Skip to content
people-society-6-1200x675px

Region Jämtland Härjedalen

Success story - Healthcare

Gradient light yellow mesh

Every patient-record access accounted for using Governance for Healthcare

Compliance
Effectively monitors IT infrastructure and helps ensure compliance with the Swedish Patient Data Act
Transparency
Increases transparency by providing citizens quick and easy insight to information about the access and use of their medical records
Audit insight
Pinpoints unwanted and unintentional use of medical records, and helps improve user behavior via audit dashboards and log reports

The challenges

  • Rapidly increasing volume of sensitive patient data across digital systems
  • Rising number of users requiring access to medical records across the network
  • Growing risk of cyberattacks disrupting vital healthcare services
  • Legal compliance obligations under the Swedish Patient Data Act
  • Need-to-know access restrictions are operationally unsustainable in emergencies
  • Rigorous access audits required alongside broad information availability
  • Unintentional and accidental access violations require preventive measures
  • Audit data collection needed to identify trends and improve user behavior
bg-woman-phone-1221911038
"The Guardsix SIEM allows us to monitor the state of our infrastructure continuously and provides alerts if something out of the ordinary is occurring. In addition, it provides us with the necessary tools to drill down into an incident and to establish whether there is a technical problem, user error, or an actual breach of security."
Lars ChristersonInformation Security Officer, Region Jämtland Härjedalen
"Working with a mix of cluster sampling, predefined non-compliance rules, and dashboards showing aggregated outcomes, we get distinct views of the access patterns. The option to drill down in specific cases increases our ability to evaluate violations and anomalies and helps us understand user behavior. This allows us to improve our ways of working and help develop best practices for medical record platforms. In that way, Governance for Healthcare has helped us evolve from 'policing' users in a direction towards a quality improvement mission."
[ISO name]Information Security Officer, Region Jämtland Härjedalen
"Using automated rules for log filtering, we can reduce the number of false positives for potential breaches. Adding a severity level with rules can filter the incidents to identify and prioritize cases where a real violation has been found. That saves precious time."
[ISO name]Information Security Officer, Region Jämtland Härjedalen
"As security information was previously dispersed across multiple systems, and we had to manually sift through logs, analyzing data was previously a time-consuming and tedious job. Also, it was most often done in response to a problem and not proactively. This has changed as the Guardsix SIEM is automatically filtering and analyzing logs in real-time and alerting us of issues that require attention."
[ISO name]Information Security Officer, Region Jämtland Härjedalen
"Using Guardsix Governance for Healthcare to automate reports for specific target groups, we can deliver on specific needs. A great example is a patient requesting an access summary for his or her records. This data is now available for citizens through the public digital self-service portal 1177.se, allowing citizens to access their information online using their standard BankID login."
[ISO name]Information Security Officer, Region Jämtland Härjedalen
"We are looking into the potential of the Guardsix UEBA module and advanced machine learning to increase security by adding behavioral analytics to our security toolbox. We believe there is a huge potential in the data collection and analytics capabilities in the Guardsix solution that could potentially be used to improve patient safety or quality testing, which is an exciting perspective."
[ISO name]Information Security Officer, Region Jämtland Härjedalen

The Solution

Using Guardsix has increased transparency and reduced time spent on log reporting in Region Jämtland Härjedalen. Plans are made to add more log sources to get an even more granular view of security in the network.
"Using Guardsix Governance for Healthcare to automate reports for specific target groups, we can deliver on specific needs. A great example is a patient requesting an access summary for his or her records. This data is now available for citizens through the public digital self-service portal 1177.se, allowing citizens to access their information online using their standard BankID login." — Information Security Officer, Region Jämtland Härjedalen

The background

Region Jämtland Härjedalen is located in the middle of Sweden, bordering Norway to the west. With a population of around 127,000, it's one of the smallest among the 21 Swedish regions. But in terms of territory it's the third-largest. This makes for a region sparsely populated, characterized by large woods, mountains, and beautiful lakes, with almost half of the population living in the only major city Östersund.
The Region is responsible for the healthcare and dental care of the citizens in Jämtland Härjedalen and the primary medical facility is Östersund Hospital, the only hospital in the region. Approx. 3,000 employees work in the regional healthcare sector, and the Cambio COSMIC medical record system is one of the primary digital tools keeping health-related information of all citizens.
Gradient dark mesh

We protect what keeps society running

See how Guardsix can help your organisation protect patient data and ensure compliance.