Our Commitment to You
SafeEvault is dedicated to helping our customers meet the needs of their customers. In the information world this often means that our customers are given a set of requirements valued by their customer. In many cases adherence to these requirements comes in the form of a certification or compliance to an industry guideline. Our intent is to consistently be in step with our customer’s needs in this area, thus we attempt to give our customers information about how the use of SafeEvault’s service meets these guidelines for data protection. Each section on this page will address a different set of requirements. If you have questions about a requirement that is not listed here, please contact us at SEVInfo@SafeEvault.com. We will make every attempt to provide you with the information necessary to assist you in meeting your data protection needs.
HIPAA – Health Insurance Portability and Accountability Act (Congress 1996)
Information – http://www.cms.hhs.gov/HIPAAGenInfo
Section – 164.308(a)(7)(i) – CONTINGENCY PLAN
Requirement – Establish a contingency plan for responding to requests for information in case of emergency or other occurrence (i.e. fire, vandalism, system failure, or natural disaster) that damages systems containing electronically protected health information.
SafeEvault’s Value Proposition – SafeEvault’s online backup service provides a secure offsite location for the storage and recovery of our customer’s data from anywhere in the world.
Section – 164.312(a)(1) – ACCESS CONTROL
Requirement – Implement policies to restrict the access of electronically protected health information to those persons or software programs that have been granted access rights.
SafeEvault’s Value Proposition – All access to backup files is restricted to an authorized user name and password. In addition, a second level of data protection is provided since the information contained in any backup file remains encrypted while stored on SafeEvault’s redundant hardware. These files are password protected and can only be decrypted by a person using this password.
Â
Section – 164.312(b)(1) – AUDIT CONTROL
Requirement – Implement policies required to record and examine activities on systems containing electronically protected health information.
SafeEvault’s Value Proposition - Automated use of SafeEvault’s backup service ensures an accurate audit trail of changes made to health information contained on your system. SafeEvault also monitors and notifies our customer of any failure in the backup systems which might require attention. Attention to this detail allows our customers the ability to detect failures before an issue arises.
Â
Section – 164.312(c)(1) – DATA INTEGRITY
Requirement – Implement policies to protect electronically protected health information from improper alteration or destruction.
SafeEvault’s Value Proposition – Our systems use the latest technology to verify that what is sent to our backup servers is an exact copy of what our customers send. Our retention feature ensures that this data is accurately and efficiently archived for point in time retrieval based on our customer’s backup policies. The data is maintained in three places and accessible from one of two highly available locations. The third location is our backup of your backup. This provides a level of data protection against destruction that effectively meets this requirement.
Â
Section – 164.312(d)(1) – IDENTITY AUTHENTICATION
Requirement – Implement policies that verify the identity of a person seeking access to electronically protected health information.
SafeEvault’s Value Proposition – Access to all SafeEvault files and account information is restricted to an authorized user name and password.
Â
Other Health Acts of interest:
- The Mental Health Parity Act of 1996 (MHPA);
- The Newborns' and Mothers' Health Protection Act of 1996 (NMHPA); and
- The Women's Health and Cancer Rights Act of 1998 (WHCRA).
Sarbanes–Oxley Rules and Regulations (Securities and Exchange Commission November 2002)
Information - http://www.sarbanes-oxley.com/section.php
Â
Section – 103(a)(2)(A)(i) – ARCHIVING INFORMATION
Requirement – Prepare, and maintain for a period of not less than 7 years, audit work papers, and other information related to any audit report, in sufficient detail to support the conclusions reached in such report
SafeEvault’s Value Proposition – SafeEvault’s automatic online backup service provides our customer with the ability to set multiple periodic backup processes. The retention period and backup schedule for each of the process is fully configurable to meet our customer’s needs. One backup can be maintained on a yearly basis for 7 years in conjunction with daily backups retained for a shorter duration. Our service allows our customer the ability to meet this requirement online and onsite with a disk to disk copy for additional archiving.
Â
Section – 105(b)(2)(B) – AVAILABILITY OF INFORMATION
Requirement – Require the production of audit work papers and any other document or information in the possession of a registered public accounting firm or any associated person thereof, wherever domiciled, that the Board considers relevant or material to the investigation, and may inspect the books and records of such firm or associated person to verify the accuracy of any documents or information supplied
SafeEvault’s Value Proposition – SafeEvault’s service provides our customer with tools necessary for the recovery of accounting records and their inspection from multiple dates.
Â
Section – 301(4)(A) – HANDLING INFORMATION
Requirement – Receipt, retention, and treatment of complaints received by the issuer regarding accounting, internal accounting controls, or auditing matters
SafeEvault’s Value Proposition – SafeEvault’s retention feature ensures that this data is accurately and efficiently archived for point in time retrieval based on our customer’s backup policies. The data is maintained in three places and accessible from one of two highly available locations. The third location is our backup of your backup. This provides a level of data protection against destruction that effectively meets this requirement.
Section – 404(a)(1) – RESPONSIBILTY FOR INFORMATION
Requirement – State the responsibility of management for establishing and maintaining an adequate internal control structure and procedures for financial reporting
SafeEvault’s Value Proposition – Use of SafeEvault’s online backup service shows a high level of concern by our customer’s management team. Our service shows reasonable responsibility for the accuracy and integrity of the accounting data. It also shows responsibility for the recovery of data and provides business continuity. Management teams who employee our services are effectively managing their exposure to the risks associated with information loss, corruption, and disaster.
Â
Section – 802(a) – RECOVERY OF INFORMATION
Requirement – Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed under title 11, or in relation to or contemplation of any such matter or case, shall be fined under this title, imprisoned not more than 20 years, or both .
SafeEvault’s Value Proposition – Use of SafeEvault’s online backup service provides recovery of information in case of malicious or accidental manipulation from multiple points in time based on the needs and policies set by our customers. These files are protected from deletion by user name and password.
SEC 17 - 17 CFR 240.17a-4 – Electronic Storage of Records (Securities and Exchange Commission – February 1997)
Information - In 1997, the Commission amended section 17(a)(1) of the Securities Exchange Act of 1934 ("Exchange Act") paragraph (f) of Rule 17a-4 to allow broker-dealers to store records electronically. http://sec.gov/rules/interp/34-47806.htm#P27_3520
*** Please contact SafeEvault if you need SEC 17 compliance (SEVInfo@SafeEvault.com).
Virtual
Data Recovery | Data Backup | Online Disaster
Recovery Plan | Server Backup Software Solution
| Business Continuity | Restore Server and Desktop
Images | File Recovery | Data Protection | Remote
Online Backup | Windows Server Recovery | Texas:
Austin, Dallas/Fort
Worth, Houston or ANYWHERE in the World! | 30
Day Free Trial | Backup Software | Backup Solution | Data Backup Service | Data Backup Software | Offsite Data Backup | Offsite Data Backup and Recovery Services | Offsite Data Backup and Storage | Remote Data Backup | Remote Data Backup Software | Secure Offsite Data Backup Services
|