Configurable Role-Based Security to Protect Medicaid Data and Applications

The NYS DOH needed to provide users with secure online access to protected and sensitive healthcare data. To accomplish this, CMA sought to provide a solution within the Medicaid Data Warehouse.…

Business Case

The NYS DOH needed to provide users with secure online access to protected and sensitive healthcare data. To accomplish this, CMA sought to provide a solution within the Medicaid Data Warehouse. The following requirements were necessary: 

  • Highly configurable role-based security 
  • Full compliance 
  • Masked data/encryption algorithms
  • Online user provisioning 
  • Integrated security solution that is applied at both the application and database levels  

The Solution

CMA has decades of experience being the custodian of highly confidential information and the accompanying required system security. We recognize the sensitivity of the data entrusted to our care and accept the significant responsibility of safeguarding this data.  

CMA uses Oracle Identity Manager (OIM) to provide secure, single sign-on access for all users. OIM supports role-based access, authentication and authorization and provides the ability to effectively manage the end-to-end lifecycle of user identities across all enterprise resources, both within and beyond the firewall and into the cloud. 

Multi-factor authentication is enforced for all users upon sign-on. Once a user is successfully authenticated the CMA security solution utilizes Virtual Private Database (VPD) to further control data access by filtering the data from unauthorized users by implementing policy based security rules that prevent any data misuse. VPD ensures that users are only able to view data that they are authorized to see by providing the ability to restrict access at the table, column and/or row level. 

All security changes are configurable at the user level and applied at the database level, meaning the same security rules are applied regardless of the method the user is currently utilizing to access the data. 

Each user has a single set of security credentials that are passed with them as they navigate throughout the portal. A user who does not have access to member Social Security Numbers cannot view them whether they try to access that data via OBIEE or another analytical tool. 

To ensure that there is a standard “look-and-feel” and a consistent user experience, all prescribed components in the solution are deployed via a unified Web Portal.  The technology selected for the Web Portal is Oracle WebCenter Portal and includes content related to Data Access, Data Acquisition, Data Delivery, Managed Metadata Environment (MME), as well as social content such as Forums, Calendars, etc.  Using this unified topology ensures that the security requirements are applied consistently across all components of data collection and processing. 

Providing users with the appropriate level of access is critical, but equally as critical is ensuring users can be enrolled in both a secure and timely manner. CMA’s fully HITECH and HIPAA compliant online provisioning solution provides clients with a secure and efficient way to provision users, but also allows authorized individuals to change a user’s credentials in real-time to meet the ever-changing business needs of today’s business world. 

The Results

The NYS DOH gained a configurable role-based security solution that provides users with secure online access to protected and sensitive healthcare data.  

The solution operates at the application and data level and contains: configurable role-based security, a single sign-on web portal, dual factor authentication, all security applied at the database level, security propagated across all analytical tool result sets, users’ security credentials passed as they navigate throughout the portal, users’ security based on least privilege access (users only see what they have access to), and security applied at the tool, table, report, column, and row levels. 

Have a mission-critical program to modernize?