World News

Quest Diagnostics Fortifies Patient Data Privacy and Cybersecurity With Robust Safeguards and Ongoing Threat Mitigation Strategies

3BL | Wed, Dec 04 2024 06:10 AM AEDT

1695367561_650d4189d32c8_1692951951_64e8658fe70f4_breaking_news_600.png
Image Source: Sivastatz

Originally published in Quest Diagnostics' 2023 Corporate Responsibility Report

Safeguarding our patients’ data

Quest safeguards the privacy and security of our patients’ health information through policies, procedures, and by developing solutions to tackle emerging data security threats.

DATA PRIVACY 
We have a mature and effective privacy program that includes detailed privacy policies and procedures, training, auditing, and ongoing privacy awareness reminders. Our comprehensive program addresses a broad range of privacy subjects including protected health information disclosures, key privacy safeguards, and minimum necessary access to patient health information. These policies are available to employees on our intranet site. All employees undergo annual training on the Health Insurance Portability and Accountability Act (HIPAA). For both new and existing employees, we may provide more specialized privacy training based on an employee’s job function. In addition, the Company continues to review new regulations and state laws and implements required controls as needed.

CYBERSECURITY 
The strength and resilience of our cybersecurity and data privacy programs are critical in maintaining the trust of our patients, customers, employees, shareholders, and other stakeholders. Securing our business, customer, patient and employee data, and our information technology (IT) systems is an important part of our overall risk management framework. Quest’s cybersecurity program is overseen by the Chief Information Security Officer who reports to our Chief Information and Digital Officer.

Quest maintains a comprehensive cybersecurity program developed to align with best-practice frameworks, applicable laws and regulations, and our contractual obligations. We’ve designed the enterprise-wide program to secure our facilities and information systems and safeguard data throughout its lifecycle, including data provided to third parties performing services on our behalf. Our cybersecurity program incorporates standards, processes, and controls over a number of domains, including, but not limited to, governance, IT risk management, access controls, facility and data protection, IT systems and data transmission security, threat intelligence and incident response, supply chain risk management, disaster recovery, and vulnerability management.

Our cybersecurity risk management program monitors our systems and networks for threats, breaches, intrusions, and other vulnerabilities; assesses the security of our company-wide software, applications and systems; conducts security audits and threat assessments; responds to cybersecurity incidents; and facilitates training for our employees. We’ve also convened an IT Risk Council, with enterprise-wide representation, which receives quarterly and ad hoc updates on our cybersecurity efforts. Recognizing the interconnected nature of the healthcare industry, we prioritize supply chain security to mitigate the risks of third-party breaches. We assess the security posture of our vendors and partners with whom we interface, or who store, process, host, or transmit confidential patient and employee data or other confidential information.

Our cybersecurity program is based on multiple security frameworks, including, but not limited to, the National Institute of Standards and Technology’s NIST 800 Special Publication Information Security standard, MITRE 40 ATT&CK Framework, the Payment Card Industry Data Security Standard, the System and Organization Controls for Service Organizations 2, and International Organization for Standardization (ISO) 9001:2015 and ISO 15189.

Our cybersecurity program is continuously evolving to adapt to emerging threats, strengthen our security posture, and ensure the resilience of our services. Our Board of Directors oversees our cybersecurity via the Cybersecurity, Quality & Compliance, and Audit & Finance Committees.

Read more

PRNews

SKF to showcase innovative solutions at the Tech and Innovation summit

GOTHENBURG, Sweden, Dec. 4, 2024 /PRNewswire/ -- SKF to unveil a broad range of products and solutions to continue serving customers with ...

Cision | Wed, Dec 04 2024 08:28 PM AEDT

Read More
PRNews

Discovering the Scenic and Graceful Jiangnan:Zhejiang's Tourism and Cultural Splendor Celebrated in Kuala Lumpur

KUALA LUMPUR, Malaysia, Dec. 4, 2024 /PRNewswire/ -- On December 2, Kuala Lumpur played host to the Picturesque Zhejiang (Malaysia) Cultural and Tourism ...

Cision | Wed, Dec 04 2024 08:19 PM AEDT

Read More
PRNews

Digital asset adoption in APAC is almost three-times the global average, Consensus report finds

HONG KONG, Dec. 4, 2024 /PRNewswire/ -- Digital asset adoption in the Asia Pacific (APAC) region reaches 22% in 2024, almost three-times the global ...

Cision | Wed, Dec 04 2024 08:18 PM AEDT

Read More
PRNews

Trina Storage and TÜV NORD Release Comprehensive White Paper on Safety and Reliability in Energy Storage Systems

MUNICH, Dec. 4, 2024 /PRNewswire/ -- Trina Storage, the global leading energy storage product and solution provider, is pleased to announce the ...

Cision | Wed, Dec 04 2024 08:00 PM AEDT

Read More
PRNews

DUBAI WATCH WEEK'S 10TH EDITION OF HOROLOGY FORUM DEBUTS IN HONG KONG, CELEBRATING THE WORLD OF HOROLOGY IN THE HEART OF THE CITY

An array of panel sessions, masterclasses, curated timepiece showcase and in-depth interviews connects the horological community HONG KONG, Dec. 4, 2024 /PRNewswire/ ...

Cision | Wed, Dec 04 2024 07:45 PM AEDT

Read More