Case Studies

How Virtual Hallway Successfully Completed Their ISO 27001 Audit

How Virtual Hallway Successfully Completed Their ISO 27001 Audit

At Carbide, we pride ourselves on enhancing our customers’ information security strategies through innovative solutions and expert guidance. We recently sat down with Dr. Jacob Cookey, Co-Founder & Chief Information and Privacy Officer at Virtual Hallway to discuss the benefits of working with Carbide. Virtual Hallway was created by doctors for doctors, focused on fostering collaboration among healthcare providers to streamline clinical knowledge exchange and enhance patient care by reducing waitlists.

Can you describe your role at Virtual Hallway and how it relates to managing the company’s information security?

I serve as the Chief Information and Privacy Officer at Virtual Hallway. This role requires balancing the business need to grow and respond to serving the healthcare needs of the populations that we serve while adhering to the highest industry standards of privacy and security.

What were the primary security challenges your organization faced before working with our platform and Advisory Team?

The initial challenge that motivated us to reach out to Carbide was the need to formally present the privacy/security controls we were employing in the form of a privacy impact assessment (PIA) for a health system we were working with at the time. From there, with our growth plans including other Canadian provinces as well as the US, we knew our privacy posture would continually require ongoing planning, tracking, documentation, review, etc. Carbide offered a team with knowledge and experience combined with a user-friendly platform to accomplish this.

Can you share any improvements in your business since working with us?

It would be difficult to estimate how much time was saved, but suffice it to say that it certainly allowed us to accelerate our growth as a company and to successfully complete privacy/security reviews with all of the partners, customers, and key stakeholders that we’ve worked with to date. Working with Carbide was also key to our success in our first ISO 27001 audit.

Which security frameworks, including ISO 27001, are most important for your operations, and how do they impact your day-to-day work?

Key frameworks that are most important to us include: PIPEDA, HIPAA, ISO 27001 as well as each of the provincial personal health information acts (e.g. PHIPA, PHIA, HIA, etc). Our day to day work is intimately tied to adhering to these frameworks.

What challenges did Virtual Hallway face during the ISO 27001 audit process, and how did Carbide’s platform and Advisory team help overcome them?

The ISO 27001 process was quite challenging and required very extensive and specific controls and documentation. Carbide’s platform and advisory team were an absolutely essential part of our ability to successfully complete the ISO 27001 audit. The support from the Carbide team has been tremendously valuable. The combination of high level knowledge of the privacy/security sector and friendliness and patience of all the Carbide team members we’ve interacted with, has been second to none.

Which features of the platform have been the most valuable for your team, and how have they improved your security operations?

For us, the supported policy development, the ability to implement staff privacy training and the platform’s auditor-view (to facilitate the auditing process) are the most valuable aspects of the platform. This has optimized our security operations while allowing our team to focus more time on business operations.

How has improving your information security through our platform impacted your business as a whole?

Improving our information security with the support of Carbide has allowed us to more quickly and efficiently communicate our privacy posture to our customers and partners. The fact that we take privacy and security so seriously has also enhanced the trust placed in us.

What advice would you give to other businesses that are considering partnering with Carbide for their security and compliance needs?

The sooner you choose to partner, the better. There will inevitably be elements of your privacy/security controls that you are not fully optimizing, or even some that you may be completely unaware of. You will also be pleasantly surprised with the efficiency that Carbide offers.

Share