SlideShare ist ein Scribd-Unternehmen logo
1 von 8
Downloaden Sie, um offline zu lesen
wounddesk.com
Security at
+WoundDesk
WHITE PAPER, MARCH 2016
Security at
+WoundDesk
WHITE PAPER, MARCH 2016
At +WoundDesk, the security of your data is
our highest priority.
We value your online security as much as you
do. And for good reason: every healthcare
provider using our service expects their data
to be secure and confidential. We understand
how important the responsibility of safe-
guarding this data is to our customers, their
patients and work to maintain that trust.
If you have additional questions regarding se-
curity, we are happy to answer them. Please
write to us and we will respond as quickly as
we can.
— Andreas Lorenz, Lead technology @ digitalMedLab
+WoundDesk
wounddesk.com
Trust and transparency
Trust is the foundation of our relationship with You. We value the confidence you’ve put in us
and take the responsibility of protecting your information seriously. To be worthy of your trust,
we built and will continue to grow +WoundDesk with an emphasis on security, compliance, and
privacy.
As transparency is one of the principles on which our company is built, we aim to be as clear
and open as we can about the way we handle security. Should a security breach occur, we will
promptly notify our users via our blog, Twitter and/or email of the nature and extent of the
breach, and take steps to minimize any damage.
Privacy policy
You own your data, and whether it’s your personal or patient information, we’re committed to
keeping it private. Our privacy policy clearly describes how we collect, use, protect and handle
your information when you use our websites, software, and service.
For more information on our commitment to providing secure services, please see our Privacy
Policy, and Terms of Service.
Protect and control
+WoundDesk is designed with a secure, distributed infrastructure with multiple layers of
protection. We work behind the scenes to protect your data and empower account administra-
tors with tools that provide control and visibility. Our robust information security management
framework is designed to assess risks and build a culture of security at +WoundDesk.
Data Center Security
+WoundDesk security | White Paper 3
wounddesk.com
Data Security
Customer Data is stored redundantly at multiple locations in our hosting provider’s data centers
to ensure availability. We have well-tested backup and restoration procedures, with a maximum
retention period of 90 days, which allow recovery from a major disaster. Customer Data is
automatically backed up off site. The Operations team is alerted in case of a failure with this
system.
We do not retroactively remove repositories from backups when deleted by the user, as we may
need to restore the repository for the user if it was removed accidentally.
Additionally account administrators of any +WoundDesk services plan can export team and
patient Data to backup locally.
All passwords stored in our databases are salted and hashed using an industry standard hash
function.
Application Level Security
+WoundDesk supports SSL encryption throughout the application. SSL is a bank grade security
protocol that allows your information to be transmitted securely.
+WoundDesk account passwords are hashed. Our own staff can't even view them. If you lose
your password, it can't be retrieved—it must be reset.
Login pages have brute force protection with rate limiting.
We perform regular automated and manual vulnerability scans of our applications using accred-
ited industry standard tools to identify and patch potential security vulnerabilities and bugs. 
+WoundDesk maintains an extensive, centralized logging environment in its production envi-
ronment which contains information pertaining to security, monitoring, availability, access, and
other metrics about the +WoundDesk services. When problems are detected, our team is
notified immediately and the issues are investigated. 
Mobile App Security
We have implemented a double layer of security by using an unique AppKey per organization
and your Username and Password.
+WoundDesk security
wounddesk.com
Sensitive data is always transmitted via SSL and no customer data is stored in the mobile app.
Additionally all cached data is deleted when you logout of +WoundDesk.
Sessions are, on the mobile app and the web-based administration, limited to 20 minutes of
inactivity before they are terminated, reducing the risk that a users unattended mobile phone or
computer provides unauthorised access to their data.
Credit card safety
When you sign up for a paid account on +WoundDesk, we don't store and don't handle anyses-
tive credit card data on our servers (PCI compliant).
For the payment process we work together with our partner Stripe. Stripe exceeds the most
stringent industry standards for security. Click here to learn more about the technical details of
Stripe's secure infrastructure.
Internal Protocol & Education
All employees are required to read and sign our comprehensive information security policy
covering the security, availability, and confidentiality of the +WoundDesk services.
All of our employees and contract personnel are bound to our policies regarding customer data
and we treat these issues as matters of the highest importance within our company.
Should an account owner ever reach out to our support team for assistance, a support member
can shadow an account. Otherwise, employee access to user accounts on our end is limited.
All new employees are given security guidelines for using social media, including information
about social engineering.
Protecting Ourselves Against You
Yes, you heard that correctly. We can do everything possible for security, but if your computer
gets compromised and someone gets into your +WoundDesk account, that's not good for either
of us.
We monitor and will automatically suspend accounts for signs of irregular or suspicious login
activity.
+WoundDesk security | White Paper 5
wounddesk.com
In addition to our scalable algorithms, we employ another layer of human reviewers, who
monitor for anomalous account activity.
Certain changes to your account, such as your password, trigger email notifications to the
account holder.
Protection by Yourself
In addition to the work we do at the infrastructure level, we provide account administrators of
paid versions of the +WoundDesk services with additional tools to enable their own users to
protect their patient data.
We also make it easy for administrators to remotely terminate all connections and sign out all
devices authenticated to the +WoundDesk services at any time, on-demand.
Detailed access logs are also available both to users and administrators of paid teams. We log
every time an account signs in, noting the type of device used and the IP address of the
connection. Something doesn't look right? Contact us.
The application enforces a strong password quality requirement on all users ensuring that
passwords will be between 8 and 15 characters in length and must contain at least one upper
case, one lower case and one numeric character.
We enforce screens lockouts and the usage of full disk encryption for company laptops.
Custom integration plan
We're extremely concerned and active about security, but we're aware that many institutions
are not allowed or comfortable hosting patient data outside their firewall. For these institutions
we offer a custom integration plan, a version of +WoundDesk that can be installed to a server
within the institution's network.
Need to report a security vulnerability?
If you believe you have found a security vulnerability on +WoundDesk, please let us know right
away. We will investigate all reports and do our best to quickly fix valid issues.
+WoundDesk security | White Paper 6
wounddesk.com
We hope you enjoyed
this white paper.
Please share your
thoughts with us
@digitalMedLab
using #security, or
find us on facebook.
wounddesk.com
Summary
digitalMedLab takes the privacy, security and protection of your data very seriously. We have
built our services, including +WoundDesk, around this priority. Our security policies and controls
align with industry standards, and we review them regularly to ensure continued compliance.
Healthcare providers, Physicians and Nurses can confidently use the +WoundDesk services to
assess and document chronic wounds, knowing that their data is protected by the architecture
and policies outlined in this document.
For more information about +WoundDesk go to: https://wounddesk.com
For a copy of this white paper as PDF, visit: https://wounddesk.com/security
+WoundDesk security | White Paper 8
About digitalMedLab
digitalMedLab is transforming how people, businesses and IT work and collaborate in the cloud era. Its portfolio of
GoTo cloud services enable people to work from anywhere with anyone by providing simple-to-use cloud-based
collaboration, remote access and IT support solutions for every type of business.
Learn more about our products and services at: https://digitalmedlab.com
© 2016 digitalMedLab GmbH. All rights reserved. +WoundDesk is a trademark of digitalMedLab, and is or may be
registered in the U.S. Patent and Trademark Office and other countries. All other trademarks are the property of
their respective owners.
No part of this publication may be reproduced in any form or by any means, without prior permission in writing
from the publishers.
wounddesk.com
SHARE

Weitere ähnliche Inhalte

Kürzlich hochgeladen

Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...tanya dube
 
Top Rated Bangalore Call Girls Ramamurthy Nagar ⟟ 9332606886 ⟟ Call Me For G...
Top Rated Bangalore Call Girls Ramamurthy Nagar ⟟  9332606886 ⟟ Call Me For G...Top Rated Bangalore Call Girls Ramamurthy Nagar ⟟  9332606886 ⟟ Call Me For G...
Top Rated Bangalore Call Girls Ramamurthy Nagar ⟟ 9332606886 ⟟ Call Me For G...narwatsonia7
 
Call Girls Kochi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Kochi Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Kochi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Kochi Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...Arohi Goyal
 
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...Dipal Arora
 
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...parulsinha
 
Call Girls Gwalior Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Gwalior Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Varanasi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Varanasi Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Varanasi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Varanasi Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Bangalore Call Girls Nelamangala Number 7001035870 Meetin With Bangalore Esc...
Bangalore Call Girls Nelamangala Number 7001035870  Meetin With Bangalore Esc...Bangalore Call Girls Nelamangala Number 7001035870  Meetin With Bangalore Esc...
Bangalore Call Girls Nelamangala Number 7001035870 Meetin With Bangalore Esc...narwatsonia7
 
Lucknow Call girls - 8800925952 - 24x7 service with hotel room
Lucknow Call girls - 8800925952 - 24x7 service with hotel roomLucknow Call girls - 8800925952 - 24x7 service with hotel room
Lucknow Call girls - 8800925952 - 24x7 service with hotel roomdiscovermytutordmt
 
Top Rated Bangalore Call Girls Mg Road ⟟ 9332606886 ⟟ Call Me For Genuine S...
Top Rated Bangalore Call Girls Mg Road ⟟   9332606886 ⟟ Call Me For Genuine S...Top Rated Bangalore Call Girls Mg Road ⟟   9332606886 ⟟ Call Me For Genuine S...
Top Rated Bangalore Call Girls Mg Road ⟟ 9332606886 ⟟ Call Me For Genuine S...narwatsonia7
 
Call Girls Visakhapatnam Just Call 9907093804 Top Class Call Girl Service Ava...
Call Girls Visakhapatnam Just Call 9907093804 Top Class Call Girl Service Ava...Call Girls Visakhapatnam Just Call 9907093804 Top Class Call Girl Service Ava...
Call Girls Visakhapatnam Just Call 9907093804 Top Class Call Girl Service Ava...Dipal Arora
 
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...hotbabesbook
 
Call Girls Siliguri Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Siliguri Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Siliguri Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Siliguri Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service AvailableCall Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service AvailableDipal Arora
 

Kürzlich hochgeladen (20)

Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
 
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
 
Top Rated Bangalore Call Girls Ramamurthy Nagar ⟟ 9332606886 ⟟ Call Me For G...
Top Rated Bangalore Call Girls Ramamurthy Nagar ⟟  9332606886 ⟟ Call Me For G...Top Rated Bangalore Call Girls Ramamurthy Nagar ⟟  9332606886 ⟟ Call Me For G...
Top Rated Bangalore Call Girls Ramamurthy Nagar ⟟ 9332606886 ⟟ Call Me For G...
 
Call Girls Kochi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Kochi Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Kochi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Kochi Just Call 9907093804 Top Class Call Girl Service Available
 
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
 
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Dehradun Just Call 9907093804 Top Class Call Girl Service Available
 
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
 
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
 
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
 
Call Girls Gwalior Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Gwalior Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Coimbatore Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Varanasi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Varanasi Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Varanasi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Varanasi Just Call 9907093804 Top Class Call Girl Service Available
 
Bangalore Call Girls Nelamangala Number 7001035870 Meetin With Bangalore Esc...
Bangalore Call Girls Nelamangala Number 7001035870  Meetin With Bangalore Esc...Bangalore Call Girls Nelamangala Number 7001035870  Meetin With Bangalore Esc...
Bangalore Call Girls Nelamangala Number 7001035870 Meetin With Bangalore Esc...
 
Lucknow Call girls - 8800925952 - 24x7 service with hotel room
Lucknow Call girls - 8800925952 - 24x7 service with hotel roomLucknow Call girls - 8800925952 - 24x7 service with hotel room
Lucknow Call girls - 8800925952 - 24x7 service with hotel room
 
Top Rated Bangalore Call Girls Mg Road ⟟ 9332606886 ⟟ Call Me For Genuine S...
Top Rated Bangalore Call Girls Mg Road ⟟   9332606886 ⟟ Call Me For Genuine S...Top Rated Bangalore Call Girls Mg Road ⟟   9332606886 ⟟ Call Me For Genuine S...
Top Rated Bangalore Call Girls Mg Road ⟟ 9332606886 ⟟ Call Me For Genuine S...
 
Call Girls Visakhapatnam Just Call 9907093804 Top Class Call Girl Service Ava...
Call Girls Visakhapatnam Just Call 9907093804 Top Class Call Girl Service Ava...Call Girls Visakhapatnam Just Call 9907093804 Top Class Call Girl Service Ava...
Call Girls Visakhapatnam Just Call 9907093804 Top Class Call Girl Service Ava...
 
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
 
Call Girls Siliguri Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Siliguri Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Siliguri Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Siliguri Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service AvailableCall Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
 

Empfohlen

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by HubspotMarius Sescu
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTExpeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 

Empfohlen (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

+WoundDesk Security

  • 1. wounddesk.com Security at +WoundDesk WHITE PAPER, MARCH 2016 Security at +WoundDesk WHITE PAPER, MARCH 2016
  • 2. At +WoundDesk, the security of your data is our highest priority. We value your online security as much as you do. And for good reason: every healthcare provider using our service expects their data to be secure and confidential. We understand how important the responsibility of safe- guarding this data is to our customers, their patients and work to maintain that trust. If you have additional questions regarding se- curity, we are happy to answer them. Please write to us and we will respond as quickly as we can. — Andreas Lorenz, Lead technology @ digitalMedLab +WoundDesk wounddesk.com
  • 3. Trust and transparency Trust is the foundation of our relationship with You. We value the confidence you’ve put in us and take the responsibility of protecting your information seriously. To be worthy of your trust, we built and will continue to grow +WoundDesk with an emphasis on security, compliance, and privacy. As transparency is one of the principles on which our company is built, we aim to be as clear and open as we can about the way we handle security. Should a security breach occur, we will promptly notify our users via our blog, Twitter and/or email of the nature and extent of the breach, and take steps to minimize any damage. Privacy policy You own your data, and whether it’s your personal or patient information, we’re committed to keeping it private. Our privacy policy clearly describes how we collect, use, protect and handle your information when you use our websites, software, and service. For more information on our commitment to providing secure services, please see our Privacy Policy, and Terms of Service. Protect and control +WoundDesk is designed with a secure, distributed infrastructure with multiple layers of protection. We work behind the scenes to protect your data and empower account administra- tors with tools that provide control and visibility. Our robust information security management framework is designed to assess risks and build a culture of security at +WoundDesk. Data Center Security +WoundDesk security | White Paper 3 wounddesk.com
  • 4. Data Security Customer Data is stored redundantly at multiple locations in our hosting provider’s data centers to ensure availability. We have well-tested backup and restoration procedures, with a maximum retention period of 90 days, which allow recovery from a major disaster. Customer Data is automatically backed up off site. The Operations team is alerted in case of a failure with this system. We do not retroactively remove repositories from backups when deleted by the user, as we may need to restore the repository for the user if it was removed accidentally. Additionally account administrators of any +WoundDesk services plan can export team and patient Data to backup locally. All passwords stored in our databases are salted and hashed using an industry standard hash function. Application Level Security +WoundDesk supports SSL encryption throughout the application. SSL is a bank grade security protocol that allows your information to be transmitted securely. +WoundDesk account passwords are hashed. Our own staff can't even view them. If you lose your password, it can't be retrieved—it must be reset. Login pages have brute force protection with rate limiting. We perform regular automated and manual vulnerability scans of our applications using accred- ited industry standard tools to identify and patch potential security vulnerabilities and bugs.  +WoundDesk maintains an extensive, centralized logging environment in its production envi- ronment which contains information pertaining to security, monitoring, availability, access, and other metrics about the +WoundDesk services. When problems are detected, our team is notified immediately and the issues are investigated.  Mobile App Security We have implemented a double layer of security by using an unique AppKey per organization and your Username and Password. +WoundDesk security wounddesk.com
  • 5. Sensitive data is always transmitted via SSL and no customer data is stored in the mobile app. Additionally all cached data is deleted when you logout of +WoundDesk. Sessions are, on the mobile app and the web-based administration, limited to 20 minutes of inactivity before they are terminated, reducing the risk that a users unattended mobile phone or computer provides unauthorised access to their data. Credit card safety When you sign up for a paid account on +WoundDesk, we don't store and don't handle anyses- tive credit card data on our servers (PCI compliant). For the payment process we work together with our partner Stripe. Stripe exceeds the most stringent industry standards for security. Click here to learn more about the technical details of Stripe's secure infrastructure. Internal Protocol & Education All employees are required to read and sign our comprehensive information security policy covering the security, availability, and confidentiality of the +WoundDesk services. All of our employees and contract personnel are bound to our policies regarding customer data and we treat these issues as matters of the highest importance within our company. Should an account owner ever reach out to our support team for assistance, a support member can shadow an account. Otherwise, employee access to user accounts on our end is limited. All new employees are given security guidelines for using social media, including information about social engineering. Protecting Ourselves Against You Yes, you heard that correctly. We can do everything possible for security, but if your computer gets compromised and someone gets into your +WoundDesk account, that's not good for either of us. We monitor and will automatically suspend accounts for signs of irregular or suspicious login activity. +WoundDesk security | White Paper 5 wounddesk.com
  • 6. In addition to our scalable algorithms, we employ another layer of human reviewers, who monitor for anomalous account activity. Certain changes to your account, such as your password, trigger email notifications to the account holder. Protection by Yourself In addition to the work we do at the infrastructure level, we provide account administrators of paid versions of the +WoundDesk services with additional tools to enable their own users to protect their patient data. We also make it easy for administrators to remotely terminate all connections and sign out all devices authenticated to the +WoundDesk services at any time, on-demand. Detailed access logs are also available both to users and administrators of paid teams. We log every time an account signs in, noting the type of device used and the IP address of the connection. Something doesn't look right? Contact us. The application enforces a strong password quality requirement on all users ensuring that passwords will be between 8 and 15 characters in length and must contain at least one upper case, one lower case and one numeric character. We enforce screens lockouts and the usage of full disk encryption for company laptops. Custom integration plan We're extremely concerned and active about security, but we're aware that many institutions are not allowed or comfortable hosting patient data outside their firewall. For these institutions we offer a custom integration plan, a version of +WoundDesk that can be installed to a server within the institution's network. Need to report a security vulnerability? If you believe you have found a security vulnerability on +WoundDesk, please let us know right away. We will investigate all reports and do our best to quickly fix valid issues. +WoundDesk security | White Paper 6 wounddesk.com
  • 7. We hope you enjoyed this white paper. Please share your thoughts with us @digitalMedLab using #security, or find us on facebook. wounddesk.com
  • 8. Summary digitalMedLab takes the privacy, security and protection of your data very seriously. We have built our services, including +WoundDesk, around this priority. Our security policies and controls align with industry standards, and we review them regularly to ensure continued compliance. Healthcare providers, Physicians and Nurses can confidently use the +WoundDesk services to assess and document chronic wounds, knowing that their data is protected by the architecture and policies outlined in this document. For more information about +WoundDesk go to: https://wounddesk.com For a copy of this white paper as PDF, visit: https://wounddesk.com/security +WoundDesk security | White Paper 8 About digitalMedLab digitalMedLab is transforming how people, businesses and IT work and collaborate in the cloud era. Its portfolio of GoTo cloud services enable people to work from anywhere with anyone by providing simple-to-use cloud-based collaboration, remote access and IT support solutions for every type of business. Learn more about our products and services at: https://digitalmedlab.com © 2016 digitalMedLab GmbH. All rights reserved. +WoundDesk is a trademark of digitalMedLab, and is or may be registered in the U.S. Patent and Trademark Office and other countries. All other trademarks are the property of their respective owners. No part of this publication may be reproduced in any form or by any means, without prior permission in writing from the publishers. wounddesk.com SHARE