Controls
Updated 2 hours ago66 controls across 5 domains
Infrastructure security
How production systems, networks, and datastores are hardened and access-restricted.
| Control | Status |
|---|---|
Unique production database authentication enforced Authentication to production datastores requires authorized secure mechanisms such as IAM-issued credentials or unique SSH keys; shared accounts are prohibited. | |
Encryption key access restricted Privileged access to encryption keys in the key management service is limited to authorized users with a documented business need. | |
Unique account authentication enforced Access to systems and applications requires a unique username with a password or authorized SSH key; multi-factor authentication is enforced for all workforce accounts. | |
Production application access restricted System access is restricted to authorized personnel through role-based access control. | |
Access control procedures established The access control policy documents the requirements for the following functions:
| |
Production database access restricted Privileged access to databases containing protected health information is limited to authorized users with a business need and is logged. | |
Firewall access restricted Privileged access to network firewalls and security groups is limited to authorized users with a business need. | |
Production OS access restricted Privileged access to production operating systems is limited to authorized users with a business need. | |
Production network access restricted Privileged access to the production network is limited to authorized users with a business need and requires a VPN with device posture checks. | |
Access revoked upon termination Termination checklists ensure access is revoked for departing employees and contractors within 24 hours. |
1 to 10 of 21 results
Organizational security
People, devices, and workforce practices that keep the organization secure.
| Control | Status |
|---|---|
Asset disposal procedures utilized Electronic media containing confidential information is purged or destroyed in accordance with NIST 800-88, and certificates of destruction are retained. | |
Production inventory maintained A formal inventory of production system assets is maintained and reviewed. | |
Portable media encrypted Portable and removable media devices are encrypted when used; use is discouraged by policy. | |
Anti-malware technology utilized Endpoint protection is deployed to workforce devices and servers, configured to update automatically, and is centrally logged. | |
Employee background checks performed Background checks are performed on new employees prior to accessing customer data. | |
Code of Conduct acknowledged by contractors Contractor agreements include a code of conduct or reference the company code of conduct. | |
Code of Conduct acknowledged by employees and enforced Employees acknowledge the code of conduct at hire. Violations are subject to disciplinary action in accordance with the disciplinary policy. | |
Confidentiality Agreement acknowledged by contractors Contractors sign a confidentiality agreement at the time of engagement. | |
Confidentiality Agreement acknowledged by employees Employees sign a confidentiality agreement during onboarding. | |
Performance evaluations conducted Managers complete performance evaluations for direct reports at least annually. |
1 to 10 of 14 results
Product security
How our applications and API protect customer and patient data.
| Control | Status |
|---|---|
Data encryption utilized Datastores housing sensitive customer data are encrypted at rest. | |
Control self-assessments conducted Control self-assessments are performed at least annually to gain assurance that controls operate effectively. Corrective actions are completed within the committed SLA. | |
Penetration testing performed Third-party penetration testing is performed at least annually. A remediation plan is developed and vulnerabilities are fixed in accordance with SLAs. | |
Data transmission encrypted Confidential and sensitive data is encrypted in transit over public networks using TLS 1.2 or higher. | |
Vulnerability and system monitoring procedures established Formal policies outline the requirements for the following IT and engineering functions:
| |
PHI minimization enforced Protected health information is limited to the minimum necessary for each workflow and is de-identified before model inference where feasible. | |
Audit logging of PHI access Every read, export, and change to protected health information is recorded with actor, time, and record identifiers, and is available to customers on request. | |
Customer data isolation enforced Customer data is logically isolated by tenant with row-level authorization on every query. |
Internal security procedures
Governance, change management, and resilience practices.
| Control | Status |
|---|---|
Continuity and Disaster Recovery plans established Business Continuity and Disaster Recovery Plans outline communication plans to maintain information security continuity in the event of the unavailability of key personnel. | |
Continuity and Disaster Recovery plans tested The documented BC/DR plan is tested at least annually and results are reviewed with leadership. | |
Cybersecurity insurance maintained Cybersecurity insurance is maintained to mitigate the financial impact of business disruptions. | |
Configuration management system established A configuration management procedure ensures system configurations are deployed consistently throughout the environment. | |
Change management procedures enforced Changes to software and infrastructure are authorized, documented, tested, peer reviewed, and approved prior to production deployment. | |
Production deployment access restricted Access to migrate changes to production is restricted to authorized personnel. | |
Development lifecycle established A formal systems development life cycle governs the development, acquisition, implementation, changes (including emergency changes), and maintenance of information systems. | |
System description maintained A description of the system, its boundaries, and its components is maintained for audit purposes. | |
Whistleblower policy established A formalized whistleblower policy and an anonymous communication channel allow reporting of potential issues or fraud concerns. | |
Board oversight briefings conducted Leadership is briefed at least annually on the state of cybersecurity and privacy risk, and provides feedback and direction as needed. |
1 to 10 of 17 results
Data and privacy
How data is classified, retained, and returned or destroyed.
| Control | Status |
|---|---|
Data retention procedures established Formal retention and disposal procedures guide the secure retention and disposal of company and customer data. | |
Customer data deleted upon leaving Customer data containing confidential information is purged from the application environment in accordance with best practices when customers leave the service. | |
Data classification policy established A data classification policy ensures confidential data, including protected health information, is properly secured and restricted to authorized personnel. | |
Privacy notice published A public privacy notice describes what personal data is collected, why, and how individuals can exercise their rights. | |
Data subject request procedures established Procedures exist to respond to access, correction, and deletion requests within regulatory timelines. | |
Business Associate Agreements executed Business Associate Agreements are executed with covered-entity customers and with subprocessors that handle PHI. |