Epic Monitoring with SCALR XDR

Are you protecting your “crown jewels?”

Electronic Medical Records (EMR) solutions contain a healthcare organization’s most critical and sensitive patient data. However, these EMR systems are rarely monitored, and there is often no regular review of the system for security events. This puts the most important data source in your organization at risk and can potentially lead to data breaches, unauthorized access, and other security incidents that could compromise patient privacy and the integrity of the medical records.

SCALR XDR Epic Monitoring provides:

 

24x7x365 Monitoring of Epic Security Events

SRA will perform 24x7x365 real-time monitoring of your Epic platform, forwarding your relevant security logs to the Sentinel SIEM. Our team of security incident analysts will correlate and investigate potential incidents.

Data Lake Integration

SRA will integrate your Epic E1M SIEM logs into Azure Data Explorer, with a subset curated for analysis inside of Azure Sentinel. This intelligent routing gives you the freedom to investigate all of your Epic logs in a centralized location while optimizing your SIEM storage and reducing costs.

SOAR Automation

SRA will configure Security Orchestration, Automation, and Response (SOAR) automations to facilitate efficient and effective initial triage and escalation processes. This automation ensures that all escalations are managed promptly, providing a swift response to any potential security events.

Contact us here to discuss adding Epic Monitoring to your SCALR XDR service:

Epic Detection Rules

SRA develops and maintains a library of detection rules for the Epic system which will be configured into the SCALR™ XDR monitoring. Examples of these rules include:

N

Identify password spray on MyChart

N

Volumetric Glass Breakage

N

Admin User Password Resets

N

Glass Break Rejections

N

SAML Cert Failure

N

MyChart Activity Threat Intel Match

N

Excessive MyChart Username Recovery Failures

N

Excessive MyChart Authentication from a single IP address

N

Adversary in the Middle (AITM) Attack

N

MyChart Server Admin Elevation Failure