United States
HIPAA
For products that create, store or move protected health information (PHI) in the US.
- HIPAA Privacy and Security Rules
- Administrative, physical and technical safeguards mapped in discovery and built into the product.
- BAAs with every vendor
- Business associate agreements in place with each vendor that touches PHI, from hosting to messaging.
- Encryption at rest and in transit
- PHI is encrypted in the database, in backups and on every connection.
- Audit logging
- Every read and change of patient data is logged with who, what and when.
- Role-based access
- Each user sees only what their role requires, with access reviewed over time.
- Breach response plan
- A documented plan for detecting, containing and reporting incidents.