The Healthcare Team in Brodnica – the hospital operates according to a clearly defined mission, which is as follows: providing comprehensive and professional health services using the latest diagnostic and treatment methods, nursing, and rehabilitation, focused on the needs and expectations of patients to ensure health security for the residents of Brodnica County and all other individuals within the hospital’s operating area, based on the principle: YOUR HEALTH – OUR MISSION.
In line with this mission, the hospital carries out tasks aimed at maintaining, saving, restoring, and improving health.
Facts and figures
Full name
Zespół Opieki Zdrowotnej w Brodnicy
Industry
Hospital
What did the client expect?
ZOZ Brodnica was seeking consultants to conduct an audit of their information system’s security. The audit needed to be performed in compliance with the provisions of the National Cybersecurity System Act (KSC). The client required that the project be executed dynamically, while maintaining operational continuity and not disrupting the ongoing activities of the organization. Therefore, they needed the support of an experienced external company that had already completed similar projects. The choice fell on PBSG. Our offer was selected due to, among other factors, numerous references and a scope of work tailored to the organization’s specific needs.
The selection process was based on public procurement rules and was preceded by extensive consultations and an analysis of the consulting market in Poland. The project was completed in 2023.
What did we do?
WE ADJUSTED THE SCHEDULE
We tailored the scope of work and the schedule to the specifics of the organization. The entire project was divided into logical steps that, on one hand, ensured efficient and fast execution, and on the other, did not disrupt the ongoing operations of the unit.
WE ANALYZED THE CURRENT STATE
First, we took a close look at the current state of the organization in terms of information security. We conducted an analysis that allowed us to identify the systems and infrastructure necessary for the uninterrupted provision of the critical service.
WE CONDUCTED THE AUDIT
After reviewing the organization’s resources to ensure compliance with the organizational and technical requirements of the critical service operator, we provided recommendations for updating the documentation and optimizing security tools.
WE PREPARED THE DOCUMENTATION
After the recommendations were approved, we focused on updating, completing, and optimizing the documentation. As a result, the client gained formal and procedural support to help ensure the proper level of information system security.
What were the results?
The task was to align the organization with the requirements of the KSC Act in accordance with the standards adopted by the organization, along with the preparation of documentation. The service was delivered in line with the established schedule and plan.
We efficiently built the organizational and technical capabilities required by the regulation to ensure the proper level of information security for the information system. The entire work was focused on ensuring the security of processed information at the group level and raising the level of cybersecurity throughout the organization.
Worth highlighting, thanks to the project, ZOZ Brodnica reduced the operating costs of the information security management system by 40%. Additionally, the hospital improved its cybersecurity control processes, which is crucial for organizations operating in the healthcare sector, benefiting both the organization and its patients.
What did the client gain?
Compliance with the requirements and obligations outlined in the Act on the National Cybersecurity System.
Optimization of security tools for maintaining business continuity in healthcare processes.
A 40% reduction in the operating costs of the information security management system.
Increased awareness of staff regarding information security and cybersecurity.
Required documentation that defines responsibilities, procedures, and risks that may disrupt the provision of critical services.