CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • Managed iT Services

Improving Efficiency and Protecting Patient's Information by Automating the Identity and Access Management Process

Ana Agostini, Administrative Director-Information Technology Services, Memorial Healthcare System

Tweet

content-image
Credentialing employees and vendors to have access to the appropriate programs in a timely manner and protect access to these systems was imperative for Memorial Healthcare System, especially if some of these systems provided access to personal health information (PHI). From an IT perspective, the additional criteria included time efficiency and agility to provide access to these systems.

A few years ago, our provisioning process was done manually. We had to create, modify, or disable access to all accounts for employees and vendors one by one. With this setup, it could easily take an analyst up to 30 minutes to create all requested accounts for each user.

With the lack of standardization, there were delays and inconsistencies when processing access requests for new employees or vendors. We realized it was important for us to find a vendor we could partner with to design an automated process which would standardize the provisioning of accounts and increase our efficiency in providing the correct access needed.

Memorial Healthcare System (MHS) built a role database that defines the applications and level of access each role should have based on the job functions and location of each employee or vendor. Our current Electronic Health Record (EHR) was the main driver when building this role database, ensuring appropriate access to patient information was assigned to our end users.
The clinical, business and technical teams, along with our Human Resources Department, collaborated to identify what applications and the level of access required for each job role.

After Identity Governance, our current Identity and Access Management system was implemented. What used to manually take up to 30 minutes, it’s now being processed automatically in seconds for many accounts at the same time. For employees, the creation of the accounts, changes to their role due to transfers or promotions, or account terminations all happen automatically when there is any change in our Human Resources system. For vendors, we use the Identity Governance Portal to enter the vendor information and select the appropriate role. All accounts are automatically created with the appropriate access based on the defined role. By automating the provisioning of user and application accounts, our System Access analysts can now focus on better quality of service, supporting our customers with additional access requests, and making sure they have what they need related to level of access in a timely manner.

Another great feature implemented was the ability to monitor when vendors’ accounts were set to expire. Prior to this implementation, vendors accounts would expire, interrupting business operations and delaying any work the vendor was performing while the access was validated by the sponsor and then reinstated by the System Access team. With this new feature, the sponsor is notified via email 14 and 7 days prior to the expiration date. The sponsor has the ability to easily request an extension of the expiration date if needed, avoiding any access interruption for the vendor, therefore, saving money to the organization.

We also partnered with the vendor to design the Period Access Review (PAR) process for all applications that are part of Identity Governance. This is an automated/online report sent quarterly to all employee managers and sponsors of vendors to verify if the applications and the level of access granted to their direct reports is still accurate.

The manager or sponsor can validate their current access, request a change, or submit a termination request if the direct report no longer needs the access to a specific application. These requests go directly to the MHS System Access Team, which expedite the process and keep a log of what was requested and by whom.

This electronic Periodic Access Review is fast and easy, and has helped us tremendously to keep our patient information safe by removing unnecessary access to critical systems and Protected Health Information (PHI) in a timely manner.

We are constantly adding new applications to Identity Governance and refining our role database to continue improving the provisioning process at MHS.
At Memorial, patient privacy is everyone's responsibility!

Check this out: 

Top Identity and Access Management Solution Companies in Europe

Top Identity and Access Management Consulting Companies in Europe

Weekly Brief

loading
views
  • Adopting And Driving AI Across an...

    Dr. Yves Gorat Stommel, Deputy Head of Function Evonik Digital, Evonik [ETR: EVK]

  • Challenges under the Hood: Cloud...

    Ivan Romero, Global Head Of Public Cloud, Wealth Management & Insurance, Banco Santander(BME: SAN)

  • Evolving Role of the CISO

    Christos Syngelakis, Group Chief Information Security Officer, Motor Oil[Fra: Mhz]

  • EU Cyber Challenges For The Private...

    Paulo Moniz, Director- Information Security and It Risk, EDP [ELI: EDP]

  • Inspiring Extraordinary Customer Success

    Alexander Bender, Global Head of Client and Broker Relationship Management, Allianz

  • Unveiling the Power of Data Visibility

    Muhammad Saleem, Head of Data Architecture, Bae Systems [LON: BA]

  • Transforming The Trucking Industry...

    Jair Ribeiro, Data Analytics and AI Leader, Volvo Group

  • The Transforming Landscape of...

    Cameron Farrar, Vice President - Head Of Software Asset Management, Marsh Mclennan(NYSE: MMC)

RECENT EDITIONS
‹ ›

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://managed-it-services.cioapplicationseurope.com/views/improving-efficiency-and-protecting-patient-s-information-by-automating-the-identity-and-access-management-process-nid-1108.html