Security Controls

Security Controls

Our security controls include, but are not limited to, the following:



• Access Control Policies: Access to sensitive data is restricted to authorized users, processes, and devices. Verification through authentication controls (e.g., passwords, two-factor authentication, token and certificate-based authentication) is required, and access is managed according to the risk of unauthorized access.



• Multi-Factor Authentication (MFA): MFA is required for all users accessing sensitive systems hosting or processing PII, PHI, and EHR and for remote network access via the Internet.



• Privileged Access: Users assigned elevated or administrative access are managed using Privileged Access Management (PAM) solutions to control and monitor access to sensitive systems and detect and respond to potential misuse. This access is granted only when necessary and revoked when no longer required.



• Secure Software Development: Security and privacy-by-design practices are integrated into the development lifecycle for all internally developed or customized applications. These practices include secure coding standards, code reviews, secrets scanning, vulnerability scanning, and penetration testing.



• Secure System Configurations: Systems and applications are configured to operate with the least functionality necessary to meet organizational objectives. Unnecessary software, ports, services, and access methods are disabled or removed to reduce the potential cyber attack surface.



• Data Classification: Data assets are classified according to its sensitivity (e.g., Public, Proprietary, Confidential) and protected accordingly. Data handling and labeling procedures align with assigned classification levels.



• Encryption: Encryption services are used to protect sensitive data, including the use of strong encryption algorithms (e.g., AES-256 for data at rest and TLS/SSL for data in transit).



• Logging and Monitoring: Access to sensitive data is logged, capturing details such as user identity, access time, and action performed. Logs are monitored and periodically reviewed to detect unauthorized access or suspicious activity.



• Incident Management: Incident response (IR) plans are established and tested regularly to ensure preparedness for potential cybersecurity incidents. Regular drills and simulations (e.g., tabletop exercises) are conducted periodically to test the effectiveness of the IR process. A third party cybersecurity partner is on retainer to assist CMI with incident investigations, forensics, and communications in the event of a major cyber attack or data breach.



Training: All employees receive regular cybersecurity awareness training to recognize and respond to potential threats (e.g., phishing, social engineering, password management, safe internet practices). Specialized training is provided to those in key roles or with access to sensitive information, such as providing HIPAA Cybersecurity Rule awareness training for those with access to PHI or EHR.