Why health organizations certify
Health data is among the most sensitive information an organization can hold, and the consequences of a breach reach patients as well as the balance sheet. Hospitals, health systems, and insurers increasingly require independent certification from technology suppliers, and regulators expect to see a governed security program rather than a list of tools.
What the audit focuses on
For health technology companies, the audit examines how protected health information flows through the platform and who can see it. For providers, it examines the clinical and administrative environments where records are created and used. In both cases we look closely at:
- Data classification. Whether health information is identified, labeled, and handled according to its sensitivity throughout its lifecycle.
- Minimum necessary access. Role design, break-glass procedures, and monitoring of access to records.
- De-identification. Data masking in non-production environments and analytics.
- Retention and deletion. Evidence that information is deleted when no longer required, including in backups and with suppliers.
- Integrations and devices. Security of interfaces with electronic health record systems, connected devices, and third-party services.
- Breach response. Incident procedures that include regulatory and contractual notification timelines, with evidence of testing.
Aligning with HIPAA and ISO 27799
We expect the ISMS to identify HIPAA, state law, and contractual business associate obligations as requirements, and to show how the controls in the Statement of Applicability address them. ISO 27799, the health informatics guidance for ISO 27002, is a useful reference for control selection and we are familiar with it.
Scope and timing
Health technology scopes usually cover the platform, engineering, support, and corporate functions. Provider scopes may cover selected facilities or the whole organization. Where facilities are included, audit time increases to allow for site visits, and we plan them to minimize disruption to clinical work.