Identify technical and configurations exposures before they become exploited
Meditology employs a safe testing methodology designed from decades of experience penetration testing in healthcare. We have extensive experience coordinating technical testing with leading cloud service providers.
It’s rare that you deal with a vendor where everyone you deal knows their game.
From the first sales call onward, there was never a time where I thought anyone on the Meditology Team was less than excellent. Everyone knew what they were talking about and it made me feel good that they knew what they were talking about. No doubt they know the IT security space.
Particularly valued working with Meditology because of the expertise that has been brought to the questions we have.
We are a different beast as a university. Most vendors put us in cookie cutter mold, but you took time to understand how we were different and couched the assessment. That was valuable – making the product fit our work environment.
Everybody on the Meditology Team has been above-board and excellent to deal with and very responsive.
We get a bit of a different team each year but it’s always consistent, which is what I need as a practitioner.
Director of Information Security
Medical Center in the South
. . . . . . . . . . .
We learned there was an industry and Meditology benchmark and we were happy we had that data.
Meditology delivered on our ability to have a Roadmap going forward. For 10-15 years I have been involved in different clients and companies, and I like the Meditology SRA deliverable for the way the data was laid out and the graphics – was innovative.
I talked to Meditology last year, as they came highly recommended by other colleagues, and I wanted to bring Meditology in with our Executive Director.
I had a level of expectation when I brought the Team in. And I have not been disappointed. They are professional, very knowledgeable – and it’s very clear they know exactly what they are doing, what needs to be done, and have the content behind them to provide this service. You don’t have to worry about communication – they communicate and over-communicate.
The Meditology Team has been very responsive and very good.
We got an accurate and comprehensive assessment of our security risks and will use the deliverables as a “Roadmap.” The Team really knocked it out, all the interviews, evidence, got it all submitted – and the SRA Report is an accurate reflection of where we are.
Manager of Information Security
Large Not-for-profit Healthcare System, Health Plan, and Medical Group
The value in our multi-year partnership with Meditology is high.
Very valuable to our organization. Team members are very valuable. We had conversations around GRC and HIPAA and some of the recent court rulings. And this didn’t have to be provided as part of the Security Risk Assessment.
Manager of Information Security
Large Not-for-profit Healthcare System, Health Plan, and Medical Group
For what this effort was supposed to be, I thought it was good to have an outside perspective. Some internal teams may make assumptions and it is good to have an objective point of view. We learned a lot of useful insights from this whole effort and it was worthwhile. It gave us the perspective of changing our methods of assessing the practices which is valuable.
Very reassuring to see the information in the Meditology Security Risk Assessment report.
The Meditology Security Risk Assessment engagement was very well organized and presented us with information that was helpful for us to know, what our next steps should be, and our biggest security concerns. It’s very valuable to have an outside independent group do our security assessment because it’s hard to see where our own holes are.
We chose Meditology mainly for their demonstrated knowledge and understanding of HIPAA, ARRA/HITECH and established security standards.
They were unfailingly professional throughout the information gathering and data gathering processes, kept to their timeline and verified the results that they found. The reports produced were accurate and easy to understand, with appropriate benchmarking to other health care organizations and the security industry as a whole. Most importantly, they provided concrete and achievable suggestions to help mitigate the risks identified.
CISO, Baptist Memorial Health Care Corporation of Memphis, TN
We engaged Meditology to assist us with Security Risk Assessment services on two different occasions.
They were highly knowledgeable and extremely professional throughout the duration of each project, and the quality of the final deliverables they provided was exceptional. Meditology’s healthcare focus and core competency of Information Security and Privacy were indispensable to the engagement. Their deep knowledge of the HIPAA and HITECH regulations, as well as the Common Security Framework and supplemented by industry operational experience of their team members, added huge value to the assessment. Meditology was able to address significant risk areas in a straightforward manner and was able to provide practical examples and insight on how to go about correcting issues. We will definitely call upon Meditology again when the need arises.
Chief Technology Officer & CISO, Kelsey-Seybold Clinic
I was impressed with Meditology's team, the professional manner in which they interacted with our stakeholders, and the comprehensiveness of the final deliverable.
My original experience with Meditology was during a risk assessment at a different healthcare organization. I was impressed with Meditology's team, the professional manner in which they interacted with our stakeholders, and the comprehensiveness of the final deliverable. Upon joining Avanti, I saw the need for a similar, thorough review of our security controls and I immediately thought of Meditology for the job. Meditology's professionals completed the risk assessment with the same professionalism and quality as my first experience. Again, the team met my high expectations throughout the engagement and even went above and beyond the original contracted scope to assist with some last minute requests that provided additional value to me and the organization. I anticipate Meditology will continue to be a trusted adviser for my future security needs.
Meditology came to us recommended by our members and is well-respected in its service community.
As a health information exchange (HIE), we are a highly customer-focused organization – and we recognize this same orientation in a consulting partner. Meditology came to us recommended by our members and well-respected in its service community. They were readily able to evaluate our policy and security framework, and identify areas of key focus. We particularly appreciated their knowledge around HIPAA and our statewide HIE. With their help, we created an entire array of organizational policies. Meditology also conducted a security assessment that demonstrated we had appropriate safeguards in place for robust exchange. This has helped assure our member hospital/health systems, healthcare insurers, and ambulatory practices. Naturally, the effort has had an important influence on our service procedures. We look forward to continued work with Meditology for our consulting and ongoing risk-assessment needs.
Senior Director of Information Technology and Chief Information Security Officer, HealthShare Exchange of Southeastern Pennsylvania
Although the project had tight constraints, Meditology exceeded our expectations with high-quality deliverables completed on-time and on-budget.
One of NASCO's key controls for security management is the annual revalidation of security access to the primary claims processing system, to ensure appropriateness of access based on role. NASCO engaged Meditology to perform the security revalidation based on our prior, positive experience working with the firm's leadership and we are pleased we did. Although the project had tight constraints, Meditology exceeded our expectations with high-quality deliverables completed on-time and on-budget. Meditology also provided valuable guidance and suggestions for making the annual security access revalidation process more cost-effective and efficient.
Lauret Howard, SMP
Vice President, Strategy, Brand and Risk Management, NASCO
Onsite Health Diagnostics has relied on Meditology Services for HIPAA security risk assessment and penetration testing since 2014.
Meditology’s information security services have provided OHD’s customers and business partners with confidence in the seriousness with which we take the our responsibility to protecting their highly sensitive data. We have been more than pleased with Meditology’s professionalism, diligence and responsiveness, and we look forward to working with them for years to come. Since our founding, OHD has been dedicated to exceptional client service, providing stress-free employee health screenings and workforce health data analytics. Our clients, who include Fortune 500 corporations, hospital systems, financial institutions, state & local governments and small businesses alike, rely on OHD’s commitment to privacy and security when it comes to their employee health data.
Meditology worked hand in hand with our existing teams to perform a thorough analysis.
Meditology leads security-related events in the area. After hearing their expertise we decided to utilize their services for one of our annual risk assessments. Meditology worked hand in hand with our existing teams to perform a thorough analysis. I was impressed with their reviews of even our remote locations to not only conduct interviews but to verify what was truly in practice. Meditology conducted regular meetings with the security team to ensure timelines were on schedule and that we had a mutual understanding of the findings and status. I’ve worked with many companies over the years on these assessments and Meditology is not a group that just checks the boxes. Meditology has an intelligent staff that is up to date on the current regulations.
They have deep conversations on what is needed and why. They help you achieve your goals by aligning where you are today with where you want to be in the future and setting a course.
I am glad we decided to work with Meditology and create a partnership that aligns with our interests.
Director of Technology Services, Harbin Clinic Information Technology Services