Federally Qualified Health Center network, multiple NYC sites with 200+ staff
Identity and endpoint consolidation across an FQHC network
- Challenge
- Legacy IT left the FQHC with overlapping identity systems, shared workstation logins at patient-intake terminals, and inconsistent endpoint encryption. A state grantor review flagged deficiencies against HIPAA Security Rule and SHIELD safeguards.
- Outcome
- Single consolidated identity plane with per-user authentication at every workstation, full-disk encryption enforced across all endpoints, role-based access tied to clinical vs. administrative function, and HIPAA + SHIELD documentation produced for the follow-up grantor review. Review closed without further findings.
