How Caris Life Sciences utilizes 1Password to quickly and securely access sensitive health data
About the company
Caris Life Sciences® (Caris) is a leading next-generation AI TechBio company and precision medicine pioneer. Through comprehensive molecular profiling and the application of advanced AI and machine learning algorithms, Caris has created the large-scale, multi-modal database and computing capability needed to analyze and unravel the molecular complexity of disease. Caris’ digitized data is stored in hybrid on-prem and AWS environments.
99%
Reduction in time waiting for access
Reducing blast radius with privileges controls
Mitigating access risk by limiting privileges for read only, readwrite, and admin privileges, preventing excessive privileges.
Granular JIT Provisioning to S3 Folders
The DevOps team created policies that enabled the right people to access specific folders while blocking access to other folders in the bucket.
Eliminating Access Management Overhead
Integrating with existing IAM infrastructure, Apono reduces the need for time and resource-intensive admin management.
The Challenge: Cloud Adoption Introduces Access Risks
Operating under the tight regulations of HIPAA and other regulatory requirements, Caris Life Sciences needed to ensure that access to specific resources containing Protected Health Information (PHI) was controlled securely.
Due to the sensitive nature of Caris data, our team required a solution that enabled secure access to the S3 buckets in AWS, as well as access to the folder level for more granular segmentation.
Ronen Niv
Sr. Director of Engineering at Caris Life Sciences
Solution: Implement least privilege without the headache
Caris selected 1Password’s Cloud Access Security platform as it allows for exceedingly precise controls in the cloud.
Using 1Password’s Privileged Access platform, the Caris developed Access Flow policies providing Just-in-Time access to individual S3 folders. This pinpoint approach ensured that researchers could access the needed resources while restricting access to other folders in the same S3 buckets.
“We’ve implemented 1Password’s privilege management capabilities to control not just who can access resources, but who can read-only, read-write, or have admin privileges for a given resource, helping to further reduce risk,” Ronen said. Privileged Access integrated seamlessly into Caris’ existing processes, reducing the need for additional manpower while enabling Caris to maintain strong access controls and visibility.
The Outcome: Faster approvals with delegation and automation
In tackling the approvals delay challenge, the Caris team built out a number of Access Flows to specific sensitive resources in their cloud and on-prem environments and preassigned the right approvers. This saved everyone effort and time and allowed the teams to get to their data faster.
“Our data engineers control access to their own resources,” says Ronen. “This takes DevOps out of the middle since they don’t have to reach out for approvals. It improves the overall process, and we get the added value of all requests being fully documented.”
Caris now uses 1Password’s auto-generated reports that continuously monitor and log all access actions with the team’s justifications to streamline audits for various compliance needs.
Researchers and developers quickly recognized that they could access needed resources within minutes instead of hours or days, which helped to eliminate unnecessary requests and downtime.
“Knowing that access will be provided in minutes keeps workflows on track,” said Ronen. “The efficiencies gained have been remarkable.” The Privileged Access platform was also used to successfully consolidated Caris’ on-prem Linux and HPC servers which further streamlined access management and reduced overhead costs.
Eliminate standing access
See just-in-time access provisioned and removed across cloud, database, and K8s environments.