Welvie is a health care decision-support company. Its platform offers online health education, data services, and consumer outreach to national and regional health insurance companies and third-party administrators (TPAs). Since Welvie was founded in 2008, security and compliance have become important considerations as expectations from clients and the growing threat environment increased.
With limited resources and a distributed workload, Welvie formed a dedicated team to oversee compliance and security. Their commitment to continuous improvement led them to establish a robust security and compliance program and pursue HITRUST Certification.
With their partnership with A-LIGN, Welvie has implemented technical controls and streamlined their processes to become a high-scoring organization within the HITRUST framework.
The Challenge: Seeking an Experienced Partner for Long-Term Growth
Prior to A-LIGN, Welvie worked with another Third Party Assessment Organization (3PAO) to achieve HITRUST Certification. However, after the initial certification, they searched for an assessor that could better serve their unique needs to fortify their compliance program, including:
- Extensive Framework Knowledge: Because Welvie started pursuing HITRUST Certification when it was still new, other third-party assessors did not have a comprehensive understanding of the framework that A-LIGN provides.
- Support in an Increasing Threat Landscape: With a heightened risk of attack in this digital age, Welvie needed a trusted assessor to help them bolster their security to comply with HITRUST CSF standards.
- Continuous Improvement: Welvie required a partner that fostered improvement and long-term growth through their assessments. Beyond a point-in-time assessment, Welvie wanted support throughout their compliance journey to achieve excellence for their security program.
We push each other to be better through this partnership. … Working with A-LIGN is a partnership. You’re not my vendor. You’re not somebody I tell what to do or you tell me what to do. You’re somebody who cares about my business.
Angela Loehr Merek
VP of Account Services
The Solution: Growing Together and Scaling Compliance
After researching other 3PAOs who had ample experience with HITRUST CSF, Welvie ultimately pursued a partnership with A-LIGN beginning in 2018. Welvie chose A-LIGN as their trusted HITRUST assessor due to A-LIGN’s established relationship with the certification body and deep understanding of the framework from hundreds of prior assessments.
HITRUST has fine-tuned and improved their framework to ensure evaluated entities are protected in the heightened threat landscape. As the framework evolves, companies undergoing HITRUST Certification are required to adjust their controls. A-LIGN assisted Welvie to ensure the correct and updated policies were implemented for Welvie to earn a high score on their assessment.
Throughout the relationship, A-LIGN has continuously improved its tools for understanding, collecting, and scoring evidence, resulting in assessment experiences that became more streamlined, faster, and easier over time. These tools have informed the development of A-SCEND, A-LIGN’s compliance management software, which Welvie has successfully leveraged in its last several assessments.
Welvie also found great value in A-LIGN’s close partnership with HITRUST. The HITRUST organization provides support, suggests improvements, and offers an open line of communication for customers undergoing certification. The A-LIGN team works closely with HITRUST by participating in committees, annual meetings, and workshops and keeping on top of the latest evolutions of the framework.
For example, when HITRUST announced the changes to its Measured and Managed assessment, many businesses were unsure how to proceed. Welvie consulted with A-LIGN to ensure they were prepared for the changes brought on by the new methodology and requirements. Because of A-LIGN’s knowledge and relationship with HITRUST, Welvie gained a competitive advantage in the field and developed a highly effective program to monitor, measure and manage Welvie’s security program.
As Welvie continues to partner with A-LIGN for their HITRUST Certification, they strive to ensure the proper controls are in place to comply with HITRUST CSF, strengthen their defenses against cyber-attacks, and serve as a mentor for small businesses looking to build their own compliance programs.
Welvie’s online decision-making programs My Surgery (surgery decision support), My Life Letters (advance care planning), and My Immunity Score (building stronger immunity health) help build health literacy — the ability for consumers to understand health information and services and use that knowledge to enhance their health. Their programs have been implemented across the country by health plans, large employers, and government agencies.