Skip to content
Notifications
Clear all

BeyondTrust vs Delinea for a 2000-user hospital - compliance and audit

1 Posts
1 Users
0 Reactions
6 Views
(@harryk)
Trusted Member
Joined: 1 week ago
Posts: 60
Topic starter   [#19875]

Hello everyone,

I've been tasked with leading the evaluation of a new Privileged Access Management (PAM) solution for our healthcare network, and I'm hoping to tap into the community's collective experience. We're a ~2000-user organization with a mix of on-premises systems, cloud-hosted applications, and a vast array of medical devices and clinical systems. Our primary drivers are not just operational efficiency, but the heavy compliance burden from HIPAA, HITRUST, and potentially PCI-DSS for certain areas.

While we've narrowed the field to two primary contenders—BeyondTrust and Delinea (specifically their Secret Server platform)—I'm finding that the high-level feature checklists from vendors often gloss over the gritty realities of deployment and daily governance in a high-stakes, auditor-scrutinized environment like ours.

I'd be particularly grateful for insights from those who have implemented either solution in a similar regulated context. My key concerns are:

* **Audit Trail Granularity & Integrity:** In a breach investigation or during an external audit, how defensible are the logs? Can you easily trace a privileged action on a critical system (like an EMR database server) back through the PAM system with immutable proof? I'm worried about gaps in session recording for non-standard clinical applications.
* **Compliance Reporting Burden:** How much manual work is required to generate compliance reports for frameworks like HITRUST? Do the solutions offer pre-built report templates or dashboards that map directly to control requirements, or is it a constant customization exercise for your team?
* **The "Just-in-Time" Access Reality:** Both vendors tout just-in-time privilege elevation. In practice, for a busy hospital IT/clinical engineering team, how disruptive is this workflow? Have you seen pushback from staff accustomed to standing privileges, and how did you manage the change?
* **Ephemeral Account Management:** Handling service accounts for medical device integrations is a nightmare. How well does each platform handle the automatic rotation of credentials for these sensitive, often embedded, accounts without causing outages?

We're leaning towards a phased rollout, starting with IT admins and then moving to clinical systems. Any wisdom on pitfalls during this transition, or unexpected costs (beyond licensing) related to compliance-specific configurations would be invaluable.

Looking forward to a constructive discussion.

— Harry


Architect first, buy later


   
Quote