HIPAA COMPLIANCE
Through HIPAA (Health Insurance Portability and Accountability) the United States is providing privacy standards to protect patients’ medical records and other health information provided to health plans, doctors, hospitals and other health care providers.
HIPAA is an effective compliance at ConveyThis and requires a number of things:
Security Incidents – ConveyThis will track unauthorized access attempts in an effort to reduce risk and exposure to threats from outside network attacks and malware.
Access Management – ConveyThis’s requests to/from our servers are made over encrypted https (TLS 1.2/1.1) using only the most secure cipher suites.
Encryption and Decryption – ConveyThis infrastructure is a multitenant public cloud solution with the ability to segregate data by tenant on their own dedicated instance. All User information is encrypted in the ConveyThis DB.
Key Management – The key management service we utilize takes advantage of Hardware Security Modules to protect the security of the keys.
Logging and Audit Controls – HTTPS is the only form of communication allowed to the ConveyThis API. The SSL certificate can (and should) be validated in the client’s web browser. All security incidents are escalated to senior technical staff and when found to be true threats are logged against internal ticketing system for mitigation.
Monitoring – ConveyThis monitors all servers and network hardware the application is running on. Roles Based Management can be used to restrict access to those users who should not have access to PHI information.
Additional Security Incidents – Security incidents are communicated to administrators through email/text/phone call and require recognition to close incident or same notifications remains open and hits additional administrators. At ConveyThis, we are always staying up to date with privacy trends for our customers. ConveyThis’s security framework is based on the ISO 27001 Information Security Standard and includes security mechanisms that cover:
ConveyThis Personnel Security
Product Security
Cloud and Network Infrastructure Security
Continuous Monitoring and Vulnerability Management
Physical Security
Business Continuity and Disaster Recovery
Third Party Security
Security Compliance
Security is represented at the highest levels of the company, with our Chief Information Security Officer meeting with executive management regularly to discuss issues and coordinate company wide security initiatives. These policies and standards are available to all of our employees.
GDPR COMPLIANCE
Hier bei ConveyThis gab es schon immer eine Kultur der Compliance. Wir legen enormen Wert auf die Privatsphäre, insbesondere auf Ihre Privatsphäre. Deshalb informieren wir Sie über einige der jüngsten Änderungen, die wir in Bezug auf unsere vorgenommen haben Allgemeine Geschäftsbedingungen „ Datenschutzrichtlinien. Diese Richtlinienaktualisierungen treten ab dem 2/07/2019 in vollem Umfang in Kraft.
Diese Änderungen sind eine Folge der jüngsten Regelungen der Datenschutz-Grundverordnung (DSGVO) der Europäischen Union. Wir gehen davon aus, dass alle unsere Benutzer von diesen Rechten profitieren und sie gerne genießen würden, daher führen wir sie weltweit für alle ein.
Hier ist eine Übersicht über einige dieser jüngsten Updates:
- Wir haben eine globale “Opt-out-Seite” erstellt. Wir wollen dich nicht verlieren und wir möchten glauben, dass du uns auch wirklich sehr vermissen wirst. Aber wenn du wirklich gehen musst – wir verstehen es! Wir werden immer noch für Sie da sein, wenn Sie Ihre Meinung ändern.
- Wir haben es Ihnen viel einfacher gemacht, Ihre Kommunikationspräferenzen zu aktualisieren.
- Wir haben alle unsere Richtlinien neu organisiert, damit sie leichter zu finden und auch leichter zu lesen und zu verstehen sind. In unserem Hilfebereich gibt es auch viele neue Informationen (einige schöne, leichte Lesestoffe am Krankenbett) für Sie!
- Wir haben Informationen darüber beigefügt, wie wir Cookies verwenden und andere Webanalysetechnologien nutzen, sowie eine neue Cookie-Richtlinie an Ort und Stelle.
- Wir haben ConveyThis klarere Einzelheiten darüber gegeben, wie wir mit allen unseren Partnern und anderen Drittanbietern zusammenarbeiten. Wir erläutern außerdem detailliert, wie wir sicherstellen, dass unsere Partner alle für Sie wichtigen regulatorischen Fragen einhalten.
- Wir haben die erforderlichen Datenschutz- und Sicherheitskontrollen in die gesamte ConveyThis-Plattform integriert, um die Einhaltung der Vorschriften und Ihre Sicherheit zu gewährleisten!
Data Sovereignty
ConveyThis data centers are strategically located in the US and Canada to ensure compliance with regional data sovereignty requirements.
If you have additional questions about HIPAA, Privacy or GDPR compliance at ConveyThis please contact us directly at [E-Mail geschützt]
Thanks so much for choosing ConveyThis!
