Skip to content

Latest commit

 

History

History
60 lines (49 loc) · 5.31 KB

21-3rd_party_policy.md

File metadata and controls

60 lines (49 loc) · 5.31 KB
layout
default

21. 3rd Party Policy

Health Note makes every effort to assure all 3rd party organizations are compliant and do not compromise the integrity, security, and privacy of Health Note or Health Note Customer data. 3rd Parties include Customers, Partners, Subcontractors, and Contracted Developers.

21.1 Applicable Standards

21.1.1 Applicable Standards from the HITRUST Common Security Framework

  • 05.i - Identification of Risks Related to External Parties
  • 05.k - Addressing Security in Third Party Agreements
  • 09.e - Service Delivery
  • 09.f - Monitoring and Review of Third Party Services
  • 09.g - Managing Changes to Third Party Services
  • 10.1 - Outsourced Software Development

21.1.2 Applicable Standards from the HIPAA Security Rule

  • 164.314(a)(1)(i) - Business Associate Contracts or Other Arrangements

21.2 Policies to Assure 3rd Parties Support Health Note Compliance

  1. Health Note does not allow 3rd party access to production systems containing ePHI.
  2. All connections and data in transit between the Health Note Platform and 3rd parties are encrypted end to end.
  3. A standard business associate agreement with Customers and Partners is defined and includes the required security controls in accordance with the organization's security policies. Additionally, responsibility is assigned in these agreements.
  4. Health Note has Service Level Agreements (SLAs) with Subcontractors with an agreed service arrangement addressing liability, service definitions, security controls, and aspects of services management.
    • Subcontractors must coordinate, manage, and communicate any changes to services provided to Health Note.
    • Changes to 3rd party services are classified as configuration management changes and thus are subject to the policies and procedures described in §9; substantial changes to services provided by 3rd parties will invoke a Risk Assessment as described in §4.2.
    • Health Note utilizes monitoring tools to regularly evaluate Subcontractors against relevant SLAs.
  5. No Health Note Customers or Partners have access outside of their own environment, meaning they cannot access, modify, or delete anything related to other 3rd parties.
  6. Health Note does not outsource software development.
  7. Health Note maintains and annually reviews a list all current Partners and Subcontractors.
    • The list of current Partners and Subcontractors is maintained by the Health Note Privacy Officer, includes details on all provided services (along with contact information), and is recorded in [§1.4](#1.4-Health Note-organizational-concepts).
    • The annual review of Partners and Subcontractors is conducted as a part of the security, compliance, and SLA review referenced below.
  8. Health Note assesses security, compliance, and SLA requirements and considerations with all Partners and Subcontractors. This includes annual assessment of SOC2 reports for all Health Note infrastructure partners.
    • Health Note leverages recurring calendar invites to assure reviews of all 3rd party services are performed annually. These reviews are performed by the Health Note Security Officer and Privacy Officer. The process for reviewing 3rd party services is outlined below:
      1. The Security Officer initiates the SLA review by creating an Issue in the Health Note Quality Management System.
      2. The Security Officer, or Privacy Officer, is assigned to review the SLA and performance of 3rd parties. The list of current 3rd parties, including contact information, is also reviewed to assure it is up to date and complete.
      3. SLA, security, and compliance performance is documented in the Issue.
      4. Once the review is completed and documented, the Security Officer approves or rejects the Issue. If the Issue is rejected, it goes back for further review and documentation.
  9. Regular review is conducted as required by SLAs to assure security and compliance. These reviews include reports, audit trails, security events, operational issues, failures and disruptions, and identified issues are investigated and resolved in a reasonable and timely manner.
  10. Any changes to Partner and Subcontractor services and systems are reviewed before implementation.
  11. For all partners, Health Note reviews activity annually to assure partners are in line with SLAs in contracts with Health Note.
  12. SLA review is monitored on a quarterly basis using the Quality Management System reporting to assess compliance with above policy.
  13. The 3rd Party Assurance process is reviewed annually and updated to include any necessary changes.
  14. Changes to the 3rd Party Assurance process will also be made on an ad-hoc basis in cases where operational changes require it or if the process is found lacking.

Revisions

Revision Date Revision Description Notes
4/18/2019 Initial Initial
4/14/2020 Reviewed No changes
3/29/2021 Reviewed No changes
2/24/2022 Reviewed No changes
4/10/2023 Reviewed No changes
5/02/2024 Reviewed No changes