Binzhou People’s Hospital data protection platform construction

 

Status of industry

Binzhou People's Hospital currently has multiple core business systems, including "HIS", "LIS", "EMR" and other medical business systems. The current application environment is mainly composed of multiple PC servers connected to the storage system through redundant optical fiber switches, forming a database server area and an application server area.
The current computer room in the old part of the People's Hospital was built in 2016. It has been constructed with a network architecture consisting of a core switching area, server area, terminal access area, security audit area, DMZ area, and Internet boundary area. The core switching area uses 2 H3C 12508 switches for core switching, and at the same time, 2 Shanshi Network Science core firewalls and IPS are used for protection. The terminal access area has nearly 1,600 internal network terminals, and they are equipped with Asin's anti-virus software. The security audit area conducts security audits of the hospital's business and network through database auditing, bastion host, access desktop system, anti-fraud system, log auditing system, and vulnerability scanning system.

 

Solution

Data protection from a technical perspective can include multiple security components such as secure operating systems, application systems, antivirus software, WEB firewalls, host monitoring and auditing systems, network monitoring, information auditing, security authentication, communication encryption, etc. Any single component alone cannot ensure the security of the information network. Network security is a dynamic and comprehensive system engineering. Therefore, it requires us to develop an excellent solution, which must be a comprehensive and three-dimensional solution. The security product deployment topology diagram of the overall hospital information security solution is as follows:

 

 

To build the most mature, reliable and forward-looking hospital information system infrastructure platform for the medical industry, and through this project, complete the overall construction of the data center of the West District of Binzhou People's Hospital, achieving the following goals:
Technological maturity: Widely applied in hospitals of the same industry and of the same scale;
Safe and reliable: The core business of the hospital must not be interrupted. We offer 7*24-hour uninterrupted service capabilities to achieve the highest level of business continuity.
Excellent performance: Provides high-speed data processing capabilities for core business systems, enhancing overall performance;
Disaster Recovery System: The disaster recovery system ensures that data is completely intact and enables business systems to recover quickly.
Advanced system architecture: Capable of meeting the future rapid development needs of Binzhou People's Hospital; meeting the hospital's business requirements in line with the three-level security protection standards, and providing a stable, efficient and flexible network security environment.

 

 

 

Scheme value

The platform’s multi-product collaborative defense, creating a deep and orderly personalized solution.

By conducting personalized demand analysis for each security domain of the hospital network, implementing targeted measures for protection, and achieving overall strategy coordination, a comprehensive adoption of products such as WEB application firewalls, bastion hosts, host monitoring and auditing systems, information auditing systems, intelligent network vulnerability assessment systems, and integrated centralized management systems for information security is carried out.

Advanced technologies, from the network layer to the application layer, from the terminals to the core HIS system servers, provide a comprehensive and three-dimensional coordinated defense for the hospital’s business network.

Meet various types of demands, achieve internal and external integration, and implement multi-level key protection. At the same time, combine with host terminal security protection products such as the internal network security management system to meet the requirements of comprehensive improvement of both internal and external aspects and overall coordinated defense. Fully support the hospital HIS system and business security.

Flexible expansion, continuous addition of security capabilities

Select products with excellent quality, providing comprehensive support for the informatization of hospital systems.

Provide a comprehensive three-dimensional defense system that covers both inside and outside, and from top to bottom.