We build systems that handle PHI. Here is how we handle it.
Every virtual-care company eventually sends its engineering vendor a security questionnaire. This page is our answer, written down in advance.
Your PHI stays in infrastructure you own
We work inside client-owned cloud infrastructure. Fanzoo builds and operates the systems that handle patient data, under a signed BAA and with the authorized access that operating them requires. We do not move production PHI into Fanzoo-owned systems or infrastructure.
Your PHI stays inside your security boundary, your audit trail, and your vendor agreements. For most clients that materially shortens the risk review, because there is no new place for patient data to live.
We operate under signed BAAs
Fanzoo executes a Business Associate Agreement with every client whose systems touch PHI. Ours cover permitted use and disclosure, safeguards, breach notification, subcontractor flow-down, and the return or destruction of PHI when an engagement ends.
We have operated under signed BAAs with covered entities for years. If your BAA template is ready, send it. If it is not, we have one.
What we build into the software
- ✓ Encryption at rest, in transit, and on devices
- ✓ Role-based access control, enforced in the application rather than assumed
- ✓ Audit logging of PHI access, reviewable
- ✓ Unique accounts with least-privilege access
- ✓ Multi-factor authentication on anything that reaches production
How our team works
- ✓ No production data on local machines. No database dumps, no exports, no test fixtures seeded from live patient records.
- ✓ Segmented network access over VPN with multi-factor authentication
- ✓ Automatic patching with a verification procedure
- ✓ Hardware and software firewalls, endpoint protection on every machine
- ✓ Regular full and incremental backups of critical systems
- ✓ Nationwide criminal background checks for anyone with access to sensitive systems
- ✓ Signed agreements with every vendor in a PHI path
Insurance
- ✓ $2,000,000 technology errors and omissions liability
- ✓ $2,000,000 cyber and privacy security liability
- ✓ First-party coverage for breach notification and remediation, data and systems restoration, and business interruption
Certificates available on request.
What we do not claim
We are not SOC 2 or HITRUST certified. If your diligence process requires either, tell us early and we will tell you honestly where we stand, rather than after you have signed.
Send us your security questionnaire before the first call.
We would rather answer it up front.
or call 1-800-870-9071