Fifteen Facilities. No Single Source of Truth.
A multi-facility healthcare system faced fragmented security tools, no centralized monitoring, and struggled with HIPAA compliance across disparate EHR systems (Epic, Cerner). Medical device vulnerabilities and a lack of visibility into their full attack surface put patient data at risk across every site.
Each facility had accumulated its own point tools and its own informal incident-response habits over years of decentralized IT decisions, which meant a security event investigated at one site frequently went unexamined at the others, even when the same indicator of compromise was present. Neither EHR vendor's native audit tooling was built to be correlated against the other's, so a system-wide question as basic as whether a given credential had been used to access patient records at more than one facility had no single place to be answered.
A Converged Response Across All Four Portfolios
24/7 healthcare SOC with HIPAA-compliant monitoring, Microsoft Defender XDR deployed across every endpoint and server, and a medical device security program built on network segmentation — isolating infusion pumps, imaging systems, and other IoMT devices that can't run standard endpoint agents onto their own segments with tightly scoped firewall rules, since a compromised nurse-station workstation and a compromised infusion pump call for very different containment plays.
Unified monitoring through integrated NOC/SOC operations gave facilities and IT teams a shared alert queue instead of two teams working from two separate ones. Disaster recovery infrastructure was built to a <4-hour recovery time objective (RTO) — a target set by clinical reality, since an EHR outage doesn't just cost revenue, it forces facilities back to paper charting, which carries its own patient-safety and documentation risk. M365 security hardening (conditional access, mailbox audit logging, DLP tuned for PHI) was applied consistently across all 15 facilities rather than site by site.
vCISO services provided ongoing security governance and a formal HIPAA compliance-as-a-service program — risk assessments, policy management, and the administrative safeguards work a 15-facility system needs a standing governance function to keep current, not a once-a-year audit-prep exercise.
EHR security optimization across Epic and Cerner was a materially different problem from generic endpoint or network security. It meant building role-based access control mapped to actual clinical roles — a floor nurse, an ED physician, a billing coordinator, and a system administrator each need different EHR access, and HIPAA's minimum-necessary standard requires that access be provably scoped to job function, not just technically restricted. It meant instrumenting audit logging for PHI access specifically — not just who logged into the EHR, but who viewed which patient's record, when, and whether that access lines up with an active clinical relationship, since inappropriate-access investigations depend on that granularity existing before an incident, not after. And it meant running one unified SOC across two EHR vendor environments that don't expose the same logging formats, alerting hooks, or audit trail structure out of the box; normalizing both into a single set of detection rules and a single incident response workflow was its own integration project layered on top of the SIEM deployment, not a byproduct of it.
Physical security convergence tied access control badge systems and nurse call system monitoring into the same SOC that watches the network, so a forced-door alarm at a facility and a suspicious authentication attempt against that same facility's VPN surface to the same analysts on the same timeline, instead of being triaged by two separate teams that may never compare notes.
What Changed
Unified security visibility across all 15 facilities, a HIPAA audit passed with zero findings, a 78% reduction in security incidents, and a mean time to detect (MTTD) under 15 minutes.
Six separate vendor relationships eliminated through convergence, cutting operational complexity and reducing annual security spend by $340,000 while materially improving security posture.
The 78% incident reduction, sub-15-minute MTTD, and $340K savings figures above are aggregated from anonymized outcome data across multiple real Armorstack multi-facility healthcare engagements of comparable scope — unified SOC/NOC deployment, HIPAA-regulated EHR environments, and 6-vendor-to-1 consolidation. They are not drawn from, or attributed to, any single client, and no spokesperson quote is attached to them. Figures are recalculated from engagement data at each publication refresh; ask us for the underlying methodology.
Ready for Results Like These?
Running a unified SOC across Epic and Cerner — or any multi-vendor EHR environment — isn't a generic monitoring problem; it requires security operations built around clinical roles and PHI access patterns, not just network traffic. If that gap exists across your facilities, let's talk about closing it.Talk to Armorstack →
877-890-5508 · [email protected]