| Requirement |
Description |
How Rewind meets this requirement |
| Risk management |
Reduce risks and vulnerabilities, conduct periodic technical and nontechnical evaluations in response to environmental or operational changes. |
Rewind takes a proactive and comprehensive approach to risk management. We have implemented policies and procedures to safeguard data including PHI, as well as ensuring confidentiality, integrity, and availability of data in line with HIPAA standards.
Regular risk assessments are conducted to identify and address potential vulnerabilities, including security threats, data breaches, and regulatory compliance gaps. Rewind employs robust encryption, access controls, and monitoring systems to protect data and educates our workforce on HIPAA requirements.
Rewind has integrated HIPAA compliance into our overall risk management framework, demonstrating our commitment to maintaining the trust and privacy of our customers |
| Workforce security |
– Background screening and proper termination procedures.
– Sanctions against workforce members. |
All new employees or contractors are subject to background checks and employees receive quarterly privacy and security training.
At Rewind, all employees and contractors with access to confidential information are bound by employment agreements and confidentiality commitments. |
| Information access management |
– Authorization of access for employees who work with PHI.
– Appropriate granting of access (least privileged basis).
– Terminate a session after a predetermined time of inactivity. |
At Rewind, access is assigned based on a user’s team, ensuring access is limited to those with a legitimate need. Quarterly access reviews occur to ensure access is restricted appropriately. Access is modified or removed in a timely manner based on the results of these reviews or when a user’s role changes.
Privileged access to production environments is strictly limited to authorized personnel, aligning with the principle of least privilege. |
| Incident response management |
– Audit logging/detection (including monitoring of login attempts).
– Identify and respond to suspected or known security incidents. Mitigate and document the incidents and their outcomes. |
Rewind users are able to monitor activity related to their organization’s users, plans, and content.
Rewind has implemented an incident response process which consists of identified roles and responsibilities, recording actions associated with incident investigation including descriptions and actions taken, and completing a post-incident review.
For further details on Rewind’s incident response process, please visit the Security Portal. |
| Privacy and security responsibility |
– Identify an individual responsible for the development and implementation of the HIPAA security compliance program.
– Identify an individual responsible for the development and implementation of the HIPAA privacy compliance program. |
Rewind has a dedicated Trust Team responsible for our security, privacy, and compliance programs, including HIPAA requirements. |
| Security awareness and training |
– User awareness training. |
Rewind conducts quarterly security training and ongoing awareness campaigns to ensure all personnel are well-informed about privacy and security requirements and the importance of safeguarding data including Protected Health Information (PHI). |
| Business continuity and disaster recovery planning |
– Processes to enable continuation of critical business operations
– Processes to ensure the integrity of data. |
At Rewind, we prioritize data resilience by performing bi-annual disaster recovery tests, ensuring that our backup systems are always ready to respond to any unexpected events and that our
customers’ data remains secure and accessible.
Disaster recovery testing involves executing technical runbooks to ensure correctness along with tabletop testing of various disaster scenarios to ensure procedures are correct. |
| Business Associate Agreements |
– Business Associate Agreements contain assurances that customer data will be appropriately safeguarded by Rewind and third-party suppliers. |
Rewind has a Business Associate Agreement that includes assurances that we will appropriately safeguard our customer’s data.
Additionally, we ensure relevant third party suppliers will protect your PHI by requiring them to sign Business Associate Agreements with us. |
| Physical security and endpoint controls. |
– Facility access controls
– Workstation and device security |
The Rewind application is hosted within AWS “secure by design” data centers.
Rewind’s office buildings have physical security and access controls in place, such as CCTV and on-site security officers. Access to the building and office is limited to employees with approved access and controlled via access cards.
Rewind has implemented physical and technical safeguards to restrict access to authorized users for all workstations. Technical and physical safeguards, where applicable, are logically enforced by the Rewind mobile device management solution. |
| Policies and procedures |
– Retain documentation for six years from the date of its creation, or the date when it was last in effect, regarding the provisions of the HIPAA Security Rule. |
Rewind has implemented written security policies and procedures and records the actions, activities, and assessments associated with HIPAA compliance. These will be maintained for a minimum of six years. |
| Transmission security |
– Security measures to ensure that ePHI is not improperly modified.
– Mechanisms to encrypt ePHI whenever it is deemed appropriate. |
All data at rest in our databases, cache services, or other data stores is encrypted using standard AWS encryption mechanisms – typically AES 256.
For data in transit across the network, all communication takes place using HTTPS
(encrypted) connections. We use a certificate with a 2048 bit key size on all of our Rewind endpoints and certificates are rotated yearly. |