Eliminating Data Security Risks for a publicly listed Healthcare provider.
Client Challenge
Potentially, a $50m problem!
Interlink was chosen by our client following an incident with their previous service provider that could easily have resulted in a significant data security breach.
The consequences of such a breach have increased significantly recently, given the passing of legislation in November 2022 by the Australian Parliament.
The maximum penalty for a repeated or serious privacy breach has since increased to the greater of:
• $50 million;
• three times the value of any benefit obtained through the misuse of information;
• 30 per cent of a company's adjusted turnover in the relevant period.
As a result, we had a very clear brief from our client:
• eliminate the IT asset disposal risk of healthcare data finding its way into the public domain
Our client also made it perfectly clear that simply wiping their HDDs – either on-site or at our facility – was something they could not accept.
Solution
After careful consultation and analysis, Interlink developed a 3-step process:
1. Deploy Interlink’s resources to our client’s capital city facilities to:
audit decommissioned devices,
remove and securely store all HDDs in lockable bins, and
remove all client asset labels and tags
2. Crush all decommissioned HDDs onsite, allowing for witnessed destruction
3. At the completion of steps 1. and 2. remove all devices and process for value recovery or environmental disposal
Interlink develops a unique process to meet the demanding requirements of one of Australia’s leading healthcare providers.
Result
We’ve utilised this process at multiple client sites around the country and are now working with our client to further refine the process to reduce costs while maintaining zero data security risk.
What the client said:
“Having had a disappointing experience with our previous vendor, we were very particular with our requirements when we went to market to select a new Asset Management Services provider.
While we were satisfied overall with the various responses we received, Interlink demonstrated that they were prepared to make numerous changes to their standard processes to accommodate our requirements, which include ensuring that no data-bearing devices leave our premises with their hard drives intact.
Their flexibility and willingness to listen ultimate made the difference, leading to us signing a national Master Services Agreement with them.”