概述

为什么《健康保险流通与责任法案》(HIPAA) 对 Alohi 很重要?

HIPAA对于Alohi至关重要,因为它指导我们尽可能地保护患者健康信息的私密性和安全性。我们对卓越的承诺包括彻底遵守HIPAA制定的严格标准。通过认真实施每一项必需的行政、物理和技术保障措施,我们确保全面遵守其法规。

医生、医院、保险公司和其他从事医疗保健的实体信任Alohi,因为我们的方法反映了行业的最佳实践。这使Alohi成为医疗保健信息管理中隐私和安全的基准。

数据

Alohi 的数据保护程序和策略是什么?

At Alohi, we are deeply committed to protecting your data through meticulous monitoring, advanced encryption, secure handling practices, and a commitment to continual improvement, ensuring the utmost standards of data protection and regulatory compliance. Here is our approach:

Access Control

In the Alohi Suite, we vigilantly monitor every file transfer, automatically archiving each one. This allows us to maintain oversight over who accesses our systems, especially those that manage sensitive health information (ePHI).

Data Encryption & Secure Transmission

All stored files at rest, including signed and faxed documents, are encrypted using 256-bit Advanced Encryption Standard (AES). Each user benefits from unique encryption keys to ensure their data's security.

Audit Trails

Sign.Plus and Fax.Plus maintain comprehensive records of all documents sent or received, enabling thorough retrospective analysis. Our systems and policies are designed for strict monitoring of activities, especially concerning ePHI, to ensure robust oversight.

User Authentication

Accessing Alohi Suite requires a unique identifier like an email or a securely encrypted username and password. Each login is authenticated with a unique digital ID cookie, securing your session from beginning to end.

No-Storage Option

Alohi Suite offers you the choice to bypass storing your data on our servers. If selected, incoming documents are directly emailed to you without being saved on our end, and outgoing documents are deleted immediately after transmission.

Data Deletion

Should you choose to end your service with an Alohi product, you can request the removal of all your data from our servers. We ensure no paper trails are left; any necessary printed materials are destroyed immediately after use.

Fortified Data Centers

Our data centers are secure strongholds, adhering to the highest security standards and certifications. Designed to safeguard your information rigorously, they comply with a multitude of security frameworks and certifications.

Continuous Security Enhancement

We proactively identify risks and fortify our security measures, including regular updates to our policies, ongoing staff training, security assessments of our applications and networks, risk evaluations, and strict adherence to regulatory compliance.

Additional robust measures incorporated by Alohi:

  • 存储的签名和传真文档采用 256 位 AES 加密。
  • 强制执行带有安全 SSL/TLS 证书的 HTTPS。
  • 数据备份存储在安全的世界一流数据中心。
  • 帐户所有者身份验证。
  • 限制了对所有服务器和生产工作站的外部访问。
  • 完善的监控和升级系统。
  • 自动数据备份。
  • 自动病毒检查。
  • 报告我们意识到的任何违规行为。
  • 数据泄露通知。
  • 对生产系统的访问受到唯一SSH密钥对的限制。
  • 所有员工都完成了彻底的背景调查,并且必须签署保密协议作为其雇佣合同的一部分。
  • 所有员工都根据 HIPAA 的要求接受有关我们政策和程序的培训。
  • 指定一名 HIPAA 安全官员,负责制定、维护和培训有关我们 HIPAA 政策和程序的知识。