Skip to navigationSkip to main content
Just Healthcare

Trust Center

Just Healthcare Solutions

Security, privacy, and compliance for every eligibility check, authorization, claim, and appeal we handle.

Controls

Updated 2 hours ago

66 controls across 5 domains

Infrastructure security

How production systems, networks, and datastores are hardened and access-restricted.

ControlStatus

Unique production database authentication enforced

Authentication to production datastores requires authorized secure mechanisms such as IAM-issued credentials or unique SSH keys; shared accounts are prohibited.

Encryption key access restricted

Privileged access to encryption keys in the key management service is limited to authorized users with a documented business need.

Unique account authentication enforced

Access to systems and applications requires a unique username with a password or authorized SSH key; multi-factor authentication is enforced for all workforce accounts.

Production application access restricted

System access is restricted to authorized personnel through role-based access control.

Access control procedures established

The access control policy documents the requirements for the following functions:

  • adding new users;
  • modifying users; and
  • removing an existing user's access.

Production database access restricted

Privileged access to databases containing protected health information is limited to authorized users with a business need and is logged.

Firewall access restricted

Privileged access to network firewalls and security groups is limited to authorized users with a business need.

Production OS access restricted

Privileged access to production operating systems is limited to authorized users with a business need.

Production network access restricted

Privileged access to the production network is limited to authorized users with a business need and requires a VPN with device posture checks.

Access revoked upon termination

Termination checklists ensure access is revoked for departing employees and contractors within 24 hours.

1 to 10 of 21 results

1 / 3

Organizational security

People, devices, and workforce practices that keep the organization secure.

ControlStatus

Asset disposal procedures utilized

Electronic media containing confidential information is purged or destroyed in accordance with NIST 800-88, and certificates of destruction are retained.

Production inventory maintained

A formal inventory of production system assets is maintained and reviewed.

Portable media encrypted

Portable and removable media devices are encrypted when used; use is discouraged by policy.

Anti-malware technology utilized

Endpoint protection is deployed to workforce devices and servers, configured to update automatically, and is centrally logged.

Employee background checks performed

Background checks are performed on new employees prior to accessing customer data.

Code of Conduct acknowledged by contractors

Contractor agreements include a code of conduct or reference the company code of conduct.

Code of Conduct acknowledged by employees and enforced

Employees acknowledge the code of conduct at hire. Violations are subject to disciplinary action in accordance with the disciplinary policy.

Confidentiality Agreement acknowledged by contractors

Contractors sign a confidentiality agreement at the time of engagement.

Confidentiality Agreement acknowledged by employees

Employees sign a confidentiality agreement during onboarding.

Performance evaluations conducted

Managers complete performance evaluations for direct reports at least annually.

1 to 10 of 14 results

1 / 2

Product security

How our applications and API protect customer and patient data.

ControlStatus

Data encryption utilized

Datastores housing sensitive customer data are encrypted at rest.

Control self-assessments conducted

Control self-assessments are performed at least annually to gain assurance that controls operate effectively. Corrective actions are completed within the committed SLA.

Penetration testing performed

Third-party penetration testing is performed at least annually. A remediation plan is developed and vulnerabilities are fixed in accordance with SLAs.

Data transmission encrypted

Confidential and sensitive data is encrypted in transit over public networks using TLS 1.2 or higher.

Vulnerability and system monitoring procedures established

Formal policies outline the requirements for the following IT and engineering functions:

  • vulnerability management;
  • system monitoring.

PHI minimization enforced

Protected health information is limited to the minimum necessary for each workflow and is de-identified before model inference where feasible.

Audit logging of PHI access

Every read, export, and change to protected health information is recorded with actor, time, and record identifiers, and is available to customers on request.

Customer data isolation enforced

Customer data is logically isolated by tenant with row-level authorization on every query.

Internal security procedures

Governance, change management, and resilience practices.

ControlStatus

Continuity and Disaster Recovery plans established

Business Continuity and Disaster Recovery Plans outline communication plans to maintain information security continuity in the event of the unavailability of key personnel.

Continuity and Disaster Recovery plans tested

The documented BC/DR plan is tested at least annually and results are reviewed with leadership.

Cybersecurity insurance maintained

Cybersecurity insurance is maintained to mitigate the financial impact of business disruptions.

Configuration management system established

A configuration management procedure ensures system configurations are deployed consistently throughout the environment.

Change management procedures enforced

Changes to software and infrastructure are authorized, documented, tested, peer reviewed, and approved prior to production deployment.

Production deployment access restricted

Access to migrate changes to production is restricted to authorized personnel.

Development lifecycle established

A formal systems development life cycle governs the development, acquisition, implementation, changes (including emergency changes), and maintenance of information systems.

System description maintained

A description of the system, its boundaries, and its components is maintained for audit purposes.

Whistleblower policy established

A formalized whistleblower policy and an anonymous communication channel allow reporting of potential issues or fraud concerns.

Board oversight briefings conducted

Leadership is briefed at least annually on the state of cybersecurity and privacy risk, and provides feedback and direction as needed.

1 to 10 of 17 results

1 / 2

Data and privacy

How data is classified, retained, and returned or destroyed.

ControlStatus

Data retention procedures established

Formal retention and disposal procedures guide the secure retention and disposal of company and customer data.

Customer data deleted upon leaving

Customer data containing confidential information is purged from the application environment in accordance with best practices when customers leave the service.

Data classification policy established

A data classification policy ensures confidential data, including protected health information, is properly secured and restricted to authorized personnel.

Privacy notice published

A public privacy notice describes what personal data is collected, why, and how individuals can exercise their rights.

Data subject request procedures established

Procedures exist to respond to access, correction, and deletion requests within regulatory timelines.

Business Associate Agreements executed

Business Associate Agreements are executed with covered-entity customers and with subprocessors that handle PHI.