Identity and access
Email-based verification or two-factor authentication depends on the security of the user's mailbox. Require strong email protection, current recovery information, screen lock, device updates, and prompt reporting of lost devices or unexpected codes.
- Individual accounts; no shared clinical or administrative credentials.
- Two-factor authentication for sensitive access and protected email accounts.
- Role-based access aligned with job responsibilities.
- A controlled invitation, role-change, leave, and offboarding process.
- Session protection, secure password reset, and monitoring for suspicious sign-in.
Data and technical safeguards
Ask what happens at the application layer, not only the hosting layer. A secure cloud provider does not automatically secure the vendor's authorization checks, code, support process, or configuration.
- Encryption in transit and at rest, with documented key and secret management.
- Tenant and object-level authorization tested on every sensitive route.
- Secure upload limits, validation, malware controls where appropriate, and safe file handling.
- Rate limits, abuse controls, dependency management, and timely vulnerability response.
- Environment separation, protected deployment credentials, backups, and recovery testing.
Vendor and subprocessor assurance
- Current list of subprocessors, processing locations, purposes, and change notice.
- Restrictions on vendor workforce access and a logged approval process.
- Contractual confidentiality, safeguards, incident notification, return, and destruction terms.
- Independent assurance relevant to the actual service scope, with exceptions reviewed.
- Clear model-provider terms, including whether customer information is used for training.
Detection and incident response
- 01
Detect
Define which access, administrative, export, deletion, and processing events are logged and who reviews meaningful signals.
- 02
Contain
Know how to suspend an account, revoke sessions, stop a workflow, preserve evidence, and contact the vendor.
- 03
Assess
Identify the information, people, systems, time period, cause, and ongoing risk without spreading more sensitive data.
- 04
Notify and report
Follow PHIPA, contract, insurer, regulator, law-enforcement, and patient-notification requirements as applicable.
- 05
Learn
Correct the control weakness, verify the fix, document decisions, and monitor for recurrence.
Retention, continuity, and exit
- Approved retention and deletion rules for each data type and backup.
- A tested way to export required records in a usable form.
- Downtime procedures that do not depend on the unavailable system.
- Recovery objectives appropriate to the workflow and evidence that restore works.
- A contract-exit plan covering access removal, data return, deletion, and confirmation.
Sources and further reading
Sources were checked on . External guidance can change; open the source before relying on it.