Healthcare IT & GRC — Active Directory · Microsoft 365 · Entra ID · HIPAA · NIST CSF 2.0
Lubbock, TX · Portfolio · LinkedIn · elazarferrer1@gmail.com
I keep identity and access secure, automated, and compliant. 4+ years in enterprise technical support — including healthcare IT support for CVS Health's workforce — now combining identity administration, security & GRC (NIST CSF 2.0, HIPAA), and data analytics to reduce both financial and compliance risk in healthcare.
Interactive dashboards built on real CMS, HHS/OCR, FDA & CISA data → elazarf123.github.io/healthcare-data-portfolio
- Hospital Readmission Risk & PHI Access-Audit — readmissions vs. real CMS/AHRQ benchmarks + HIPAA access-log flagging
- HIPAA Breach Intelligence — 772 real 2025 HHS/OCR breaches with risk scoring + NIST CSF 2.0 control mapping
- Medical Device & IoMT Security — connected-device vulnerability exposure (FDA recalls, CISA advisories) mapped to NIST CSF
- Identity & Directory: Active Directory (multi-VM domain lab), GPO, Kerberos, AD CS / PKI / LDAPS, FSMO, replication health
- Microsoft 365 & Azure: Entra ID, Conditional Access, Exchange Online, Intune, SSPR, Azure AD Connect
- Automation & Data: PowerShell (bulk provisioning, stale-account detection, privileged-group auditing), SQL, Python, Chart.js
- Security & GRC: NIST CSF 2.0, HIPAA, access controls, vulnerability assessment, incident documentation
| Project | What it is |
|---|---|
| healthcare-data-portfolio | 3 live dashboards — healthcare analytics + HIPAA/security (CMS, HHS, FDA, CISA data) |
| healthcare-data-integration | EHR-to-Claims reconciliation done three ways — Excel, SQL, and Python (pandas) — with denial-rate analysis and chronic-condition timelines (ICD-10, CPT) |
| healthcare-bi-pipeline | End-to-end BI workflow: Python ETL, star-schema warehouse, data-quality rules, revenue-cycle KPIs |
| iam-access-review | Joiner-mover-leaver access review — Python reconciliation of directory vs HR & RBAC (orphaned accounts, privilege creep) + gated PowerShell remediation |
| nist-csf-hipaa-risk-assessment | Full GRC deliverable set — scored NIST CSF 2.0 assessment, HIPAA crosswalk, owned risk register, phased POA&M |
| phi-access-anomaly-detection | Detection engineering over EHR audit logs — 4 insider-threat rules mapped to HIPAA & NIST CSF 2.0 |
| healthcare-it-support-toolkit | Clinical IT runbooks (EHR downtime, anti-vishing) + Python service-desk SLA analysis |
| powershell-ad-m365-scripts | Production-style AD & M365 administration scripts with error handling and CSV reporting |
| cyber-port | 6 documented hands-on labs (AD, PKI/LDAPS, DNS/DHCP, M365, replication) |
Google Business Intelligence · Google Data Analytics · Google Cybersecurity · Google IT Support · Healthcare IT Support (Johns Hopkins) · CompTIA A+ (in progress)
- CompTIA Security+ — in progress
- AZ-900 Azure Fundamentals — studying
- Building & documenting home-lab scenarios, then writing the After-Action Report