Raytheon Company, a defense giant known for developing Tomahawk missiles, is not just in the business of making high-tech defense devices. It also dabbles in health care.
Lexington, Mass.-based Raytheon, which also operates a unit in Portsmouth, has launched a new health-care application dubbed the RiskDoctor.
The application, similar to a doctor, doesn’t only figure out what hurts, it also figures out how to make the pain go away when it comes to being HIPAA compliant.
Seifert Systems Invests in Energy Efficiency to Strengthen Operations
For manufacturers, energy is more than just another operating expense. It plays a critical role…
Learn More
HIPAA (Health Insurance Portability and Accountability Act), the largest government actions in health care since Medicare, forces providers to protect confidentiality and security of health-care data. It also enforces improved health-care information delivery through electronic data.
RiskDoctor assesses a health-care company’s security risk through a security analysis of their internal systems and policies.
Steven Erd, manager of business development for Raytheon’s Intelligence and Information Systems unit in Virginia, said the application is built on a commercial, off-the-shelf engine.
“The RiskDoctor is used by our security professionals to do a snapshot of a (providers) current state,” he said. “Additionally, we have the ability to scan the system’s performance.”
The application then compiles a report that indicates which safeguards and requirements need to be in place. Once the RiskDoctor processes a report on the risks, it also helps the client with what it needs to do in order to ensure that it is HIPAA compliant.
For example, the RiskDoctor would work with a provider on its emergency operation plan. One example would be what it would do if it lost power.
“If your data was lost, how would you recover the data?” Erd said clients are asked. “We then provide hosting services to help them craft a plan.”
Raytheon’s application also quantifies a provider’s vulnerability. First it analyzes the annual loss expectancy and then provides the client with the right solutions.
The defense giant’s move into health care may be atypical, but it made sense for the company, executives said.
“Raytheon has been very involved in information security for decades and already does work for the Department of Health and Human Services,” said Erd. “When the HIPAA security rules were published, it made perfect sense for us to combine our health care and security knowledge.”
Mary Walker, vice president of business development for Raytheon Information Solutions’ emerging health-care practice, said the company has had a history of taking core technology and applying it in the medical and health-care environment.
“If you look at health care, it is the stepchild to technology,” Walker said.
Raytheon’s core technology, for example, has been used in other applications including telemedicine/telehealth.
The company has a contract with a state prison system to allow doctors to treat and view the data of patients in a state penitentiary.
“It saves the state a lot of money by rather than transferring a sick patient from one place to another, they use the satellite technology to look at patients in the prison,” Walker said. “If they need to do a radiology image, they can shift it back and forth.”
All of the work in health care has prompted the company to develop a health-care practice. Once a practice is in place, Walker said the company plans to open a separate business unit.
“Raytheon has been methodical about how they do these things,” she said. “We have a health-care practice that is evolving. We’re going to chip away at the market.”
Locally, Polar Cove, a Providence-based security consulting business, is also assessing how health-care providers fare in compliance.
Erik Petersen, chief technical officer at Polar Cove, said it’s his job to help find out what the vulnerable landscape of a business is by providing both consulting and risk assessments.
“You can’t build a project roadmap to compliance until you at least find out how vulnerable of a landscape you have,” Petersen said.
Petersen’s company is reaching out to hospitals to make them aware of their vulnerabilities when it comes to HIPAA’s security regulations.
Health-care providers must have systems and procedures in place to protect a patient’s medical records and data.
“Most hospitals have no idea (where to start),” Petersen said. “They have to get on the ball. Security is difficult to do on its own and when you marry it with compliance, it becomes a two-headed beast.”
Polar Cove said its risk assessment doesn’t involve a lot of software but it does require a lot of on-site consulting.
First, Polar Cove scans and runs a few technical security checks on a hospital’s existing enterprise system. Consultants then analyze management controls by sitting down with a company’s CIO, CFO and records department. Polar Cove then provides the hospital consulting on policy, procedures and training.
“We give them a very detailed report and in some cases we have followed on with training and implementing point solutions such as firewalls,” Petersen said.
For the complete current issue, visit our subscription Web site, or call (401) 273-2201, ext. 227 or 234.












