2.1.1 Data Security Procedures & Safeguards

The following were implemented as data security procedures and safeguards.

    1. AzureSQL has encrypted storage
    2. Azure Key Vault:  All Encryption Keys are stored in AzureKey Vault; Azure Key Vault is used to store secret keys, encryption keys, SSL certificate keys, etc.
    3. Data Security: Sensitive ePHI data is encrypted at application level
    4. Cache items are encrypted
    5. End-to-end SSL encryption from browser to server on both frontend and backend applications
    6. ePHI data is encrypted at application level
    7. Client caching for requests that contain ePHI are disabled
    8. Database access is configured to only be accessed from the application server