How Memorial Hermann Health System keeps patient care running with always-on identity security

63k+

user accounts monitored and managed through ISPM

95%+

of active users secured by Adaptive Multi-Factor Authentication

200+

SaaS apps secured through Okta

50%+

of password reset-related IT tickets eliminated

“With ITP and ISPM, we’re shifting from reviewing at a point in time to real-time, continuous detection and response across our organization. They present all of the information we need upfront, so we can immediately tackle the issues at hand.”

Padma Sree Ventrapragada,

Director, Cyber Risk and IAM, Memorial Hermann

Access controls for medical professionals and hospital staff are a critical gateway for securing sensitive patient data. Memorial Hermann Health Systems (MHHS), a non-profit, community-owned health system based in Houston, Texas, understands that Protected Health Information (PHI) makes medical records a prime target for threat actors. With more than 63k users, including office staff, medical professionals, volunteers, students, and more across 11 hospitals, MHHS needs technology solutions that help deliver high-impact patient care without risking their data.

This approach to technology led MHHS to treat identity as a primary part of their security strategy. “All attributes of identity can cause material harm if they’re not properly managed,” says Zach Phillippe, deputy CISO. “Understanding what individuals can do, what they can see, and how they interact with our systems is just as valuable as any other form of cybersecurity.”

Implementing enterprise-grade security controls to protect patient data

As the organization has grown, its tech stack has grown with it, and with more than 200 software-as-a-service (SaaS) applications deployed across the system, the team needed a way to maintain visibility across these cloud-based apps. MHHS’s existing process involved scattered spreadsheets and manual access reviews, which were labor intensive and time-consuming. “We’re responsible for ensuring access controls are up to date,” adds Padma Sree Ventrapragada, director of cyber risk and IAM. “But when reviews were done manually, by the time we finished analyzing everything, we would have to start over.”

Meanwhile, as the app pool continued to expand, end user password reset requests were becoming more and more frequent. These reset requests became the IT support team’s primary task which diverted them from focusing on more complex problems. The MHHS team knew they needed an enterprise-ready identity partner designed to support on-premises and cloud-based identity management, help them support their complex organization, and provide user-friendly multi-factor authentication (MFA). “MFA is a top-five security control solution, and we knew Okta would help get it in place and close those gaps,” Phillippe says. 

Improving resiliency and day-to-day user protections

Okta is now a core pillar of Memorial Hermann's cloud resiliency strategy, ensuring that if their local network goes offline (due to a hurricane or cyberattack), clinicians can still access EMR data and keep patients safe. “Because of how Okta integrates with our systems, we have continuous identification and authorization that increases our resiliency,” Phillippe says. “That access directly impacts patient care. If a clinician has to resort to paper forms, they’re delaying care, so we have to be ready in both disaster states and our daily work.”

By combining foundational identity controls and ongoing monitoring and detection with a single identity partner, MHHS can more consistently deliver end-to-end security before, during, and after authentication. For MHHS employees, Single Sign-On, Adaptive MFA, and FastPass make access simple and secure from the moment they access a device, even for users in the system’s extended network. With 95%+ of active MHHS accounts secured by MFA, the organization can trust their most important systems are protected from phishing attacks.

The team has also implemented fully self-service password resets, regardless of location or affiliation with MHHS. Eliminating this bottleneck, coupled with other password adjustments, helped reduce service desk IT tickets by more than half, ultimately allowing clinicians to keep focused on their patients rather than access. 

Outside of their core employees, clinicians and staff at small, rural healthcare facilities, who also rely on MHHS’s Electronic Health Record (EHR) solution to run their offices, are secured through Okta. With FastPass, these otherwise independent practices can securely and consistently access patient information and other valuable data from different devices around their offices and ensure patients receive continuous care. 

With logins secured, the team could shift its attention toward building a way to continuously detect and remediate user risk. They found Identity Threat Protection (ITP) and Identity Security Posture Management (ISPM) would help move away from manual review processes to ongoing, real-time monitoring. “Beyond MFA, the solution that really changed the game for us was Identity Security Posture Management,” Phillippe says. “If you’re not using it, you’re looking for trouble.”

Shifting from continuous monitoring to “continuous healing”

While MHHS clinicians can stay focused on their patients, the MHHS security team is also refocusing their efforts on higher-impact projects. By replacing the manual spreadsheet audit process with a combination of ITP and ISPM, the team has built an automated, continuous identity detection and response system. This new approach leverages the advantage of a unified identity security fabric to give the team ongoing insights into the entire organization’s security posture. 

While ITP offers real-time threat detection and response that enriches Okta telemetry and remediates active threats, ISPM monitors for and helps address key gaps in their identity security hygiene. “With ITP and ISPM, we’re shifting from reviewing at a point in time to real-time, continuous detection and response across our organization,” says Ventrapragada. “They present all of the information we need upfront, so we can immediately tackle the issues at hand.” 

This combination is key to preventing any operational disruption. “If we have to divert care from our trauma centers because our infrastructure’s been hit by a cyberattack, there’s a material impact on human life,” says Phillippe. “The value of a tool like ITP is immeasurable for us because when our systems are safe, our patients are safe.”

Keeping the team’s attention on remediation rather than detection means that MHHS is able to close any potential security gaps the moment they appear, rather than relying on the next round of audits. Ventrapragada continues, “ISPM self-prioritizes, so we can solve complex issues that actually involve multiple lower-priority problems. Without it, we may have approached them one by one.” The shift in prioritization is helping the team identify and remediate issues faster than ever; identity hygiene work that once took a full work week or more to investigate across multiple tools is now just a few hours each week. 

Expanding automation to support secure AI agents for healthcare

As industries shift toward integrating AI agents into their workflows, MHHS sees the opportunity to assess and secure its infrastructure to bring these agents into care experiences. “It’s important for us to treat AI agents as a new identity class,” Ventrapragada shares. “As our identity partner, Okta already helps us discover and secure our human and our non-human identities, and we’re looking forward to how we can continue that relationship to secure AI.” 

In addition to monitoring and securing service accounts and AI agents, the team is looking at new ways to pair ISPM with Okta Workflows to automate their lifecycle management journeys. “ISPM catches identity gaps and Workflows can automatically fix them. Together, they’ll help us move from continuous monitoring to continuous identity healing,” Phillippe says. “And the Okta team has shown us that they care about us as partners. Not everyone has that, and we’re ready to find what else is possible together.”

About Customer

Memorial Hermann Health System (MHHS) is a leading integrated health system serving Southeast Texas. Managing access for 63k+ users requires securing diverse clinical and administrative personas, including employees, medical staff, and non-employees like residents and volunteers.

Continue your Identity journey