How to make Mikrotik RB951G HIPPA COMPLIANT

I am wanting to us a RB951G as my firewall. Is there any best practice steps to make this happen? Thanks

What is hippa?

The Health Insurance Portability and Accountability Act of 1996 (HIPAA; Pub.L. 104–191, 110 Stat. 1936, enacted August 21, 1996) was enacted by the United States Congress and signed by President Bill Clinton in 1996.

Oh. Different abbreviations… Anyway what does it mean for routers and firewalls?

I have been through many security audits - for business, and medical related networks.

The best things to have/do prior to any audit is the following:

  • Always maintain fairly current software
  • Always maintain/check logs and network activity - - - daily
  • Have qualified/experienced network admins/engineers
  • Fully document the network
  • Have policies and procedures (requirement for daily operations and disaster and you’ve-been-hacked procedures).
  • Best firewall policies are (#1 allow only what you want to pass) -and- (#2 default deny everything else).
  • If you do any type of wireless, make sure you are industry PCI compliant !!!
  • Make sure all equipment is secure and not accessible to the public
  • Perform periodic network audits
  • Consider having a qualified 3rd party perform periodic or annual security audits & keep the results available.

The absolute worst thing you can do is not-knowing and not-checking-everything–often