Privacy & Security Overview

Protecting Health Information

Protecting sensitive patient and practice information is central to Ursamin’s mission. We design and operate the Ursamin platform using administrative, technical, and organizational safeguards intended to protect the confidentiality, integrity, and availability of information entrusted to us. 

Ursamin supports healthcare organizations in meeting their obligations under the Health Insurance Portability and Accountability Act (HIPAA) and other applicable privacy and security requirements. Security and privacy are shared responsibilities. Ursamin provides platform safeguards and controls, while each customer remains responsible for configuring and using the platform appropriately, managing its users, and maintaining its own privacy and security practices. 

Where required, Ursamin enters into appropriate contractual arrangements, including Business Associate Agreements, governing the permitted use and protection of protected health information. 

Customer Access and Security

The Ursamin platform uses role-based access controls to help customers manage who may view or work with patient information. Access may be limited according to a user’s assigned role, responsibilities, organization, clinic, patient assignment, and other authorized scope within the platform. 

Customer administrators are responsible for authorizing users, assigning appropriate roles and access, promptly removing access when it is no longer needed, and periodically reviewing user permissions. Users must have an individual account and must not share login credentials. 

Ursamin uses authentication and authorization controls designed to prevent unauthorized access. Multi-factor authentication may be required or made available based on the user’s role, access method, and applicable platform configuration. Customers and users are responsible for protecting their credentials and reporting suspected unauthorized access promptly. 

Operational Security

Ursamin hosts its platform using established cloud infrastructure and applies security controls appropriate to the services and information involved. Our security program is designed to support compliance with applicable privacy and security requirements; however, compliance depends on the combined responsibilities of Ursamin, its service providers, and each customer, as well as the configuration and use of the platform. 

We apply identity and access management practices based on least privilege and restrict administrative access to authorized personnel with a business need. We use logging and monitoring capabilities to support security oversight, investigation, and response. The scope and retention of logs vary by system, service, and operational requirement. 

Ursamin maintains processes for vulnerability management, security updates, and remediation based on risk. Security reviews, testing, code review, automated checks, and penetration testing may be used as separate and complementary controls when appropriate. 

We use safeguards designed to protect health information from unauthorized alteration or destruction and to support its integrity and availability. We also maintain incident response processes intended to identify, assess, contain, and address suspected security events. 

Encryption and Data Protection

Data transmitted between supported Ursamin services, customers, and authorized third parties is protected using encrypted transport, such as Transport Layer Security (TLS) over HTTPS, where applicable. 

Data stored by Ursamin is protected using encryption-at-rest capabilities provided by the applicable cloud and storage services. Additional encryption options, such as customer-managed keys, may be available for specific customer requirements, subject to technical feasibility and agreement. 

Ursamin applies authentication, authorization, secure session controls, and other safeguards appropriate to the platform and the sensitivity of the information processed. No method of transmission or storage is completely secure, but we work to manage risk through layered security controls and ongoing review. 

Secure Software Development

Ursamin maintains separate development, testing, and production environments with controls designed to reduce unauthorized access and unintended data exposure. We use synthetic or de-identified data for development and testing whenever practical. Any authorized access to protected health information is limited to legitimate business purposes and is subject to applicable agreements, policies, and access controls. 

Our engineers follow secure development practices intended to reduce common software vulnerabilities, including injection attacks, cross-site scripting, cross-site request forgery, insecure access control, and other recognized application risks. We use code review, testing, and security checks throughout the development and deployment process. 

We use controlled deployment and infrastructure-management practices to promote consistent, reviewable, and secure configurations. Changes to production systems are managed through authorized processes that may include version control, automated deployment pipelines, testing, approvals, and security checks. 

Shared Responsibility

Protecting health information requires coordinated safeguards across people, processes, technology, and the full information lifecycle. Ursamin works to protect the platform and the information it processes, while customers are responsible for appropriate user access, workforce practices, device security, account management, and the lawful use of patient information. 

Security questions or suspected security concerns involving Ursamin may be reported to info@ursamin.com.