myday Health recognises that the confidentiality, integrity and availability of information and data created, maintained and hosted by us are vital to the success of the business and privacy of our partners.
As a service provider/product, we understand the importance in providing clear information about our security practices, tools, resources and responsibilities within myday Health so that our customers can feel confident in choosing us as a trusted provider.
This Security Posture highlights high-level details about our steps to identify and mitigate risks, implement best practices, and continuously develop ways to improve.
Here are the controls implemented at MyDay Health to ensure compliance, as a part of our security program.
Production System User Review
Identity Validation
Termination of Employment
Multi-factor Authentication
Encrypting Data At Rest
Inventory of Infrastructure Assets
Transfer of PII
Inventory of Personal Data (PD)
Choice & Consent
Limit Network Connections
External System Connections
Transmission Confidentiality
Anomalous Behavior
Data used in Testing
Centralized Collection of Security Event Logs
Conspicuous Link To Privacy Notice
Secure system modification
Approval of Changes
Unauthorized Activities
Malicious Code Protection (Anti-Malware)
Full Device or Container-based Encryption
Endpoint Security Validation
Code of Business Conduct
Organizational Structure
Roles & Responsibilities
Competency Screening
Personnel Screening
Security & Privacy Awareness
Performance Review
Automated Reporting
Incident Reporting Assistance
Third-Party Criticality Assessments
Assigned Cybersecurity & Privacy Responsibilities
Management Review of Org Chart
Management Review of Third-Party Risks
Subservice organization evaluation
Segregates Roles and Responsibilities
Subprocessor Requirements
Testing
Customer Obligations
Chief Privacy Officer (CPO)
Asset Ownership Assignment