Sun Healthcare finds Rx for remote-access ills

Opinion
Jan 11, 20053 mins

* Healthcare co. cures remote-access headache

The network-security compliance burdens of privacy and corporate governance legislation such as Sarbanes-Oxley and the Health Insurance Portability and Accountability Act continue to drive organizations to seek creative networking approaches.

Sun Healthcare Group of Irvine, Calif., for example, has alleviated remote-access headaches caused by these rules using a new implementation twist on SSL technology, says senior network engineer Zachary Grant. One such challenge has been determining what security risks remote users might pose, Grant explains.

As we mentioned in a series of newsletters last November, both IPsec VPNs and traditional SSL VPNs have respective strengths and weaknesses. As originally designed and deployed, SSL encrypts and authenticates traffic for “Webified” applications only, but alleviates some of the firewall-to-firewall interoperability restrictions of Layer 3 IPsec encryption.

In the wake of HIPAA and Sarbanes-Oxley, Sun Healthcare struggled to find a simple way to allow its many vendors and home users to access its network resources – some Webified, others not. Until last year, the company typically spent six to 12 hours per vendor  – such as suppliers of medical billing and collections services – setting up an IPsec network connection for access but with the appropriate filters, Grant explains.

“Any time the vendor [or Sun Healthcare] made a change to its own network topology, we had to coordinate,” he adds. “Also, we had to worry about our liability if we passed a virus or other infection to another network.”

Meanwhile, the healthcare group employs more than 30,000 employees nationwide, but doesn’t have the budget to supply a company-owned laptop to each worker. And policy dictates that users’ own personal computers can’t be on the corporate network because of security risks.

The healthcare company finally discovered and deployed an SSL server solution from Permeo Technologies, which runs in the company’s DMZ as an application proxy server. The Linux-based platform provides a portal that all vendors and home users can visit as a Web site (without requiring client software or any special server at their remote locations). From there, users can launch an application based on their access rights.  Technically, they retain their own IP addresses and do not become part of the Sun Healthcare network, so they cannot put it at risk, Grant explains.

“There is no configuration on any routers and no software to install,” other than the server software in the Sun Healthcare network, which takes about an hour, Grant says. 

“A traditional SSL VPN would only let you use Web applications; this lets you launch any 32-bit application and tunnels the traffic through SSL,” Grant explains.

Sun Healthcare reports a drop in time spent on secure remote-access administration of 82%. Grant, for example, says the six to 12 hours of initial setup per vendor has been reduced to 20 minutes and that 32 hours of monthly maintenance have dropped to six. Also, users can now work from home, because their computers “are not truly on our network,” increasing productivity. 

Net6, a start-up in San Jose, has offered a similar SSL solution to Permeo’s that requires some client software. Net6 was acquired in December 2004 by remote-access company Citrix.

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author