Security Practices
This document describes the security controls Intelligena LLC, a California limited liability company maintains for Practiceful. Where a Business Associate Agreement is in force between us, this document is incorporated into it and forms part of it, and we will not materially reduce the protection these controls provide without your prior written agreement.
1. Scope
These controls apply to the production systems that process customer data, to the infrastructure they run on, and to the people who administer them. They do not describe your own environment: the security of your devices, your network, your passwords and your workforce remains yours, and is the largest single factor in whether your data stays safe.
2. Encryption
- In transit. All traffic between you and the Service is encrypted with TLS 1.2 or above. Plain HTTP is redirected, and HSTS is served.
- At rest. Databases, object storage and backups are encrypted at rest with AES-256 or equivalent.
- Secrets. Application credentials are held encrypted at rest and are decrypted only into the memory of the process that needs them. They are not stored in source control in plaintext, and log output is redacted by value before it is written.
- Card data. We never receive or store a full payment card number. Card details go directly to our PCI-DSS Level 1 payment processor.
3. Access control
- Least privilege. Access to production data is limited to the personnel who need it to operate the Service, and is reviewed periodically.
- Multi-factor authentication is required for administrative access to production systems, and is available to — and, for accounts that can reach protected health information, required of — users of the Service.
- Separation of environments. Development, test and production run on separate hosts with separate credentials. Production data is not copied into development or test environments.
- Administrative access is by key, over an authenticated tunnel, from a restricted set of addresses. Password authentication for administrative access is disabled.
4. Audit logging and monitoring
- Every access to protected health information through the Service is recorded in an append-only audit log identifying who, what and when. The log is available to you for your own records and for a regulator’s.
- Administrative actions on production infrastructure are logged.
- Logs are retained for at least twelve months and are protected against alteration by the people whose actions they record.
5. Vulnerability management and remediation
Dependencies and container images are scanned for known vulnerabilities, application source is scanned for insecure patterns, and host configuration is measured against a published hardening benchmark. Confirmed vulnerabilities affecting production are remediated, or mitigated so that the risk is equivalent, within:
| Severity | Target |
|---|---|
| Critical | 7 calendar days |
| High | 30 calendar days |
| Medium | 90 calendar days |
| Low | next scheduled maintenance |
A vulnerability that is being actively exploited is treated as Critical whatever it scores. Where a fix is not available from an upstream supplier within the target, we apply a compensating control and record why.
6. Where data is held
Customer data, and every backup, replica and cache of it, is held only within the United States and its territories, including where it is held by a subcontracted hosting, storage or content-delivery facility. See the Subprocessors page for which categories of provider are involved. Where a Business Associate Agreement is in force this is a contractual commitment and not merely a description — see the BAA, section 4.
7. Backup and recovery
- Databases are backed up on a regular schedule; backups are encrypted and are held in the same region as the primary data.
- Restores are tested. A backup nobody has restored is a belief, not a control.
- Backups are retained on a rolling schedule and then overwritten. Where you ask us to delete data, copies in backups are removed as those backups age out rather than being extracted individually, and remain protected by the same controls until they are.
This Section describes what we do. It is not a warranty — see Terms of Service section 11 — and it does not replace your own obligation to retain your records.
8. People
- Personnel with access to customer data are bound by written confidentiality obligations that survive their engagement.
- Access is removed promptly when someone no longer needs it.
- Personnel receive security and privacy training appropriate to their access.
9. Subprocessors
Every subprocessor is engaged under a written contract imposing data-protection obligations at least as protective as those we owe you, including the data-residency requirement above, and no subprocessor is permitted to use your content to train its own models. We assess a subprocessor’s security posture before engaging it and periodically afterwards. The categories are listed on the Subprocessors page and the current named schedule is available on request.
10. Incident response
We maintain an incident response process covering detection, containment, investigation, notification and review. Where a Business Associate Agreement is in force with you, we will report a Security Incident or Breach of Unsecured PHI to you within seventy-two (72) hours of discovery, will cooperate with your investigation, and will provide the forensic findings we hold. The full obligation, including who bears the cost of individual notification, is in BAA section 5. Where no such agreement is in force, we notify you without unreasonable delay and within the period applicable law requires.
To report a suspected vulnerability or security incident, write to security@intelligena.com. We will acknowledge a report within two business days. We will not pursue a good-faith security researcher who reports a finding to us privately, does not access or modify data belonging to anyone else, and gives us a reasonable opportunity to fix it before disclosing.
11. How you can verify this
- We will complete a reasonable security questionnaire once in any twelve-month period on written request.
- We will provide a summary of our most recent vulnerability assessment or penetration test where one has been carried out.
- Where a regulator, an auditor or applicable law requires you to inspect our controls, we will cooperate at reasonable times and on reasonable notice, subject to confidentiality and to the protection of other customers’ data.
12. What we do not claim
INTELLIGENA LLC HAS NOT OBTAINED A SOC 2 TYPE I OR TYPE II REPORT, A HITRUST CERTIFICATION, OR ISO/IEC 27001 CERTIFICATION. NOTHING IN THIS DOCUMENT IS A REPRESENTATION THAT IT HAS. NO SET OF CONTROLS MAKES ANY SERVICE SECURE AGAINST EVERY ATTACK, AND THIS DOCUMENT IS A DESCRIPTION OF WHAT WE DO RATHER THAN A WARRANTY OF ANY RESULT — SEE SECTION 11 OF THE TERMS OF SERVICE.
Two further things a reader is entitled to know plainly. HIPAA compliance is something your practice holds and we support; it is not a status any software product can hold on your behalf. And Intelligena is not a certifying body — where a control here matters to your own risk assessment, assess it.
13. Changes
We review this document at least every twelve months. Where it is incorporated into a Business Associate Agreement, a change that materially reduces the protection these controls provide requires your agreement; other changes take effect when published, and the version at the top of this page records when it last changed.
How to reach us
- General and legal
- legal@intelligena.com
- Privacy requests
- privacy@intelligena.com
- Copyright / DMCA
- dmca@intelligena.com
- Abuse reports
- abusereport@intelligena.com
- Support
- support@practiceful.com
- Telephone
- (619) 335-8730
Notices in writing
Any notice this agreement requires to be given in writing may be sent to:
Intelligena LLC3400 Cottage Way Ste G2
Sacramento CA 95825
United States of America