Here are the controls implemented at MyDay Health to ensure compliance, as a part of our security program.
Situational Awareness For Incidents
Identity Validation
Termination of Employment
Encrypting Data At Rest
Inventory of Infrastructure Assets
Data Backups
Testing for Reliability and Integrity
Transfer of PII
Impact analysis
Limit Network Connections
External System Connections
Transmission Confidentiality
Anomalous Behavior
Capacity & Performance Management
Data used in Testing
Centralized Collection of Security Event Logs
Conspicuous Link To Privacy Notice
Secure system modification
Malicious Code Protection (Anti-Malware)
Full Device or Container-based Encryption
Endpoint Security Validation
Code of Business Conduct
Organizational Structure
Roles & Responsibilities
Competency Screening
Personnel Screening
Security & Privacy Awareness
Performance Review
Automated Reporting
Incident Reporting Assistance
Third-Party Criticality Assessments
Assigned Cybersecurity & Privacy Responsibilities
Internal Audit using Sprinto
Periodic Review & Update of Cybersecurity & Privacy Program
Management Review of Org Chart
Management Review of Risks
Management Review of Third-Party Risks
Subservice organization evaluation
Segregates Roles and Responsibilities
Subprocessor Requirements
Testing
Customer Obligations
Chief Privacy Officer (CPO)
Privacy Act Statements
Asset Ownership Assignment
Updates During Installations / Removals