ASSYST has been awarded the CMS Security & Privacy Officer Support Services (CSPOSS) contract to provide cyber security Subject Matter Experts (SME) supporting the CMS Chief Information Security Officer (CISO) and Chief Information Officer (CIO) in their objectives for maintaining and managing secure and compliant FISMA Systems. This involves delivering Cyber Risk Advisors (CRAs) as a Service, Information Systems Security Officers (ISSOs) as a Service, and ISSO Advocacy and Support Programs.
Our program delivery will support CMS Business Owners, CISOs, and executive leadership with seasoned cyber expertise to log FedRAMP ATO documentation, implement NIST RMF accurately, utilize risk data to guide decision-making, strategize POA&Ms, facilitate Zero-Trust frameworks, oversee the successful implementation of procedures, ensure the effectiveness and documentation of CMS and Security controls, manage activity for information systems and data usage to remain compliant with FISMA standards and adhere to policy and practices with CMS and NIST guidelines. ASSYST services will help CMS achieve its cybersecurity objectives by providing expert support in managing cybersecurity efforts and developing the necessary skills and knowledge among CMS cybersecurity personnel.
Vinay Shirke, the CIO at ASSYST, expressed his delight about the contract award. He said establishing Cyber Security Service Delivery Models will significantly reduce the burden for Business Owners and CISOs. These models will help identify and foster qualified cyber talent to manage FISMA systems effectively. They will also help in implementing and overseeing NIST controls, envisioning strategic roadmaps, leveraging risk data to make informed decisions regarding policy and procedure, and maintaining required documentation for obtaining and maintaining an ATO.
Cybersecurity Services
ASSYST provides cyber support services that help customers with portfolios of FISMA Systems to manage risks effectively and comply with regulations. Our services include risk management, policy and compliance, vulnerabilities, knowledge management, data management, project management, and talent management for CISOs and business leaders. Our Security Data Lake Solution harmonizes data and improves holistic threat intelligence through actionable insights. Our unique ISSO-as-a-Service (ISSOaaS) and SOC-as-a-Service (SOCaaS) connect you with adaptable security professionals who follow industry best practices to support your organization's Cyber Mission Assurance. ASSYST’s ComplySync solution applies AI/ML and collaborative document intelligence to help agencies acquire Continous Authority to Operate (cATO) capabilities.
Our seasoned cyber security experts adhere to industry standards and best practices such as NIST CSF/RMF, PMBOK, ISO 27001/9001, HS2P2 guidelines, and Zero-Trust frameworks. We offer a Cyber Resilience Program with various engagement, education, and training initiatives for customer cyber experts, business owners, and cyber leadership. These initiatives help them discuss evolving trends, share their best practices based on experience, and grow their knowledge base through certifications.
ASSYST is thrilled to announce that the HHS Centers for Medicare and Medicaid Services (CMS) has awarded us a Cyber Risk Management Program contract. This new contract will allow us to expand the boundaries of CMS's existing cybersecurity initiative and develop Security Data Lake to enhance robust reporting mechanisms that contribute significantly to informed decision-making.
Our job under this contract is to help CMS integrate programs sponsored by various Intergovernmental Agencies and data feeds from the Continuous Diagnostic and Mitigation (CDM) program. By consolidating and standardizing diverse cyber risk data, we will enable CMS to effectively report on threats, vulnerabilities, and risks and promote transparency into the security posture of their IT systems and data enterprise-wide.
In addition, we will continue to provide operation and maintenance support for enterprise Governance Risk Compliance tools. These tools are necessary for maintaining the required FISMA and FedRAMP documentation, POA&M management, necessary controls, cyber policy management, audit management, and real-time reporting through dashboards.
Mr. Vijay Narasimhan, the CTO at ASSYST, shared his remarks on this win. He continued to say that expanding the boundaries of the Security Data Lake can have several benefits. It can improve visibility into systems and data security across the enterprise, speed up threat response times, enhance risk preparedness, and guide cyber strategy for Government Agencies. This can help ensure that high-value assets remain secure, improve decision-making, and comply with federal mandates.
Cybersecurity Services
ASSYST offers CISOs and business leaders a range of services covering risk management, policy and compliance, expert audit support, vulnerabilities, knowledge management, data management, project management, and data quality management. Our Security Data Lake Solution is designed to harmonize data, which helps improve holistic threat intelligence by providing actionable insights.
We provide unique ISSO-as-a-Service (ISSOaaS) and SOC-as-a-Service (SOCaaS) solutions that offer access to adaptable security professionals who are well-versed in industry best practices and can support your organization's Cyber Mission Assurance. Our seasoned cyber security experts follow industry standards and best practices, including NIST CSF/RMF, FIPS-199, PMBOK, ISO 27001/9001, HS2P2 guidelines, and Zero-Trust frameworks. ASSYST’s ComplySync solution applies AI/ML and collaborative document intelligence to help agencies acquire Continuous Authority to Operate (cATO) capabilities.

Welcome to a new edition of ASSYST's OnPoint xChange. We present an insightful conversation between Vijay Narasimhan, who recently assumed the role of ASSYST's Chief Technology Officer (CTO), and Eugene Goldlust, a Senior Account Executive focusing on Cybersecurity. They share perspectives and ideas on the emerging requirements for Cybersecurity programs to build capacity to support adopting AI/ML solutions.
Read more on LinkedIn
ASSYST OnPoint xChange features an informative dialog on Health Data Interoperability. The maturity of the standards, regulatory mandates, and legislative compliance drive the adoption of Fast Healthcare Interoperability Resources (FHIR®). There are immense benefits at the provider-patient-payer levels, empowering patients to be in charge of their healthcare access. However, there can be benefits beyond the level of information sharing.
Mr. Vinay Shirke, Lead of ASSYST’s End-to-End Cloud based FHIR Solution “Hephaestus” Product Development and CIO, joins Mr. Khalil Zebdi, EVP Health IT solution, and Federal Business Development to discuss their journey to create Hephaestus.
They also explore the underlying technologies which support a high-quality FHIR® solution, the capabilities consumers should expect, and the potential interoperability standards benefits beyond compliance that FHIR® standards can provide for the Greater Healthcare Ecosystem, including Research and Nonprofit Organizations.
Vinay Shirke: Hello Khalil, witnessing current trends seen by healthcare providers adopting interoperability has been fascinating. Healthcare IT vendors seem keen on FHIR® based solutions to support data exchange within their technology ecosystem. With the recent introduction of government mandates requiring compliance for information sharing with patients, FHIR® is becoming more of obligation providers must meet. When we began developing Hephaestus, I remember what spurred your interest in Interoperability and led you to the idea that ASSYST should create our own FHIR® solution.
Khalil Zebdi: Vinay, having been working with HHS agencies featuring CMS, HRSA, and FDA for the past 15 years, we have held the privilege of developing close relationships I will cherish with these agencies and the people within them. A little over five years ago, as I was having lunch with a client from the CMS, she began to talk to me about the 21st Century Cures Act and the vision that she believed the legislation would drive for the future of healthcare IT. While we had heard about FHIR® and the concept of Interoperability, we weren’t quite sure how it would translate to real world use cases. But I couldn’t help myself but dive into research. As I dug deeper, I realized that FHIR® isn’t not only going to become an opportunity for IT vendors as providers would have to meet compliance but also a concept that will improve the overall quality of care we receive as patients.
When I dropped the idea of developing a FHIR® solution to the team, we evaluated the market and noticed that there weren’t many players engaged in FHIR®, which only made us more eager to jump right in. But as we began brainstorming, we asked ourselves, how can we be different from the other vendors? Many developers had stand-up FHIR® servers that performed the parsing and validation functions and housed FHIR® data. We researched many of the progressing trends occurring in HL7 and FHIR® but also with EMR vendors and Public Health IT. We wanted to exploit the experience we had obtained by working with various Federal, State, Local and Commercial agencies, as we already understood what it took to meet federal compliance with HIPAA and develop a federally approved software system. This drew us to the conclusion that whatever our product was going to be, it had to support the client in adopting FHIR®, maintain flexibility to the various use cases, be scalable to adapt to an expanding data environment and provide users the ability to visualize their data.
Thus, we created the vision for Hephaestus! Named after the God of Fire, we developed Hephaestus to bring change as a scalable solution that would aid organizations in transitioning from their use of legacy data formats to the most recent version of FHIR®. Hephaestus accelerates adopting and implementing the HL7 FHIR® standard by automating metadata exploration, data mapping, parsing, validating, transmission, API, and Business Intelligence (BI) with a data Visualization Dashboard. Being built in a Six-Component Microservice architecture and Cloud compatible, there are various use cases for ample providers that Hephaestus provides an answer for.
Khalil Zebdi: Vinay, when you kicked off developing Hephaestus, what tools and technologies did you feel were best to augment a FHIR® solution of this caliber? If I’m a Healthcare IT vendor, a provider, or an industry stakeholder, what approaches should I take when selecting a FHIR® solution that can aid the transition process? And what capabilities should I expect from a FHIR® solution?
Vinay Shirke: Khalil, as you explained earlier, from years of market research and experience with healthcare IT, we were in a good place to identify technologies and tools to construct a FHIR® solution, all of which we felt were necessary to build into Hephaestus.
As a basis, your FHIR® solutions should be able to effectively parse and validate non-FHIR® data sets into the most recent and relevant FHIR® format to be housed within a select FHIR® server so it can effectively be used for data exchange across platforms. The process of transforming data sets from legacy formats to FHIR® is the most important step, as many providers use varying data set formats, causing difficulties for users to remodel their data sets properly. Aggregated data collection can come from various sources and formats such as Excel sheets, CSV., XML, and JSON. Vendors are looking to build their apps with FHIR® to facilitate data ingestion from these sources. The platform should be able to collect metadata sets, analyze them and correlate them into schema formats (FHIR®Spy). For example, we built Hephaestus with SMART HL7 Bulk FHIR® to automate the uploading of Bulk FHIR® (large volumes of FHIR® data) data from various sources. In addition, users should be able to standardize their target schema formats reflecting their metrics for analysis fitting their business requirements, which is why we designed an interface enabling customization functions to format schemas. A proper solution should be able to interface with the source schemas (incoming datasets) and target schemas (FHIR® or defined metrics) and map out the transformation process and with the implementation of AI/ML capabilities stemming from the FHIR® server to automatically recommend the mapping of various data elements from the source schema to the target schema from previous activity (FHIR®Bricks).
A powerful parsing engine within your FHIR® server is imperative to complete the transformation process. We strongly recommend using a FHIR® server that leverages AI/ML to break down and restructure the various source data sets, re-structure them into the targeted FHIR® format, and prepare the dataset in a consumable format, then direct them to their appropriate storage location (FHIR®Proof). This step should also include a good validation tool, as we want to maintain the validity of data sets and their contents during the restructuring process. In addition, we believe that a platform should also be Cloud- compatible with supporting evolving data demands in Healthcare. From our years of experience, we have learned that everyone in the industry is adopting the cloud, including HHS agencies managing programs with the private sector, and are beginning to migrate their Healthcare systems to the cloud. So we felt it was imperative to make Hephaestus a Cloud-based solution.
Then comes the next step, which is the actual exchange of data. We identified SMART on FHIR® during our research. We built its RESTful API frameworks into Hephaestus, which not only augments your data collection process through quick exchanges of small and large data sets and contains authorization standards to govern data exchange. It clearly defines workload functions that guide applications to securely exchange data amongst each other efficiently while remaining versatile to different volumes of data sets (FHIR® Break). SMART on FHIR® supports integration with Bulk FHIR® Servers, which enables gathering large data sets using Bulk FHIR® API and meets compliance with the 21st Century Cures Act. Using the OAuth 2.0 Token Authentication standard, product and business owners can set controls on access levels using User-Managed Access (UMA) 2.0 protocol, which grants users tokens for a finite time for engagement in health information exchange. We feel that this is important to a successful adoption of FHIR® to assure all stakeholders that while their data is more open for sharing, it is also protected.
Lastly, we advise integrating a good analytical tool into your solution. Using SMART on FHIR® enables clients to integrate many open-source applications in the SMART App Gallery. These can be anything from patient dashboards to data visualization tools that can be used for reporting and analytics. For example, we are very enthusiastic about Superset. This open-source Data Visualization tool (FHIR® BI) is customizable. It enables users to define their metrics of measurement and Key Performance Indicators (KPI) and customize their interactive dashboards for analysis. Integrated dashboards provide organizations autonomy to slice and dice data with the AI/ML component of their FHIR® server and their aggregated health data and create dynamic graphical representations of their patients and the populations they serve.
Khalil Zebdi: We see the immediate need for healthcare providers to adopt FHIR® and the benefits it can provide to improve the overall quality of healthcare. However, with access to all that data, do you believe there are healthcare objectives that FHIR® beyond compliance can support? For example, can FHIR® support data analysis and construction of open health data products for Public Health initiatives?
Vinay Shirke: Today’s age in technology is moving more towards shared services and building open data models for services. Access to networks and the creation of open data services can aid Healthcare objectives for many organizations that use healthcare data programs to support their operational model. Interoperability can be the tethering framework for bringing together enterprises' health information data to build foundations of data models supporting healthcare programs, whether for private businesses or public health partners. We can use FHIR® to build open systems leveraging Cloud capabilities for ingesting and organizing Health data from a shared collection of participating stakeholders using FHIR® Bulk API exchanges to visualize populations based on their aggregate data in support of large-scale healthcare Programs. For instance, the Bulk FHIR® protocol, while not specifically established for data analytics and shared service programs, can interface with open data programs to define population groups and support information sharing across communities and population taxonomies. Organizations, Communities, and Public Health Stakeholders engaging in programs collecting large quantities of healthcare data in efforts to gain insights on trends in patient populations can adopt these standards to expedite data exchange, hone in requirements, customize metrics for data collection for analytical objectives, all of which will improve accuracy and speed of research and program operations.
How will this translate to the real world? We can support informative public platforms such as websites reporting important information with real time numbers on occurring phenomena such as infectious diseases or available hospital beds in a certain region. We can properly evaluate health conditions in a particular labor environment and use it to guide occupational safety policies. Grantors can gain direct analytical insight into their grantee constituents' activity & performance to more effectively manage their programs and allocate grants and resources in a cost efficient way. Clinical trials involved with the release of critical drugs for treatment will have access to obtaining accurate data that can improve trial processes and expedite approvals. Public health agencies can collect data models reflecting populations to improve operational strategy and provide information relevant citizen populations.
With greater data access, we can be more informed in how we conduct business and, as a result, provide better services and products to the people we serve. Promoting a more data driven culture across the healthcare industry will significantly help business processes mature and benefit with increased efficiency and the ability to integrate with modernized technologies.
Hephaestus is ASSYST's most recent innovation to come out of our Green Accelerator Program, designed, developed, and implemented for Healthcare Providers, Government Health Agencies, Health IT Companies, and Health Insurance Companies. Hephaestus is an eloquent, lightweight, low-code application platform that provides customers with the component architecture required to implement the FHIR® specification.
Discover more at https://www.assyst.net/hephaestus/
As a Health IT Systems Integrator and Platform Solutions provider, ASSYST helps US government health and human services agencies, research, and nonprofit organizations to deliver high-quality health and wellness services. Our customers include the Centers for Medicare and Medicaid Services (CMS), Food and Drug Administration (FDA), Health Research and Services Administration (HRSA), Program Support Center (PSC), and many State and Local Government agencies. ASSYST has been an industry leader in data interoperability, trusted data exchange, compliance, metadata, taxonomy, open data, and dissemination initiatives for over 25 years. In addition to HL7® FHIR®, ASSYST delivers solutions complying with data exchange standards, including XML, GJXDM, NIEM, XBRL, EDI, X12, and SDMX. ASSYST is an HL7 Gold Level member organization.
Thank you for all your feedback on Part One. In the second segment, our intent is to cover a few essential components of the Cybersecurity Program, such as Knowledge Management, Project Management, and Talent Management.
Cybersecurity Analytics - Cybersecurity analytics is becoming an increasingly more important function of the cybersecurity organization. Proactively performing threat detection using analytics provides security teams and data scientists the capability of processing and analyzing very large datasets of threat information in real time. Cybersecurity analytics enables data scientists and threat hunters to design and develop predictive threat models based on threat intelligence and knowledge of the security data. The CISOs who utilize the best tools and technologies for their analytics platform and provide the appropriate training for the Cyber workforce can implement smart alerts and develop more meaningful reports and dashboards, resulting in improving detection and remediation capability while reducing the ambiguity when performing the investigation of security events.
Knowledge Management - Knowledge Management is becoming a critical function of the Cybersecurity program. The knowledge management process increases the effectiveness of the Cybersecurity program by institutionalizing the decision-making and continuous learning activities. The knowledge management process and tools enable the Cybersecurity organization to effectively identify, document, and communicate information and status regarding Cybersecurity projects, vulnerabilities, threats, security events, and incidents occurring in the environment, as well as provide guidelines and standard operating procedures (SOPs) for IT and asset owners. The CISO ensures knowledge management projects are identified, planned, initiated, and executed. Today’s CISO defines and designs the Cybersecurity organization’s knowledge management framework and decides the tools and technology used to implement and administer the system. A mature knowledge management system uses Cloud technology to collect, maintain, and communicate Cybersecurity content to allow leadership to easily understand the status of security-related projects and programs. A well-designed and correctly implemented knowledge management system provides the CISO and asset owners with insight using KPIs, metrics, and information of interest, and the dashboards for visualizing and communicating the progress of the Cybersecurity projects.
Project Management - Applying project management principles to the Cybersecurity program keeps security-related initiatives on budget and on schedule. Additional benefits include strategic alignment, streamlining project execution, optimizing resource capacity and allocation, instilling a culture of continuous improvement, and more effective problem resolution and risk management. There are important details and standard project artifacts as part of the project management activities that are not included in the POA&M process. For example, well-defined project deliverables, roles, and responsibilities, WBS, resource assignments and task schedules, project risk tracking and mitigation, communication planning, quality assurance, and continuous improvement. A mature project management approach provides the CISO with fundamental information about specific projects and statuses needed to create and maintain the integrated master plan and schedule. The CISO requires an integrated master plan and schedule for managing resource allocation and capacity, budgeting, monitoring, and controlling the Cybersecurity program portfolio.
Talent Management - As Cybersecurity vulnerabilities and threats increase and become more sophisticated, the risk rises for those programs that do not have the correct skill sets or enough talent. Every CISO requires a Cyber talent management approach that best leverages internal staff, contractors, and outsourcing. A highly trained and skilled Cyber workforce greatly reduces risks to the organization. However, achieving this requires the CISO to define and assess the Cyber workforce needs and develop, design, train, and retain Cyber talent. Fortunately, there are proven approaches and tools that the CISO can utilize to perform these functions to strengthen the Cyber workforce. Accomplishing this requires assessing the Cyber workforce's talent gaps and aligning the talent management plan with the organization’s Cyber goals. It is critical that the organization’s acquisition strategy supports the Cyber talent strategy. Acquisition alignment and support allow the CISO to attract the right talent, grow the workforce, and create an environment where cyber employees and contractors are retained. The CISO is responsible for defining the workforce requirements, establishing talent benchmarks, evaluating potential risks caused by gaps in talent and skill sets, and defining career paths. Defining a clear and concise career path significantly improves the organization’s ability to source, recruit, and retain Cyber talent, and it supports the job analysis, skills assessment, training, and talent forecasting process.
The present decade has seen Cybersecurity breaches across Government, Private, and Non-Profit systems. Needless to mention how it is impacting individual privacy and personal information. Many of us have been the victims of information breaches due to failed Cybersecurity approaches. Agencies and businesses have managed Cybersecurity as ad-hoc reactionary projects, and many government agencies lack a coherent acquisition strategy that aligns with the organization’s Cybersecurity strategy. This ad-hoc approach is not working in today’s environment, especially when considering the massive amounts of data and transactions occurring in areas of Defense and Intelligence, Homeland Security, Healthcare, Regulatory Compliance, Census Information, and Digital Commerce.
We are covering this OnPoint blog in multiple parts. The first part has perspectives on the relevance of Project Portfolio Management, Risk Management, Managing Vulnerabilities, Policy, and Compliance in an Enterprise level Cybersecurity Program.
Portfolio Management for the CISO - The constant attention that Cybersecurity demands is changing the role of the Chief Information Security Officer (CISO). Given today’s cyber-threat landscape, evolving Cloud adoption strategies, and edge security requirements, CISOs have multiple simultaneous projects occurring within their portfolio that are necessary for protecting sensitive information and the organization’s high-value assets. CISOs are operating with a shortage of skilled cybersecurity professionals; they're inundated with new requirements, experiencing difficulties balancing resources, and struggling to determine what Cybersecurity services to outsource. CISOs are establishing a portfolio approach to managing Cybersecurity programs to improve some of these operating difficulties. Some benefits include improvement in the project prioritization and selection process, better visibility across the Cybersecurity portfolio, and improved alignment of projects with the organization’s business goals. Other benefits include more efficient use of resources, improvements in the accuracy of performance metrics, timelier project deliverables, decreases in project risks, and more informative decision-making.
Risk Management - Today’s CISO faces several types of intangible and tangible risks with potentially negative consequences to the Cybersecurity program and the organization, its employees, customers, and stakeholders. The types of risks include project related risks, information security risks and threats to the organization’s systems, engineering and technology risks, risks related to a lack of knowledge or skill gaps, and risks to productivity. Identifying, evaluating, and prioritizing risks to the Cybersecurity program helps the CISO organize projects and allocate resources. Strategies include identifying and evaluating the risks and threats with the highest negative consequences, the highest probability of occurring as the topmost priority, and risks and threats with lesser negative consequences or lower probability of occurring as less important priorities. Every CISO requires a disciplined approach to identifying, assessing, and prioritizing risks and threats, as well as well-defined mitigation strategies and problem management plans that include impact analysis, risk tracking, root cause analysis, lessons learned, and risk reduction plans. Effective risk management for the Cybersecurity program creates value for the organization because the resources expended mitigating risks is less than the consequences of inaction.
Policy and Compliance - An established portfolio and project management approach for the Cybersecurity program provides the CISO with the capability to define and maintain policies and the necessary processes and procedures to comply with and adhere to those policies. The policy management activities involve developing, updating, communicating, and maintaining the policies and procedures for the Cybersecurity program and are integral in developing more detailed standard operating procedures and project deliverables. Complying with internal and regulatory policies consumes a large percentage of the CISO’s resources, so integrating the compliance requirements within the project plan, work breakdown structure, and task schedules is required to streamline compliance activities. As the CISO’s policy and compliance requirements expand beyond the Assessment & Authorization (A&A), Authority to Operate (ATO) process, complying with and adhering to the organization's internal approach for Project Life Cycle Management (PLCM), and Systems Development Life Cycle (SDLC) will determine the level of maturity of the Cybersecurity program. Applying portfolio and project management principles to Cybersecurity related projects supporting the Security Information and Event Management (SIEM) system, the Security Operations Center (SOC), and the Network Operations Center (NOC) allows the CISO to comply with internal processes and regulatory policies and procedures more effectively.
Managing Vulnerabilities - The CISO owns the organization’s vulnerability management process, and is responsible for the design and implementation of the process. The vulnerability management activities involve services that continuously assess system vulnerabilities, and the process is more effectively implemented using portfolio and project management principles. Establishing a project management approach allows the CISO to organize and schedule resources to prepare and execute vulnerability scans, define remediation activities, and perform rescans. The CISO defines the scope of the vulnerability management process, which systems are included or excluded, and determines the type of scans and schedule. The security engineers execute the initial vulnerability scans, the results are recorded, and visualization tools are used to review the results and prepare reports. The CISO and asset owner are briefed on the number of vulnerabilities detected, the severity level and risk rating of the identified vulnerabilities, and the risk remediation plan. The CISO establishes clear deadlines for remediation activities, and the time frame is aligned with the level of risk detected. Once a vulnerability is remediated, a rescan is required to verify the remediating actions were implemented. The vulnerability management process is part of the organization’s effort to control Cybersecurity risks. The process allows the CISO to continuously review vulnerabilities occurring in the operating environment and assess the level of risks associated with each vulnerability. Managing vulnerabilities utilizing project management best practices provides the CISO with a mature approach to identifying and mitigating vulnerabilities.
Continue to Part 2

At ASSYST, our culture of giving back is not just a series of one-off events; it’s a deeply ingrained aspect of who we are. In 2023, we demonstrated this commitment through several key initiatives, most notably our annual donation events, which are a cornerstone of our community involvement. These ongoing efforts inspire hope and significantly impact the communities we serve, reassuring you of our unwavering commitment.
One of the highlights of our philanthropic efforts last year was our support for Northern Virginia Family Services (NVFS). Through a company-wide donation drive, we collected and contributed resources that directly benefited the families and individuals served by NVFS. This was just one example of how we strive to make a tangible difference in our community.
Our commitment to supporting local organizations has a rich history. In previous years, we proudly supported the Loudoun Abused Women’s Shelter (LAWS), providing much-needed assistance to those affected by domestic violence. These efforts reflect our dedication to choosing causes that are most in need and ensuring our contributions have a meaningful impact.
What truly sets our philanthropic efforts apart is the active involvement of our employees. At ASSYST, giving back is a collective effort. Our team members are crucial in organizing donation drives, participating in volunteer activities, and working closely with the organizations we support. This hands-on involvement fosters a strong sense of responsibility and engagement across the company, uniting us around a shared goal of making a positive difference. We believe that effective philanthropy requires thoughtful planning and ongoing evaluation. To ensure our contributions are impactful, we carefully assess the needs of various organizations before selecting those to support. This strategic approach, coupled with our ongoing evaluation, instills confidence in our audience about the soundness of our philanthropic decisions.
Moreover, our commitment to the community extends beyond donations. We maintain long-term partnerships with local non-profits, collaborating on initiatives that address persistent community needs. By regularly reviewing the outcomes of our donations and partnerships, we ensure that our efforts are not just short-term solutions but part of a continuous, impactful approach to giving back, providing a sense of security and confidence in our commitment.
“ Our commitment to giving back is more than just corporate responsibility; it reflects our values as a company. We believe that by actively involving our employees in these initiatives, we not only positively impact our community but also foster a sense of purpose and connection within our team, ” said Joe Anderson, COO of ASSYST.
At ASSYST, we are proud of the strong philanthropic culture we’ve built. Our annual donation events and ongoing community partnerships reflect our dedication to making a lasting difference in the lives of those in need. As we look to the future, we remain committed to supporting meaningful causes and fostering a spirit of giving that resonates throughout our company, giving you hope for the positive impact we will continue to make.

ASSYST's OnPoint xChange Data Dialogs presents excerpts from an insightful conversation between Vinay Shirke, ASSYST CIO, and Eugene Goldlust, Senior Account Executive, with a special focus on Cybersecurity. In their first exchange, Vinay and Eugene spoke about how a Security Data Lake (SDL) solution improves holistic Threat Intelligence for organizations by providing Actionable Insights. They discussed how an SDL could enhance and provide complete visibility to system stakeholders that are filtered out or missing from an SIEM solution, a traditional data warehouse, and the multitude of other third-party security endpoint tools that organizations deploy.
Discover more on LinkedIn

June 12, 2023, Sterling, VA: ASSYST is celebrating its 30th anniversary, a remarkable milestone in providing transformative solutions and exceptional customer service. Over the years, ASSYST has been devoted to driving innovation and empowering businesses, positioning the company as a reliable partner for organizations seeking best-in-class solutions. By continuously evolving to support mission and enterprise initiatives, ASSYST has numerous accomplishments establishing the company as The One Point of Source for Transforming Your Business.
When we began, the focus was on providing customers with exceptional engineering capabilities and professional consulting services for modernizing applications and implementing ERP solutions, primarily for the international banking and finance sector and several Fortune 500 companies.
Strategically located in the National Capital Region (NCR), we were able to expand into other sectors and markets, such as State and Local government and non-profit organizations. As our strategy broadened from providing primarily engineering and professional consulting services, we began managing programs and implementing and supporting mission systems for the US Federal government sector.
Some of our earlier accomplishments contributing to ASSYST's expansion and growth include competing and securing a number of long-term IT service contracts with State governments and various County governments in and around Washington, DC, and Baltimore. Other significant accomplishments involved establishing long-term GSA Schedules, including IT Schedule 70, HACS, Health IT, and Cloud 518210C. Some of the more significant IDIQ GWAC contracts contributing to our growth, and where ASSYST competed and successfully performed, include GSA Alliant SB, SEC DIOMDS, CMS SPARC, and Army CHESS ITES-3S.
As we celebrate 30 years of employee contributions and exemplary customer service, ASSYST continues to expand and grow our business in areas of regulatory, healthcare, defense, and other sectors and industries. We continue to broaden our service capabilities and expand our solution development activities as we further invest in innovation through our Green Accelerator Program.
As we recognize employee contributions and customer loyalty, please join me, raise a glass, and hold it high, to celebrate ASSYST's many achievements supporting over 30 US Federal government customers, multiple State and Local governments and departments, several Fortune 500 companies, and the non-profit sector. The future is bright and promising.
With the utmost appreciation and admiration to ASSYST employees, our customers, and partners, past and present, we thank you.
With warm personal regards,
As ASSYST celebrates its 30th anniversary, it looks forward to continuing service excellence and bringing innovation to our customers to empower government, businesses, and non-profits with transformative solutions.

The advent of modern technology concepts and the emerging growth in Generative artificial intelligence (Gen AI) have unlocked a world of possibilities for improving healthcare data objectives. Here we have members of ASSYST’s Hephaestus Product Development Team; Padmaraj Viswanathan, a Solution Architect and AI/ML Engineer at ASSYST's Green Accelerator Program for Hephaestus, sits down with John Kimberl, an experienced Health Data Solutions Analyst to exchange ideas, explore the possibilities and delve into the potential of Generative AI and its role in facilitating Health Data Interoperability. Exploring this topic can uncover ideas supporting crucial health data operations for smooth data exchange, informed decision-making, and improving patient-centered care and public health initiatives.
Discover more on LinkedIn