedicated infrastructure will be part of a hybrid architecture. They might choose dedicated, bare metal hardware for a non-bursting analytics environment, patient portal (which handles some PHI), low-latency telehealth application, or PHI-heavy picture archiving and communication system (PACS).
Cloud environments might be a better fit for workloads that need elasticity or specialized infrastructure. For example, population health analytics systems need burst capabilities, while AI models require numerous GPU servers. By matching workload needs to the right environment, organizations can optimize performance, reduce latency, enhance control, and avoid excessive costs.
Aligning Workloads with the Right Dedicated Hardware
Beyond choosing dedicated infrastructure for some workloads, healthcare organizations should also align different types of workloads with optimal hardware configurations. The Hivelocity Healthcare Bundle offers three workload tiers, each with multiple customizable configurations, to meet specific workload requirements.
Engineering Compute: These servers are best for development, testing, staging, and internal tooling environments as well as analytics workloads that use de-identified data.
Production Compute: These servers are designed for business applications that handle some limited PHI, such as patient portals, scheduling, reporting, and other administrative systems.
Hi-Protected Compute: The right fit for PHI-intensive workloads, these servers can be used for EHR platforms, telehealth applications, PACS platforms, clinical data warehouses, and other workloads where patient data is central to the application.
Carefully aligning workloads and dedicated hardware configurations helps ensure each workload is optimized for performance, security, and cost.
Defining Ownership with Dedicated Hardware
To protect sensitive data, while also meeting business and technical requirements, healthcare security leaders must work with their colleagues and external partners to clearly define ownership. They need to establish responsibilities for each part of the technical stack—from the physical hardware up through the database and application layers. And establishing those responsibilities means contributing to infrastructure decisions.
For healthcare organizations, using dedicated hardware for at least part of the IT architecture can help address workload requirements while clearly demarking ownership responsibilities. While the infrastructure provider protects the physical hardware, the healthcare organization oversees the rest of the stack. With responsibilities defined, the CISO can focus on strengthening security for the areas their organization controls.
Learn more about Hivelocity offerings for healthcare organizations.
FAQ
Q: Why should healthcare CISOs care about infrastructure decisions?
A: Healthcare CISOs need to know who is responsible for protecting every aspect of their IT environment. They should participate in infrastructure decisions that affect who controls workloads and tech stack layers. In particular, they should help select the optimal infrastructure for workloads that touch protected health information (PHI).
Q: How does dedicated infrastructure help healthcare organizations?
A: Dedicated bare metal infrastructure can provide better performance for latency-sensitive workloads while also eliminating the premium for elasticity that not every workload requires. The right infrastructure provider can also help clearly define security responsibilities, with the provider protecting the physical hardware.
Q: Why is a shared-responsibility model beneficial for healthcare organizations?
A: A shared-responsibility model clearly defines who is responsible for protecting key parts of the tech stack. When healthcare organizations work with infrastructure providers, those providers are responsible for physical, environmental, and network controls, and they provide reports that can be used for HIPAA audits. Healthcare providers oversee application security, access controls, data encryption, and compliance management.


