Epic Systems is the leading Electronic Health Record (EHR) platform used by healthcare organizations across the country. While large hospital systems can afford to implement Epic directly, smaller physician practices typically gain access through Epic Community Connect. This program allows large health systems to extend their Epic environment to affiliated practices, enabling patient data sharing and streamlined workflows.
However, this integration comes with strict requirements: Epic mandates nearly 20 cybersecurity controls that must be met by every participating practice.
The Challenge
Meeting Epic’s cybersecurity standards is no small feat—especially for smaller practices. These physician offices:
Often lack in-house cybersecurity or even basic IT expertise.
Are not owned by the sponsoring hospital system, so they can’t rely on the hospital’s cybersecurity resources.
Must attest to meeting Epic’s cybersecurity requirements on a quarterly basis—a demanding and continuous burden.
This combination of limited resources and high expectations creates a major security and compliance gap.
The Solution: Velocity by Stern Security
A major U.S. healthcare system—already using Stern Security’s Velocity platform for third-party risk management (TPRM), faced this very challenge. With over 70 Epic Community Connect practices, the organization needed a fast, scalable, and effective way to ensure compliance across all affiliates.
The healthcare system turned to Stern Security and asked: Can Velocity handle this?
Built a tailored Epic Community Connect cybersecurity assessment module within Velocity.
Translated technical requirements into clear, non-technical language that practice administrators could easily understand.
Developed automated quarterly reminders to simplify ongoing compliance.
Identified and validated contacts for each practice.
Completed 70+ assessments across the entire physician network—on time and within scope.
The Results
In just two months, the entire process was up and running. Every assessment was successfully executed using the Velocity platform. The healthcare system now has a repeatable, scalable process for Epic Community Connect cybersecurity compliance—with evidence-based results they can trust.
Why It Matters
Healthcare organizations participating in Epic Community Connect are required to meet Epic’s cybersecurity standards. Without the right tools, this can be a costly and error-prone process.
Velocity by Stern Security is purpose-built to simplify these complex assessments:
Streamline compliance with clear, understandable requirements.
Reduce risk by validating evidence and automating processes.
Empower providers to focus on what they do best—delivering outstanding patient care.
Ready to Simplify Your Epic Community Connect Assessments?
Let Velocity do the heavy lifting.
Whether you manage 5 or 500 connected practices, Stern Security’s Velocity platform can help you maintain compliance, reduce risk, and protect patient data—all with less effort.
Contact us today to learn how Stern Security can help your organization streamline Epic Community Connect cybersecurity compliance.
The hospital was struggling to manually review hundreds of vendor (business associate) solutions which was causing delays in large projects. The security team tried hiring a third-party risk management service to offload the vendor reviews, but the results were greatly inaccurate.
At the same time, the hospital was trying to measure their internal security posture using CIS, NIST CSF, and the HIPAA Security Rule through spreadsheets. The spreadsheets only provided point-in-time reviews, could not be easily shared, collaboration was difficult, and the security frameworks could not be easily updated on the spreadsheet.
To address both the vendor and internal risk measurement problems, this hospital decided to use the Velocity SaaS solution by Stern Security.
An Industry Problem
The growing risk management issues that the hospital was experiencing are common across all industries. Companies often initially try to address the vendor risk issue manually by sending spreadsheet questionnaires to vendors. However, this process incredibly time consuming. They have to manage the questionnaires, send and retrieve from vendors, review the responses, have meetings about the risks, and create reports. This process can take months to complete for a single vendor. Ideally, the customer would complete this every year for a vendor, but very few organizations have the bandwidth to accomplish anything close.
Many companies try to outsource the vendor risk management work to a service provider or purchase a product to complete the task. Unfortunately, most of the results from these solutions are inaccurate. Even fewer solutions address both internal and vendor risk.
Velocity prioritizes accuracy
After limited success with the manual approach and other products, this hospital found their ideal solution with Velocity.
Solution
Onboarding with Velocity took the hospital one hour with most of the time spent on training. The hospital quickly replaced the spreadsheet used to measure internal risk and saw immediate results. Instead of using an outdated version of the CIS framework, the hospital could use the latest version with Velocity. The hospital also received a prioritized list of items to work on to increase security posture. Additionally, when the hospital fixed an item on the list, they could see their security posture improve.
Customer employees became rockstars with Velocity
The hospital also made rapid improvements on their vendor risk management process. Instead of sending the standard security questionnaire to vendors, the hospital sent invitations from the Velocity platform and let the product do all of the work. The hospital received detailed security reports for their vendors within ¼ of the time. Hospital cybersecurity staff that was originally tasked with performing these vendor security reviews, could now spend their time on other tasks while directing more vendors through Velocity than they could ever before. Velocity greatly sped up the hospital’s vendor security review process which made the entire project evaluation process more efficient. Additionally, Velocity increased accuracy, and saved the hospital valuable funds. Velocity added such value to the hospital that they renewed their subscription the following year.