Health Insurance Providers:
See how a peer reduced the costs and risks associated with their member & operational data
Book an Intro Call
Results achieved from Classify360’s content-level data classification:
Reduced Data Footprint
Historical data cleanup resulted in the deletion of 400+ million operational files and archiving of over 1 billion files, reducing your peer’s data footprint by 17%.
Minimized Future Security Risks
Risk reduction achieved by moving member data older than 5 years off-network while the deletion of unnecessary operational files reduced exposure surface.
Achieved Ongoing Governance & Compliance
Ongoing retention policies with automated workflows ensure that compliance is maintained for newly created data and that data is kept in a clean state.
BACKGROUND:
The health insurance customer suffered a substantial data security event exposing members’ personal data and yielding significant HIPAA violation fines. Required to take corrective action through the implementation of a data analysis and risk management plan, the customer deployed Congruity360’s Classify360 solution to discover, understand, and protect their stored data while remaining HIPAA-compliant.
THE SOLUTION:
AirGap – Protect Member Data from Security Risks
Client was required to retain member data for 11 years per industry regulations, however only 5 years of member data is accessed on a regular basis. Congruity360’s Classify360 identifies, classifies, and moves member data aged beyond 5 years to a second data center via Congruity360’s secure AirGap. Should a security event within the customer’s network occur again, older, rarely accessed member data would not be impacted.
If files stored in the AirGap data center are required for legal purposes, they are securely returned to the customer’s network with no interruption to business operations
Additionally, Classify360 is able to delete all member records over 11 years old in an automated and monitored remediation process.


Classify360 – Reduce Costs & Risks of Operational Data
Classify360 platform governs remaining day-to-day business-generated data, much of which resides on on-premise systems. Classify360 implements customer data workflows to classify operational data into one of four categories:
Protected Data – medical history, PPI and similar
Proprietary Data – financial, legal, company-sensitive, or critical information
Internal Data – non-critical and non-sensitive information
Public Data – publicly available information
Data stewards review the results of each classification workflow, determine which actions to take – migrate, archive, preserve, or defensibly delete data – within a monitored and reportable regulatory compliance framework.
