Maintaining the Availability, Integrity and Confidentiality of all systems is a top priority at Patient Prompt®. A Certified Information Systems Security Professional (CISSP) has designed all electronic security aspects of our system.
In compliance with both Canadian PIPEDA and US HIPAA laws, all confidential information is transmitted via Secure Sockets Layer (SSL). SSL ensures that all data passed between the client office and the central server remains private and unaltered. SSL is an industry standard and is used by millions of websites, including banks and the federal government, in the protection of their online transactions with their customers.
Since our Patient Prompt® confirmation product is an extension of our client’s application rather than an application itself, all interactions with end-users (i.e. the patients with an appointment) take place over the telephone via a series of confirmation calls. Since the users do not interact directly with the system like they would in a traditional application setting, Patient Prompt® is able to completely lock down all external touch points, ensuring a very secure solution. Patient Prompt® uses both physical and logical security controls to safeguard both customer and client information.
All Patient Prompt® servers are located in state-of-the-art data centers that provide a highly secure physical infrastructure, including the latest in biometric authentication, video surveillance, and round-the-clock security officers. Patient Prompt® data centers are engineered to eliminate any single point of failure, with multiple layers of redundancy in power systems, HVAC, and fire detection and suppression. All environmental systems are monitored 24 x 7.
Patient Prompt® uses a variety of interfaces to exchange information between client systems (i.e. the PM/EMR software package) and the Patient Prompt™ central database. Every end-point interface communicating with our environment is issued a unique security token which is used to authenticate the client with our system. Authentication and all communications with Patient Prompt® take place through a secure 128-bit encrypted SSL tunnel between the remote client site and the Patient Prompt® data center. Once securely communicated, all client information is stored on a cluster of servers, specifically hardened against attacks following the most recent hardening guides. Most importantly, our data center is set up in a tiered environment with separate servers for Web, Application and Database. This tiered environment provides an additional layer of security in that the Database server is not accessible to the public and can only be accessed through our web and application layers as data makes its way through the three tiers.
Should you require further information regarding the transmission of data and its security contact us at:
privacyofficer@patientprompt.com










