Objectives
To implement a robust ISMS conforming to ISO/IEC 27001 that would provide a framework of security and trust at every level of the organisation: board, clinical operations, technology and members.
Healthcare
Implementation of an Information Security Management System based on ISO/IEC 27001 for Uruguay’s leading mobile emergency medical service, part of the country’s largest healthcare group.
Problem
In a sector as sensitive as healthcare, the confidentiality of clinical and personal information is not just another technical requirement: it is the basis of the relationship with the member. The institution wanted to consolidate that trust by strengthening its security infrastructure and practices, under an internationally recognised framework it could demonstrate to third parties.
Solution
We implemented an ISMS conforming to ISO/IEC 27001 covering clinical operations and supporting processes, sustaining the project through the unprecedented challenges of the COVID-19 pandemic, with teams working remotely and the operation under exceptional pressure.
Result
Certification achieved with no non-conformities at stage 2 of the initial certification audit —an uncommon result— and, beyond the certificate, an organisational culture in which information security became part of day-to-day operations.
Uruguay’s leading mobile emergency medical service is a benchmark in its sector and part of the country’s largest healthcare conglomerate. Its long-standing commitment to service levels for its members increasingly included the integrity and privacy of their data. The decision to certify did not come from a regulatory requirement but from a strategic choice: to demonstrate, with evidence auditable by an independent third party, that its members’ information is protected.
Objectives
To implement a robust ISMS conforming to ISO/IEC 27001 that would provide a framework of security and trust at every level of the organisation: board, clinical operations, technology and members.
Approach
Despite the restrictions imposed by the pandemic, the work focused on establishing policies, practices and tools aligned with the standard, with attention to every detail of the implementation. The risk analysis was carried out on the institution’s real processes, not on a generic model, and knowledge transfer to the internal team was part of the scope from day one: the system had to end up in the organisation’s hands.
Results
ISO/IEC 27001 certification was obtained with no non-conformities at the critical stage of the process. The real achievement, however, is the security culture that permeated the organisation and positioned it as a leader not only in care but in safeguarding its members’ information, being the first in its sector to gain that recognition in the country.
The project showed that with determination and focus it is possible to sustain a demanding process even in times of global uncertainty. Security does not end with a certificate: it is a promise of trust to members and to society.
It depends on the starting maturity and the scope, but a complete implementation and certification project in a healthcare organisation usually falls between nine and eighteen months, from the gap assessment audit to stage 2 of certification. In this case the project ran during the COVID-19 pandemic, with the team working remotely.
It means the external auditor found no breach of the standard’s requirements at stage 2 of the initial certification —neither major nor minor. It is an uncommon result: the usual outcome is to close the audit with some minor non-conformities that the organisation must resolve before receiving the certificate.
ISO/IEC 27001 is not a healthcare-specific standard, but its risk analysis and controls apply to the information assets the organisation defines within its scope, medical records included. In Uruguay it is complemented by Law 18.331 on personal data protection, which treats health data as sensitive data with reinforced requirements.
your business partner