Turbo Law Inc.

Turbo Law Inc.

Trust Center

Turbo Law is the litigation operating system for law firms and insurance carriers.

Its unified AI platform supports case review, drafting, research, strategy, and assistance in one workspace built for complex litigation.

Controls

Comprehensive overview of the security control frameworks we run — grouped by category so you can jump straight to the domain you care about.

Control Environment

  • Security awareness training implemented

    Employees are required to complete security awareness training within 30 days of being hired and at least once a year thereafter.

  • Compliance with policies, rules and standards for information security

    The organization conducts regular reviews to ensure compliance with its information security policy, topic-specific policies, rules, and standards.

  • Code of Conduct acknowledged by contractors

    The company mandates that contractor agreements either include a code of conduct or refer to the company’s own code of conduct.

  • Board meetings conducted

    The board of directors meets at least once a year and keeps formal minutes of its meetings. It includes members who are independent of the company.

  • Audit controls implemented

    The company has implemented hardware, software, and procedural mechanisms to log and review activity within information systems that store or process electronic Protected Health Information (ePHI).

  • Board charter documented

    The board of directors has a formal charter that defines its oversight responsibilities related to internal controls.

  • Security policies established and reviewed

    The company’s information security policies and procedures are formally documented and reviewed at least once a year.

  • Employee background checks performed

    The company conducts background screenings for all new hires.

  • Performance evaluations conducted

    Managers are required to conduct performance evaluations for their direct reports at least once a year.

  • Code of Conduct acknowledged by employees and enforced

    Employees are required to acknowledge the code of conduct upon hiring. Any violations may result in disciplinary action as outlined in the company’s disciplinary policy.

  • Board oversight briefings conducted

    Senior management briefs the board of directors, or an appropriate subcommittee, at least once a year on the company’s cybersecurity and privacy risk posture. The board offers guidance and feedback to management as necessary.

  • Board expertise developed

    The board possesses the necessary expertise to oversee management’s design, implementation, and operation of information security controls, and consults external security experts when needed.

Communication and Information

  • System changes communicated

    The company notifies authorized internal users of system changes.

  • SOC 2 - System Description

    Provide a complete overview of your system for inclusion in Section III of the audit report.

  • Security policies established and reviewed

    The company’s information security policies and procedures are formally documented and reviewed at least once a year.

  • Data integrity maintained

    The company has implemented policies and procedures to safeguard electronic Protected Health Information (ePHI) against unauthorized alteration or destruction.

  • System changes externally communicated

    The company informs customers of critical system changes that could impact their processing.

  • Code of Conduct acknowledged by employees and enforced

    Employees are required to acknowledge the code of conduct upon hiring. Any violations may result in disciplinary action as outlined in the company’s disciplinary policy.

  • Third-party agreements established

    The company maintains written agreements with vendors and third parties, which include applicable confidentiality and privacy commitments.

Risk Assessment

  • Infrastructure performance monitored

    The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.

  • Compliance with policies, rules and standards for information security

    The organization conducts regular reviews to ensure compliance with its information security policy, topic-specific policies, rules, and standards.

  • Risk assessment objectives specified

    The company defines its objectives to support the identification and assessment of risks associated with achieving them.

  • Annual risk assessment performed annually

    The company performs the risk assessment process at least annually and whenever significant changes occur in the environment, such as acquisitions, mergers, or relocations.

  • Audit controls implemented

    The company has implemented hardware, software, and procedural mechanisms to log and review activity within information systems that store or process electronic Protected Health Information (ePHI).

  • Risk management program established

    The company maintains a documented risk management program that provides guidance on identifying potential threats, assessing the significance of associated risks, and implementing mitigation strategies.

  • Risks assessments performed

    The company performs risk assessments at least annually. This process includes identifying threats and changes (environmental, regulatory, and technological) that may affect service commitments, formally assessing the related risks, and considering how potential fraud could impact the achievement of objectives.

  • Change management procedures enforced

    The company requires changes to software and infrastructure components to be authorized, documented, tested, reviewed, and approved before being implemented in the production environment.

Monitoring Activities

  • Security controls evaluated

    The company conducts periodic technical and nontechnical evaluations, initially based on the HIPAA Security Rule, and subsequently in response to environmental or operational changes affecting the security of electronic Protected Health Information (ePHI), to determine whether its security policies and procedures continue to meet the requirements of the HIPAA Security Rule (Subpart C).

  • Critical system review performed quarterly

    For service providers, the company performs reviews at least quarterly to confirm personnel comply with security policies and operational procedures.

  • Nonconformity and corrective action

    When a nonconformity is identified, the organization: 1. Responds to the issue by: a) Taking action to control and correct it b) Addressing any resulting consequences 2. Assesses the need for action to prevent recurrence or occurrence elsewhere by: a) Reviewing the nonconformity b) Identifying its root causes c) Determining whether similar issues exist or could potentially arise 3. Implements necessary corrective actions 4. Evaluates the effectiveness of those actions 5. Updates the information security management system as needed Corrective actions are proportionate to the impact of the nonconformities. Documented information is retained to demonstrate: 1. The nature of the nonconformities and the actions taken 2. The results of any corrective actions

  • Audit controls implemented

    The company has implemented hardware, software, and procedural mechanisms to log and review activity within information systems that store or process electronic Protected Health Information (ePHI).

  • Board oversight briefings conducted

    Senior management briefs the board of directors, or an appropriate subcommittee, at least once a year on the company’s cybersecurity and privacy risk posture. The board offers guidance and feedback to management as necessary.

Control Activities

  • Security controls evaluated

    The company conducts periodic technical and nontechnical evaluations, initially based on the HIPAA Security Rule, and subsequently in response to environmental or operational changes affecting the security of electronic Protected Health Information (ePHI), to determine whether its security policies and procedures continue to meet the requirements of the HIPAA Security Rule (Subpart C).

  • Documentation change control

    System documentation shall be subject to revision and change control procedures that maintain an audit trail documenting time-sequenced development and modifications.

  • Operational system checks

    Operational system checks shall be used, as appropriate, to enforce permitted sequencing of steps and events.

  • Compliance with policies, rules and standards for information security

    The organization conducts regular reviews to ensure compliance with its information security policy, topic-specific policies, rules, and standards.

  • Audit controls implemented

    The company has implemented hardware, software, and procedural mechanisms to log and review activity within information systems that store or process electronic Protected Health Information (ePHI).

  • Risk management program established

    The company maintains a documented risk management program that provides guidance on identifying potential threats, assessing the significance of associated risks, and implementing mitigation strategies.

  • Development lifecycle established

    The company has a formal systems development life cycle (SDLC) methodology that governs the development, acquisition, implementation, maintenance, and changes (including emergency changes) of information systems and related technology requirements.

  • Security policies established and reviewed

    The company’s information security policies and procedures are formally documented and reviewed at least once a year.

Logical and Physical Access Controls

  • Network firewalls utilized

    The company uses firewalls configured to block unauthorized access.

  • Physical access processes established

    The company has processes for granting, modifying, and revoking physical access to data centers based on authorization from control owners.

  • Data transmission encrypted

    The company uses secure transmission protocols to encrypt confidential and sensitive data when it is transmitted over public networks.

  • Intrusion detection system utilized

    The company uses an intrusion detection system to continuously monitor its network and detect potential security breaches early.

  • System access limitation

    System access shall be restricted to authorized individuals.

  • Data deletion requests handled

    The company validates deletion requests, and once confirmed, flags and deletes the requested information in accordance with applicable laws and regulations.

  • Password policy enforced

    The company requires passwords for in-scope system components to be configured in accordance with its policy.

  • Authority checks

    Authority checks shall restrict system use, electronic signing, access to operations or system input/output devices, record alteration, and performance of the operation at hand to authorized individuals.

  • Firewall access restricted

    The company limits privileged access to the firewall to authorized users who have a valid business need.

  • Data encryption utilized

    The company encrypts datastores containing sensitive customer data at rest.

  • Network segmentation implemented

    The company’s network is segmented to block unauthorized access to customer data.

  • Security patches installed within one month

    The company installs critical security patches within one month of their release, as determined by the risk ranking process defined in VPM-4.

  • Securely dispose of data

    The organization securely disposes of data in accordance with the documented data management process, ensuring that disposal methods are appropriate for the sensitivity of the data.

  • Production data segmented

    The company purges or removes customer data containing confidential information from the application environment in accordance with best practices when customers discontinue the service.

  • Visitor procedures enforced

    The company requires visitors to sign in, wear a visitor badge, and be escorted by an authorized employee when accessing the data center or other secure areas.

  • Access reviews conducted

    The company performs access reviews at least quarterly for in-scope system components to ensure access is appropriately restricted. Required changes are tracked to completion.

  • Remote access encrypted enforced

    The company restricts remote access to production systems to authorized employees using an approved encrypted connection.

  • Asset disposal procedures utilized

    The company ensures electronic media containing confidential information is purged or destroyed following best practices, with certificates of destruction issued for each device.

  • Data center access reviewed

    The company reviews data center access at least once a year.

  • Access control procedures established

    The company’s access control policy outlines requirements for the following access control functions: 1. Adding new users 2. Modifying users 3. Removing user access

  • Malicious software protection implemented

    The company has implemented procedures to guard against, detect, and report malicious software.

System Operations

  • Intrusion detection system utilized

    The company uses an intrusion detection system to continuously monitor its network and detect potential security breaches early.

  • Infrastructure performance monitored

    The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.

  • Incident response plan tested

    The company tests its incident response plan at least once a year.

  • Incident response policies established

    The company has documented security and privacy incident response policies and procedures, which are communicated to authorized users.

  • Vulnerability and system monitoring procedures established

    The company’s formal policies define requirements for the following IT and engineering functions: 1. Vulnerability management 2. System monitoring

  • Security vulnerabilities identification process exists

    The company maintains a process for identifying security vulnerabilities that includes: 1. Using reputable external sources to obtain current vulnerability information 2. Assigning risk rankings to identified vulnerabilities, clearly highlighting all high-risk and critical issues Risk rankings follow industry best practices and consider factors such as CVSS base scores, vendor classifications, and the affected system types. The risk assessment strategy ensures that all high-risk vulnerabilities are identified and that critical vulnerabilities, including those impacting public-facing systems, security infrastructure, or systems processing cardholder data, are addressed promptly.

  • Incident management procedures followed

    The company’s security and privacy incidents are logged, tracked, resolved, and communicated to affected or relevant parties by management in accordance with its security incident response policy and procedures.

  • Continuity and disaster recovery plans tested

    The company has a documented Business Continuity and Disaster Recovery (BC/DR) plan, which is tested at least once a year.

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

  • Audit controls implemented

    The company has implemented hardware, software, and procedural mechanisms to log and review activity within information systems that store or process electronic Protected Health Information (ePHI).

  • Vulnerabilities scanned and remediated

    Host-based vulnerability scans are conducted at least quarterly on all externally facing systems, with critical and high-risk vulnerabilities tracked through to remediation.

  • Log management utilized

    The company uses a log management tool to detect events that could potentially affect its ability to meet security objectives.

Change Management

  • Documentation change control

    System documentation shall be subject to revision and change control procedures that maintain an audit trail documenting time-sequenced development and modifications.

  • Production deployment access restricted

    The company restricts production change migrations to authorized personnel only.

  • Development lifecycle established

    The company has a formal systems development life cycle (SDLC) methodology that governs the development, acquisition, implementation, maintenance, and changes (including emergency changes) of information systems and related technology requirements.

  • Change management procedures enforced

    The company requires changes to software and infrastructure components to be authorized, documented, tested, reviewed, and approved before being implemented in the production environment.

Risk Mitigation

  • Vendor management program established

    The company has a vendor management program in place that includes: 1. Critical third-party vendor inventory 2. Vendor security and privacy requirements 3. Review of critical third-party vendors at least annually

  • Continuity and disaster recovery plans tested

    The company has a documented Business Continuity and Disaster Recovery (BC/DR) plan, which is tested at least once a year.

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

  • Risk management program established

    The company maintains a documented risk management program that provides guidance on identifying potential threats, assessing the significance of associated risks, and implementing mitigation strategies.

  • Risks assessments performed

    The company performs risk assessments at least annually. This process includes identifying threats and changes (environmental, regulatory, and technological) that may affect service commitments, formally assessing the related risks, and considering how potential fraud could impact the achievement of objectives.

  • Third-party agreements established

    The company maintains written agreements with vendors and third parties, which include applicable confidentiality and privacy commitments.

Additional Criteria for Availability

  • Critical system review performed quarterly

    For service providers, the company performs reviews at least quarterly to confirm personnel comply with security policies and operational procedures.

  • Production data backups conducted

    The company performs periodic backups of production data, storing the backups in a separate location from the production environment.

  • Infrastructure performance monitored

    The company uses an infrastructure monitoring tool to track systems, infrastructure, and performance, generating alerts when predefined thresholds are reached.

  • Incident response plan tested

    The company tests its incident response plan at least once a year.

  • Production multi-availability zones established

    The company employs a multi-location strategy for production environments to enable operations to resume at alternate data centers if a facility becomes unavailable.

  • Database replication utilized

    The company’s databases are replicated in real time to a secondary data center, with alerts set up to notify administrators of any replication failures.

  • Continuity and disaster recovery plans tested

    The company has a documented Business Continuity and Disaster Recovery (BC/DR) plan, which is tested at least once a year.

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

  • Environmental monitoring devices implemented

    The company uses environmental monitoring devices configured to automatically alert management in the event of environmental incidents.

Additional Criteria for Confidentiality

  • Data deletion requests handled

    The company validates deletion requests, and once confirmed, flags and deletes the requested information in accordance with applicable laws and regulations.

  • Data encryption utilized

    The company encrypts datastores containing sensitive customer data at rest.

  • Data classification policy established

    The company has a data classification policy to ensure confidential data is properly secured and accessible only to authorized personnel.

  • Securely dispose of data

    The organization securely disposes of data in accordance with the documented data management process, ensuring that disposal methods are appropriate for the sensitivity of the data.

  • Production data segmented

    The company purges or removes customer data containing confidential information from the application environment in accordance with best practices when customers discontinue the service.

  • Asset disposal procedures utilized

    The company ensures electronic media containing confidential information is purged or destroyed following best practices, with certificates of destruction issued for each device.

Additional Criteria for Processing integrity

  • Production data backups conducted

    The company performs periodic backups of production data, storing the backups in a separate location from the production environment.

  • Establish and maintain a data management process

    The organization establishes and maintains a documented data management process that addresses, at a minimum: 1. Data sensitivity 2. Data owner 3. Data handling 4. Data retention limits 5. Data disposal requirements The organization aligns these elements with enterprise sensitivity and retention standards and reviews and updates the documentation annually or upon significant changes that could impact this control.

  • Operational system checks

    Operational system checks shall be used, as appropriate, to enforce permitted sequencing of steps and events.

  • Compliance with policies, rules and standards for information security

    The organization conducts regular reviews to ensure compliance with its information security policy, topic-specific policies, rules, and standards.

  • SOC 2 - System Description

    Provide a complete overview of your system for inclusion in Section III of the audit report.

  • Data integrity maintained

    The company has implemented policies and procedures to safeguard electronic Protected Health Information (ePHI) against unauthorized alteration or destruction.

  • Processing data inputs validated

    The company’s system evaluates data inputs for compliance with input requirements and generates on-screen alerts when issues with transaction inputs or processing are detected.

  • System validation

    Persons who use closed systems to create, modify, maintain, or transmit electronic records shall validate those systems for accuracy, reliability, consistent intended performance, and the ability to detect invalid or altered records.

  • Customer data retained

    The company retains customer transaction data for the duration of the customer account. Historical transaction data is not purged until the account is deleted.

Administrative safeguards

  • Employee background checks performed

    The company conducts background screenings for all new hires.

  • Roles and responsibilities specified

    Responsibilities for the design, development, implementation, operation, maintenance, and monitoring of information security controls are formally defined in job descriptions and/or the Information Security Roles and Responsibilities policy.

  • Security awareness training implemented

    Employees are required to complete security awareness training within 30 days of being hired and at least once a year thereafter.

  • Vulnerabilities scanned and remediated

    Host-based vulnerability scans are conducted at least quarterly on all externally facing systems, with critical and high-risk vulnerabilities tracked through to remediation.

  • Security policies established and reviewed

    The company’s information security policies and procedures are formally documented and reviewed at least once a year.

  • Incident response policies established

    The company has documented security and privacy incident response policies and procedures, which are communicated to authorized users.

  • Third-party agreements established

    The company maintains written agreements with vendors and third parties, which include applicable confidentiality and privacy commitments.

  • Risk assessment objectives specified

    The company defines its objectives to support the identification and assessment of risks associated with achieving them.

  • Risk management program established

    The company maintains a documented risk management program that provides guidance on identifying potential threats, assessing the significance of associated risks, and implementing mitigation strategies.

  • Continuity and disaster recovery plans tested

    The company has a documented Business Continuity and Disaster Recovery (BC/DR) plan, which is tested at least once a year.

  • Risks assessments performed

    The company performs risk assessments at least annually. This process includes identifying threats and changes (environmental, regulatory, and technological) that may affect service commitments, formally assessing the related risks, and considering how potential fraud could impact the achievement of objectives.

  • Access control procedures established

    The company’s access control policy outlines requirements for the following access control functions: 1. Adding new users 2. Modifying users 3. Removing user access

  • Change management procedures enforced

    The company requires changes to software and infrastructure components to be authorized, documented, tested, reviewed, and approved before being implemented in the production environment.

  • Backup processes established

    The company’s data backup policy defines the requirements for backing up and recovering customer data.

  • Access requests required

    The company ensures that access to in-scope system components is based on job role and function or requires a documented access request and manager approval before access is granted.

  • Password policy enforced

    The company requires passwords for in-scope system components to be configured in accordance with its policy.

  • Access reviews conducted

    The company performs access reviews at least quarterly for in-scope system components to ensure access is appropriately restricted. Required changes are tracked to completion.

  • Access revoked upon termination

    The company uses termination checklists to ensure access for terminated employees is revoked within defined SLAs.

  • Vulnerability and system monitoring procedures established

    The company’s formal policies define requirements for the following IT and engineering functions: 1. Vulnerability management 2. System monitoring

  • Incident response plan tested

    The company tests its incident response plan at least once a year.

  • Production data backups conducted

    The company performs periodic backups of production data, storing the backups in a separate location from the production environment.

  • Private data shared upon request

    The company provides requested information, after verification, in a timely manner either in a portable electronic format or by mail, in compliance with applicable law.

  • Sanction policy applied

    The company enforces appropriate sanctions against workforce members who fail to comply with its security policies and procedures.

  • Security incidents identified and reported

    The company identifies and responds to suspected or known security incidents, mitigates harmful effects to the extent practicable, and documents the incidents along with their outcomes.

  • Contingency plan established

    The company has established and implements, as needed, policies and procedures for responding to emergencies or other events (such as fire, vandalism, system failure, or natural disaster) that may damage systems containing electronic Protected Health Information (ePHI).

  • Contingency plan tested and revised

    The company has implemented procedures for the periodic testing and revision of contingency plans.

  • Security controls evaluated

    The company conducts periodic technical and nontechnical evaluations, initially based on the HIPAA Security Rule, and subsequently in response to environmental or operational changes affecting the security of electronic Protected Health Information (ePHI), to determine whether its security policies and procedures continue to meet the requirements of the HIPAA Security Rule (Subpart C).

  • Contingency operations established

    The company has established procedures, to be implemented when needed, that allow facility access during emergencies in order to support data restoration as outlined in the disaster recovery and emergency mode operations plans.

  • Audit controls implemented

    The company has implemented hardware, software, and procedural mechanisms to log and review activity within information systems that store or process electronic Protected Health Information (ePHI).

  • Sub-processor changes

    The company issues written notice to the customer upon any changes to sub-processors and provides an opportunity for the customer to raise objections in accordance with contractual requirements.

  • Contracts with PII processors

    The company enters into a written agreement with each processor of personally identifiable information (PII), defining the processor’s responsibilities and required compliance with applicable data protection standards.

  • Compliance with policies, rules and standards for information security

    The organization conducts regular reviews to ensure compliance with its information security policy, topic-specific policies, rules, and standards.

  • Threats and vulnerabilities regularly addressed

    For public-facing web applications, the company addresses new threats and vulnerabilities on an ongoing basis and protects these applications against known attacks by implementing one of the following methods: 1. Conducting manual or automated application vulnerability assessments that: a) Occur at least annually and after any changes b) Are performed by organizations specializing in application security c) Include all vulnerabilities d) Ensure that all identified vulnerabilities are corrected e) Include re-evaluation of the application following remediation 2. Deploying an automated technical solution, such as a web application firewall, that: a) Is positioned in front of public-facing web applications to detect and prevent attacks b) Is actively running and kept up to date c) Generates audit logs d) Is configured to either block detected web-based attacks or generate alerts that are promptly investigated

  • System audit trails enabled and active

    The company ensures that audit trails are enabled and active on all system components to record relevant security events.

  • System access linked to individual users

    The company ensures that access to system components is linked to individual users to maintain accountability and traceability.

  • Critical system review performed quarterly

    For service providers, the company performs reviews at least quarterly to confirm personnel comply with security policies and operational procedures.

  • System access restricted to authorized access only

    The organization shall limit system access exclusively to authorized users, processes operating on behalf of authorized users, and approved devices, including interconnected systems.

  • Unique accounts, services, and processes are in use

    The organization shall identify system users, processes operating on behalf of users, and devices.

Physical safeguards

  • Access control procedures established

    The company’s access control policy outlines requirements for the following access control functions: 1. Adding new users 2. Modifying users 3. Removing user access

  • Change management procedures enforced

    The company requires changes to software and infrastructure components to be authorized, documented, tested, reviewed, and approved before being implemented in the production environment.

  • Production inventory maintained

    The company maintains a formal inventory of assets within the production environment.

  • Data classification policy established

    The company has a data classification policy to ensure confidential data is properly secured and accessible only to authorized personnel.

  • Physical access processes established

    The company has processes for granting, modifying, and revoking physical access to data centers based on authorization from control owners.

  • Data center access reviewed

    The company reviews data center access at least once a year.

  • Visitor procedures enforced

    The company requires visitors to sign in, wear a visitor badge, and be escorted by an authorized employee when accessing the data center or other secure areas.

  • Asset disposal procedures utilized

    The company ensures electronic media containing confidential information is purged or destroyed following best practices, with certificates of destruction issued for each device.

  • Production data segmented

    The company purges or removes customer data containing confidential information from the application environment in accordance with best practices when customers discontinue the service.

  • Portable media encrypted

    The company encrypts portable and removable media devices when in use.

  • MDM system utilized

    The company uses a mobile device management (MDM) system to centrally manage mobile devices that support the service.

  • Production data backups conducted

    The company performs periodic backups of production data, storing the backups in a separate location from the production environment.

  • Production multi-availability zones established

    The company employs a multi-location strategy for production environments to enable operations to resume at alternate data centers if a facility becomes unavailable.

  • Environmental security inspected

    The company conducts maintenance inspections of environmental security measures at its data centers at least once a year.

  • Contingency operations established

    The company has established procedures, to be implemented when needed, that allow facility access during emergencies in order to support data restoration as outlined in the disaster recovery and emergency mode operations plans.

  • Maintenance records maintained

    The company has established policies and procedures to document all repairs and modifications to the physical components of its facilities that relate to security, including items such as hardware, walls, doors, and locks.

  • System audit trails enabled and active

    The company ensures that audit trails are enabled and active on all system components to record relevant security events.

  • Authority checks

    Authority checks shall restrict system use, electronic signing, access to operations or system input/output devices, record alteration, and performance of the operation at hand to authorized individuals.

Technical safeguards

  • Access control procedures established

    The company’s access control policy outlines requirements for the following access control functions: 1. Adding new users 2. Modifying users 3. Removing user access

  • Encryption key access restricted

    The company limits privileged access to encryption keys to authorized users who have a valid business need.

  • Production application access restricted

    System access is restricted to authorized users only.

  • Production database access restricted

    The company limits privileged database access to authorized users with a valid business need.

  • Production OS access restricted

    The company limits privileged access to the operating system to authorized users with a valid business need.

  • Unique network system authentication enforced

    The company requires authentication to the production network to use unique usernames and passwords or authorized SSH keys.

  • Data transmission encrypted

    The company uses secure transmission protocols to encrypt confidential and sensitive data when it is transmitted over public networks.

  • Network firewalls utilized

    The company uses firewalls configured to block unauthorized access.

  • Contingency operations established

    The company has established procedures, to be implemented when needed, that allow facility access during emergencies in order to support data restoration as outlined in the disaster recovery and emergency mode operations plans.

  • Audit controls implemented

    The company has implemented hardware, software, and procedural mechanisms to log and review activity within information systems that store or process electronic Protected Health Information (ePHI).

  • Mechanism to authenticate ePHI implemented

    The company has implemented electronic mechanisms to verify that electronic Protected Health Information (ePHI) has not been altered or destroyed without authorization.

  • System audit trails enabled and active

    The company ensures that audit trails are enabled and active on all system components to record relevant security events.

  • System access linked to individual users

    The company ensures that access to system components is linked to individual users to maintain accountability and traceability.

  • Enforce automatic device lockout on portable end-user devices (IG2, IG3)

    The organization enforces automatic device lockout on portable end-user devices, where supported, after a predetermined threshold of failed local authentication attempts. Laptops do not allow more than 20 failed attempts, and tablets or smartphones do not allow more than 10 failed attempts. Example implementations include Microsoft InTune Device Lock and Apple Configuration Profile maxFailedAttempts.

  • System access restricted to authorized access only

    The organization shall limit system access exclusively to authorized users, processes operating on behalf of authorized users, and approved devices, including interconnected systems.

  • Unique accounts, services, and processes are in use

    The organization shall identify system users, processes operating on behalf of users, and devices.

Organizational requirements

  • Security policies established and reviewed

    The company’s information security policies and procedures are formally documented and reviewed at least once a year.

  • Third-party agreements established

    The company maintains written agreements with vendors and third parties, which include applicable confidentiality and privacy commitments.

  • Risk management program established

    The company maintains a documented risk management program that provides guidance on identifying potential threats, assessing the significance of associated risks, and implementing mitigation strategies.

  • Access control procedures established

    The company’s access control policy outlines requirements for the following access control functions: 1. Adding new users 2. Modifying users 3. Removing user access

  • Security incidents identified and reported

    The company identifies and responds to suspected or known security incidents, mitigates harmful effects to the extent practicable, and documents the incidents along with their outcomes.

  • Sub-processor changes

    The company issues written notice to the customer upon any changes to sub-processors and provides an opportunity for the customer to raise objections in accordance with contractual requirements.

  • Contracts with PII processors

    The company enters into a written agreement with each processor of personally identifiable information (PII), defining the processor’s responsibilities and required compliance with applicable data protection standards.

Policies, procedures and documentation requirements

  • Security policies established and reviewed

    The company’s information security policies and procedures are formally documented and reviewed at least once a year.

  • Customer data retained

    The company retains customer transaction data for the duration of the customer account. Historical transaction data is not purged until the account is deleted.

  • Retention of PII

    The company retains personally identifiable information (PII) only for the duration necessary to fulfill the purposes for which it was collected, in alignment with applicable data retention policies.

  • Contracts with PII processors

    The company enters into a written agreement with each processor of personally identifiable information (PII), defining the processor’s responsibilities and required compliance with applicable data protection standards.

  • Compliance with policies, rules and standards for information security

    The organization conducts regular reviews to ensure compliance with its information security policy, topic-specific policies, rules, and standards.

Notification by a business associate in the case of breach of unsecured Protected Health Information (PHI)

  • Security policies established and reviewed

    The company’s information security policies and procedures are formally documented and reviewed at least once a year.

  • Additional breach information

    A business associate provides the company, acting as a covered entity, with any additional information required for individual notifications, either at the time of notification or as soon as the information becomes available.

  • Notification of breach

    The company, in its role as a covered entity, requires all business associates to notify it upon the discovery of any breach involving unsecured protected health information. A breach is considered discovered by the business associate on the first day it becomes known or should have been known through the exercise of reasonable diligence. The business associate is regarded as having knowledge of the breach if any individual, other than the one responsible for the breach, who is an employee, officer, or agent of the business associate, is aware of it, as defined under the Federal common law of agency.

  • Timeliness of breach notification

    Unless a delay is requested for law enforcement purposes, a business associate must provide the breach notification required under the company’s Breach Notification Policy, as specified in IRO-15, without unreasonable delay and no later than 60 calendar days from the date the breach is discovered.

  • Breach notice identification of individuals

    A business associate’s breach notification includes, to the extent possible, the identification of each individual whose unsecured protected health information was, or is reasonably believed to have been, accessed, acquired, used, or disclosed in connection with the breach.

  • Breach policy and procedure

    The company establishes documented policies and procedures for responding to data breaches, which include defined notification processes to ensure timely communication to relevant stakeholders.