Überblick

Warum ist der Health Insurance Portability and Accountability Act (HIPAA) für Alohi wichtig?

HIPAA ist für Alohi von entscheidender Bedeutung, da es uns dabei hilft, Patientengesundheitsdaten so privat und sicher wie möglich zu behandeln. Unser Engagement für Exzellenz beinhaltet die sorgfältige Einhaltung der strengen Standards, die von HIPAA festgelegt werden. Durch die sorgfältige Implementierung aller erforderlichen administrativen, physischen und technischen Schutzmaßnahmen stellen wir die umfassende Einhaltung der Vorschriften sicher.

Ärzte, Krankenhäuser, Versicherer und andere im Gesundheitswesen tätige Unternehmen vertrauen Alohi, da unser Ansatz die besten Praktiken der Branche widerspiegelt. Dies etabliert Alohi als Maßstab für Datenschutz und Sicherheit im Gesundheitsinformationsmanagement.

Daten

Welche Datenschutzverfahren und -richtlinien hat Alohi?

At Alohi, we are deeply committed to protecting your data through meticulous monitoring, advanced encryption, secure handling practices, and a commitment to continual improvement, ensuring the utmost standards of data protection and regulatory compliance. Here is our approach:

Access Control

In the Alohi Suite, we vigilantly monitor every file transfer, automatically archiving each one. This allows us to maintain oversight over who accesses our systems, especially those that manage sensitive health information (ePHI).

Data Encryption & Secure Transmission

All stored files at rest, including signed and faxed documents, are encrypted using 256-bit Advanced Encryption Standard (AES). Each user benefits from unique encryption keys to ensure their data's security.

Audit Trails

Sign.Plus and Fax.Plus maintain comprehensive records of all documents sent or received, enabling thorough retrospective analysis. Our systems and policies are designed for strict monitoring of activities, especially concerning ePHI, to ensure robust oversight.

User Authentication

Accessing Alohi Suite requires a unique identifier like an email or a securely encrypted username and password. Each login is authenticated with a unique digital ID cookie, securing your session from beginning to end.

No-Storage Option

Alohi Suite offers you the choice to bypass storing your data on our servers. If selected, incoming documents are directly emailed to you without being saved on our end, and outgoing documents are deleted immediately after transmission.

Data Deletion

Should you choose to end your service with an Alohi product, you can request the removal of all your data from our servers. We ensure no paper trails are left; any necessary printed materials are destroyed immediately after use.

Fortified Data Centers

Our data centers are secure strongholds, adhering to the highest security standards and certifications. Designed to safeguard your information rigorously, they comply with a multitude of security frameworks and certifications.

Continuous Security Enhancement

We proactively identify risks and fortify our security measures, including regular updates to our policies, ongoing staff training, security assessments of our applications and networks, risk evaluations, and strict adherence to regulatory compliance.

Additional robust measures incorporated by Alohi:

  • 256-Bit-AES-Verschlüsselung für gespeicherte, signierte und gefaxte Dokumente.
  • Erzwungenes HTTPS mit sicherem SSL/TLS-Zertifikat.
  • Datensicherungen werden in gesicherten, erstklassigen Rechenzentren gespeichert.
  • Authentifizierung des Kontoinhabers.
  • Beschränkter externer Zugriff auf alle Server und Produktionsarbeitsplätze.
  • Ausgeklügeltes Überwachungs- und Eskalationssystem.
  • Automatisierte Datensicherungen.
  • Automatisierte Virenprüfung.
  • Meldung jeglicher Nichteinhaltung, von der wir Kenntnis erlangen.
  • Benachrichtigung bei Datenschutzverletzungen.
  • Der Zugriff auf Produktionssysteme ist mit eindeutigen SSH-Schlüsselpaaren beschränkt.
  • Alle Mitarbeiter durchlaufen gründliche Hintergrundüberprüfungen und sind verpflichtet, im Rahmen ihres Arbeitsvertrags eine Vertraulichkeitsvereinbarung zu unterzeichnen.
  • Alle Mitarbeiter werden gemäß den HIPAA-Vorgaben zu unseren Richtlinien und Verfahren geschult.
  • Ernennung eines HIPAA Security Official, der unsere HIPAA-Richtlinien und -Verfahren erstellt, pflegt und Schulungen dazu durchführt.