Linux Containers Authors: Pat Romanski, Lori MacVittie, Elizabeth White, Flint Brenton, Jim Kaskade

Related Topics: Linux Containers

Linux Containers: Article

Catholic Healthcare West Reduces Costs with Standardized Identity Management

Standards-based Linux-hosted directory services displaces Microsoft Active Directory

With more than 40 locations, Catholic Healthcare West was managing user identities across hundreds of applications running on multiple platforms. A streamlined identity management solution running on Linux has increased security and improved regulatory compliance, while dramatically reducing costs.

Catholic Healthcare West (CHW), headquartered in San Francisco, is the eighth largest hospital system in the nation and, with more than 9,500 beds, the largest not-for-profit hospital provider in California. The CHW network of more than 7,500 physicians and approximately 40,000 employees provides quality healthcare services for more than four million patient visits annually.

As with many healthcare organizations, many of Catholic Healthcare West's facilities had locally developed information systems and software. As a result, it was managing disparate systems and platforms across 40 hospitals and medical centers. Each location also had its own way of managing network access and user identities for nearly 1,400 applications.

To streamline IT operations, CHW wanted to move away from proprietary platforms and create a standardized, open environment. The organization also wanted to create a standard approach to identity and access management that would increase security and meet regulatory requirements, while still giving physicians and staff fast access to applications.

After thorough research, including talking to many customers who had implemented identity management across a large enterprise, Catholic Healthcare West selected a Novell identity and access management solution to run on SUSE Linux Enterprise Server.

"A solution based on open standards fits our model of doing business," said Eric Leader, chief technology architect for Catholic Healthcare West. "Healthcare procedures are not proprietary, and information concerning how best to meet the needs of our patients is freely shared among caregivers. Because we work in an open community, it makes sense for us to have an open environment."

CHW consolidated all of its directories and migrated its Windows NT domains to Novell eDirectory to manage 20,000 user identities. Novell Identity Manager synchronizes user identity information across applications running on multiple platforms including Microsoft Windows, Linux, and multiple versions of Unix.

"Many of our applications require Microsoft Active Directory, but we were uncomfortable standardizing on a proprietary platform," Leader said. "Novell eDirectory supports open standards and allows us to manage identities across our diverse environment."

With centralized identity management, CHW can provision users three times faster, giving them immediate access to the applications they need. Users even have a single ID and password for many applications that are integrated with eDirectory. CHW will also be using Novell SecureLogin to give users single sign-on access to applications that are not LDAP-enabled.

Centralized identity management has greatly improved the organization's overall security and ability to comply with HIPAA, Sarbanes-Oxley, and other regulatory requirements. Using Novell Audit, CHW can conduct timely audits to track who is accessing information and when. The IT staff can also immediately revoke network access when employees leave the organization.

"We operate in a highly regulated environment where the requirements are always changing," Leader said. "We simply had to consolidate identity management or we would see a huge increase in time spent managing regulatory issues. The identity and access management solution provided by Novell helps us stay ahead of the curve."

CHW runs its Novell identity management solution on 30 SUSE Linux Enterprise Servers and HP hardware, and also runs several mission-critical systems on Linux, including Oracle databases, software distribution, claims management, and digital image archives.

"Microsoft licensing became too burdensome, so we looked for lower-cost alternatives and found that many of our large vendors were providing support for Linux and open source," Leader said. "As we purchase new software, we look for vendors who run on Linux. Eventually, we would like to run our entire organization on Linux."

A solid disaster recovery strategy is also an integral part of HIPAA compliance. With SUSE Linux Enterprise Server, CHW is implementing redundant systems faster and at a lower cost than with proprietary platforms.

"The flexibility we have with SUSE Linux has exceeded our expectations," Leader said. "There is no way we could keep up with rapid change if we continued to manage proprietary platforms. We now have a cost-effective way to remain compliant and maintain high availability."

With a Novell identity and access management solution, Catholic Healthcare West centralized identity management across its diverse enterprise and reduced initial user administration time by 70%. The organization has increased security with role-based access, auditing capabilities, and streamlined provisioning and deprovisioning to immediately grant or revoke access.

"Before implementing the Novell solution, we provisioned users in a hundred different ways," Leader said. "We didn't think we could streamline this process without substantially increasing our staff. With the Novell solution, we have a high-quality, yet cost-effective solution that actually frees up much of our staff to work on other projects."

Running SUSE Linux Enterprise server has improved performance for several mission-critical systems, while significantly reducing hardware costs and reducing server administration time by 25%. The organization anticipates an estimated cost savings of $1.5 million.

"Novell's support for Linux has been excellent," Leader said. "We've now moved Linux from a hypothetical idea to a mission-critical platform in our organization."

More Stories By Linux News Desk

SYS-CON's Linux News Desk gathers stories, analysis, and information from around the Linux world and synthesizes them into an easy to digest format for IT/IS managers and other business decision-makers.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.

@ThingsExpo Stories
SYS-CON Events announced today that Transparent Cloud Computing (T-Cloud) Consortium will exhibit at the 19th International Cloud Expo®, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. The Transparent Cloud Computing Consortium (T-Cloud Consortium) will conduct research activities into changes in the computing model as a result of collaboration between "device" and "cloud" and the creation of new value and markets through organic data proces...
In the next five to ten years, millions, if not billions of things will become smarter. This smartness goes beyond connected things in our homes like the fridge, thermostat and fancy lighting, and into heavily regulated industries including aerospace, pharmaceutical/medical devices and energy. “Smartness” will embed itself within individual products that are part of our daily lives. We will engage with smart products - learning from them, informing them, and communicating with them. Smart produc...
SYS-CON Events announced today that Enzu will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Enzu’s mission is to be the leading provider of enterprise cloud solutions worldwide. Enzu enables online businesses to use its IT infrastructure to their competitive advantage. By offering a suite of proven hosting and management services, Enzu wants companies to focus on the core of their online busine...
WebRTC adoption has generated a wave of creative uses of communications and collaboration through websites, sales apps, customer care and business applications. As WebRTC has become more mainstream it has evolved to use cases beyond the original peer-to-peer case, which has led to a repeating requirement for interoperability with existing infrastructures. In his session at @ThingsExpo, Graham Holt, Executive Vice President of Daitan Group, will cover implementation examples that have enabled ea...
SYS-CON Events announced today that Coalfire will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Coalfire is the trusted leader in cybersecurity risk management and compliance services. Coalfire integrates advisory and technical assessments and recommendations to the corporate directors, executives, boards, and IT organizations for global brands and organizations in the technology, cloud, health...
In past @ThingsExpo presentations, Joseph di Paolantonio has explored how various Internet of Things (IoT) and data management and analytics (DMA) solution spaces will come together as sensor analytics ecosystems. This year, in his session at @ThingsExpo, Joseph di Paolantonio from DataArchon, will be adding the numerous Transportation areas, from autonomous vehicles to “Uber for containers.” While IoT data in any one area of Transportation will have a huge impact in that area, combining sensor...
November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Penta Security is a leading vendor for data security solutions, including its encryption solution, D’Amo. By using FPE technology, D’Amo allows for the implementation of encryption technology to sensitive data fields without modification to schema in the database environment. With businesses having their data become increasingly more complicated in their mission-critical applications (such as ERP, CRM, HRM), continued ...
SYS-CON Events announced today that Cloudbric, a leading website security provider, will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Cloudbric is an elite full service website protection solution specifically designed for IT novices, entrepreneurs, and small and medium businesses. First launched in 2015, Cloudbric is based on the enterprise level Web Application Firewall by Penta Security Sys...
WebRTC sits at the intersection between VoIP and the Web. As such, it poses some interesting challenges for those developing services on top of it, but also for those who need to test and monitor these services. In his session at WebRTC Summit, Tsahi Levent-Levi, co-founder of testRTC, reviewed the various challenges posed by WebRTC when it comes to testing and monitoring and on ways to overcome them.
"Matrix is an ambitious open standard and implementation that's set up to break down the fragmentation problems that exist in IP messaging and VoIP communication," explained John Woolf, Technical Evangelist at Matrix, in this SYS-CON.tv interview at @ThingsExpo, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
In his general session at 18th Cloud Expo, Lee Atchison, Principal Cloud Architect and Advocate at New Relic, discussed cloud as a ‘better data center’ and how it adds new capacity (faster) and improves application availability (redundancy). The cloud is a ‘Dynamic Tool for Dynamic Apps’ and resource allocation is an integral part of your application architecture, so use only the resources you need and allocate /de-allocate resources on the fly.
DevOps is being widely accepted (if not fully adopted) as essential in enterprise IT. But as Enterprise DevOps gains maturity, expands scope, and increases velocity, the need for data-driven decisions across teams becomes more acute. DevOps teams in any modern business must wrangle the ‘digital exhaust’ from the delivery toolchain, "pervasive" and "cognitive" computing, APIs and services, mobile devices and applications, the Internet of Things, and now even blockchain. In this power panel at @...
SYS-CON Events announced today that SoftNet Solutions will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. SoftNet Solutions specializes in Enterprise Solutions for Hadoop and Big Data. It offers customers the most open, robust, and value-conscious portfolio of solutions, services, and tools for the shortest route to success with Big Data. The unique differentiator is the ability to architect and ...
SYS-CON Events announced today that Embotics, the cloud automation company, will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Embotics is the cloud automation company for IT organizations and service providers that need to improve provisioning or enable self-service capabilities. With a relentless focus on delivering a premier user experience and unmatched customer support, Embotics is the fas...
SYS-CON Events announced today that MathFreeOn will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. MathFreeOn is Software as a Service (SaaS) used in Engineering and Math education. Write scripts and solve math problems online. MathFreeOn provides online courses for beginners or amateurs who have difficulties in writing scripts. In accordance with various mathematical topics, there are more tha...
SYS-CON Events announced today that Niagara Networks will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Niagara Networks offers the highest port-density systems, and the most complete Next-Generation Network Visibility systems including Network Packet Brokers, Bypass Switches, and Network TAPs.
The best way to leverage your Cloud Expo presence as a sponsor and exhibitor is to plan your news announcements around our events. The press covering Cloud Expo and @ThingsExpo will have access to these releases and will amplify your news announcements. More than two dozen Cloud companies either set deals at our shows or have announced their mergers and acquisitions at Cloud Expo. Product announcements during our show provide your company with the most reach through our targeted audiences.
@ThingsExpo has been named the Top 5 Most Influential Internet of Things Brand by Onalytica in the ‘The Internet of Things Landscape 2015: Top 100 Individuals and Brands.' Onalytica analyzed Twitter conversations around the #IoT debate to uncover the most influential brands and individuals driving the conversation. Onalytica captured data from 56,224 users. The PageRank based methodology they use to extract influencers on a particular topic (tweets mentioning #InternetofThings or #IoT in this ...
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, will discuss how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team a...
Virgil consists of an open-source encryption library, which implements Cryptographic Message Syntax (CMS) and Elliptic Curve Integrated Encryption Scheme (ECIES) (including RSA schema), a Key Management API, and a cloud-based Key Management Service (Virgil Keys). The Virgil Keys Service consists of a public key service and a private key escrow service.