Customer Snapshot: Healthcare

Blue Cross and Blue Shield of Kansas City

Large Health Insurer Simplifies Processes and HIPAA Compliance with Sun Identity Management Service

Blue Cross and Blue Shield of Kansas City (BCBSKC) is the area’s largest provider of health benefits, serving nearly 900,000 members in 32 counties in northwest Missouri and Kansas. The organization has approximately 1,000 employees.

Customer Challenges

  • Implement identity management solution quickly to replace non-working system
  • Meet HIPAA regulations
  • Demonstrate compliance through an audit trail

Solution

Sun Professional Services used best practices and proven methodologies to deliver an identity management solution and related services to Blue Cross and Blue Shield of Kansas City, allowing it to rapidly deploy an automated solution to satisfy HIPAA regulations and establish an audit trail.

Business Results

  • Deployed complete identity management solution in four months
  • Achieved faster time to value with rapid implementation
  • Demonstrated compliance with HIPAA and other regulations with minimum amount of staff time
  • Gained greater flexibility in making changes to role definitions
  • Automated tracking of workflow for approvals and changes
  • Improved control of software licensing fees by limiting role proliferation
  • Reduced administration time to manage identities and assets
  • Decreased contractor technical support and IT staff costs
  • Improved ability to meet internal SLAs

Story Details

From a small group hospitalization plan run by two employees in 1938, what is now Blue Cross and Blue Shield of Kansas City (BCBSKC) has grown into a complex organization with 1,000 employees offering multiple services to nearly 900,000 people. To support its employees, satisfy regulatory requirements of the Health Insurance Portability and Accountability Act (HIPAA) and demonstrate compliance through an audit trail, BCBSKC decided to replace its manual processes for managing identities and IT assets with an automated identity management system.

After looking at competing technologies from IBM and CA, the health insurer chose a solution from Waveset Technologies, Inc. (later acquired by Sun) to ensure that it provided the minimum necessary access to systems and applications in accordance with HIPAA constraints. After implementation with a third-party systems integrator proved unsuccessful BCBSKC was forced to temporarily return to the cumbersome manual processes.


" Sun Java System Identity Manager is an elegant solution. It’s a very intuitive product. The integration with Sun Velocity Identity Deployment Tool, the expertise of Sun Professional Services and their deep involvement in our development process have created a high level of trust. "
— Norma McKelvy, Corporate Privacy and Security Officer, Blue Cross and Blue Shield of Kansas City

Sun was able to provide a much-needed way out by offering Sun Java System Identity Manager 7.0 with the Sun Velocity Identity Deployment Tool (formerly Neogent VIP), which is a suite of services that enables rapid deployment of Sun identity management solutions. Combined with Sun’s experience, best practices and proven methodologies, the tool provides implementation services based on the most common cases within enterprise environments. BCBSKC selected Sun Java System Identity Manager because of its integration capability with Oracle PeopleSoft applications, the workflow engine and the solution’s many easy-to-install adapters.

Engineers from Sun Professional Services and Neogent worked closely with BCBSKC’s IT staff and managers to frame the organization’s needs, review its business processes and implement the solution in two phases. In phase one, lasting 10 weeks, Sun implemented Identity Manager for Oracle PeopleSoft, Microsoft Active Directory and Microsoft Exchange, enabling BCBSKC to automate identity management and asset provisioning and deprovisioning for new hires and employee terminations. In phase two, lasting six weeks, Sun implemented bi-level roles-based access control (RBAC), which gave the health insurer the ability to efficiently manage its nearly 700 business and functional roles.

Once completed, BCBSKC could easily manage identities and assets related to employment transfer and non-employee/contract positions. Key BCBSKC personnel participated in a week-long “boot camp” from Sun Learning Services to learn how to manage the system. BCBSKC also has a SunSpectrum Support contract to assist with maintenance and troubleshooting.

With the Sun Identity Manager solution deployed in just four months, BCBSKC has realized a fast time to value. Integration with the PeopleSoft platform ensures that the organization’s human resources system remains the authoritative source of employee and assets data. Department managers can easily provision and deprovision assets and manage employee identities, as well as request additional assets or access. Identity Manager automatically tracks the approval process and sends out e-mail notifications of the next steps involved in the workflow, helping BCBSKC to maintain HIPAA compliance while minimizing the administrative burden.

Identity Manager is delivering hard savings, too. Use of the Sun Bi Level RBAC service helps the organization keep a lid on software licensing fees by limiting the “laundry list” of assets that a department can provision. Contracted technical support and IT staff costs have decreased. With automated provisioning, the health insurer expects to meet its internal three-day service-level agreement for provisioning and deprovisioning assets, thereby improving employee productivity.

BCBSKC will streamline some of its ticketing and notification processes and plans to install adapters for IBM AIX, Microsoft SQL Server and Sybase Adaptive Server to simplify identity and asset management for users of those systems. In the long-term, BCBSKC may broaden access to Identity Manager in line with its self-service mantra. Now and in the future, the health insurer has a flexible and efficient system that will keep it HIPAA-healthy and business-efficient.

  
 
Interested in Sun's Open Storage?
Download this paper today to learn about the tools, trends and key features of Sun's Open Storage solutions.