sticky : sticky
Skip Navigation

How a Pharmacy Leader Protects Consumer Data with Sonatype

1200x628 - Graphics for Webpage CVS Health 2

When one of the largest pharmacies in the US set to make cybersecurity risk management critical to its business strategy, it needed a solution to protect the data of 120 million customers across millions of weekly digital interactions.

The Challenge: Securing Patient Data

Protecting these applications from malicious or vulnerable components that could compromise patient data while adhering to stringent HIPAA guidelines is just part of the challenge:

  • The development team performs approximately 600 application scans every day with the Sonatype platform at the heart of this continuous monitoring.
  • By constantly scanning its open source components, the DevSecOps team can stay ahead of any vulnerabilities and keep them from entering the development environment.

120 million

customers

to protect against data breaches

600

application scans

performed daily by dev team

The Solution: Sonatype Keeps Consumer Data Safe and Provides World-Class SCA

During healthcare plan open enrollment season, the customer implements a code freeze where they focus on shoring up the applications and systems they have in place while not introducing any new components or dependencies into the development environment. 

  • Sonatype Lifecycle and Sonatype Repository Firewall are critical to identify vulnerabilities in those daily scans.
  • The reports generated from the Sonatype platform are used to gain visibility into any vulnerable components and make decisions on how to prioritize remediation.
  • It’s imperative developers know what’s in their applications. Sonatype Lifecycle provides up-to-the-minute component analysis and confirmation that the software is risk-free.

The Results: Sonatype Can Help Development Teams Thrive in Large, Heavily-regulated Organizations

This organization manages a national network of thousands of pharmacies and hundreds of thousands of employees: 

  • This scale can present challenges when implementing change, even for the most progressive, technologically forward organizations.
  • The ability to respond quickly to vulnerabilities and remediate security issues can be hindered by antiquated systems or processes. 
  • Forward-thinking organizations, DevSecOps, and security teams increasingly spotlight the need for a security-centric workflow.