Security
We protect the systems we build and run.
Protection is part of running a critical application, not a separate service. Where i-tecsol holds patients’ information it acts as a HIPAA business associate, and the same discipline applies to every system it operates.
How we work
Hardened by default
Networks, servers and applications are set up to expose as little as possible, and that setup is reviewed and kept, not left to drift.
Watched continuously
Automated checks run around the clock, so a change that weakens the environment is noticed quickly rather than at the next audit.
Access on a need basis
Credentials are rotated, access is limited to the work at hand, and activity is logged.
Reviewed in writing
Security and HIPAA reviews are written in plain language for the people who have to rely on them, such as a client’s compliance officer.
Weaknesses found and fixed
We look for vulnerabilities in our own code and infrastructure before anyone else does, and every fix is verified before it is called done.
Run by the same people
The people who build the software also operate the infrastructure behind it, so protection is applied where the data actually lives.
Plain language
What we do not claim
i-tecsol does not describe software as “HIPAA certified”; HIPAA does not provide a product certification. We describe our approach here and write the specifics down for the clients who rely on them.
Systems that are run and protected by the same people.
If you operate pharmacy or healthcare systems, start with the environment you have today.