Security Overview
Secure by Design
CareLaunch's product is built using a secure development process that includes:
- Open Source Security Code Scanning: Automated analysis of code to detect vulnerabilities.
- Automated Code Deployment and Infrastructure Provisioning: Ensures consistent and secure application updates.
- Continuous Monitoring: Tracks environment changes and versions to identify potential risks.
CareLaunch leverages industry-leading tools to ensure HIPAA/GDPR compliance and implements robust controls to reduce risk and protect sensitive data.
PHI Overview
Protected Health Information (PHI) is securely stored using the Google Cloud Platform (GCP) Healthcare API, which offers:
- Comprehensive security controls, monitoring, and review.
- Segregation from other resources using:
- Identity and Access Management (IAM).
- Network-level filtering.
- Certificate-based authentication.
Compliance Certifications
Google undergoes regular independent third-party audits, providing external verification. Key certifications include:
- SSAE16 / ISAE 3402 Type II
- Here is the associated Public SOC 3 Report.
- SOC 2 report available under NDA.
- ISO 27001
- For systems, applications, people, technology, processes, and data centers.
- ISO 27001 Certification
- ISO 27017 (Cloud Security)
- Best practices for cloud service security controls.
- ISO 27017 Certificate.
- ISO 27018 (Cloud Privacy)
- Standards for protecting personally identifiable information (PII) in cloud services.
- ISO 27018 Certificate.
- FedRAMP ATO
- PCI DSS v3.2.1