Enterprise Security

Security designed for accountable healthcare operations.

Elizian is designed to support high-stakes healthcare workflows in which confidentiality, integrity, availability, accountability, and responsible access are essential. Our security approach combines administrative, technical, infrastructure, and organizational safeguards appropriate to the information, services, and customer environments involved.

Elizian’s controls are designed to protect the platform, reduce unauthorized access, support auditability, and help customers operate configured workflows responsibly. Specific contractual safeguards, implementation requirements, and security obligations may vary by customer deployment.

Enterprise control architecture

01

Identity

02

Role-based access

03

Encrypted exchange

04

Application controls

05

Audit and monitoring

06

Backup and recovery

Governed operating boundary

A layered approach to protecting Elizian.

01

Protect

Safeguards designed to protect information, software, infrastructure, integrations, credentials, and customer-configured environments.

02

Control

Identity, permissions, role-based access, documented configuration, change control, and customer-administrator oversight.

03

Detect

Logging, security-event review, vulnerability identification, operational monitoring, and escalation of suspected misuse or compromise.

04

Recover

Incident response, backup, continuity planning, restoration processes, communication, and corrective action.

Security sections

Security by design

03

Security is treated as an operating responsibility; not a marketing badge.

Elizian’s security approach begins with understanding the systems, users, data, integrations, workflows, and organizations involved in each deployment. Safeguards are selected and configured according to the service, information sensitivity, customer requirements, contractual commitments, and identified risks.

  • Limit access to authorized users and approved purposes.
  • Protect information during storage and transmission.
  • Maintain visibility into material account and system activity.
  • Separate customer responsibilities from Elizian responsibilities.
  • Evaluate risks and address identified vulnerabilities.
  • Control changes to production systems and configurations.
  • Prepare for security incidents and service interruptions.
  • Review service providers that may access or process information.
  • Maintain records supporting accountability and investigation.
  • Avoid unsupported claims about security or compliance.

No information system can be guaranteed completely secure. Elizian therefore uses layered safeguards, monitoring, governance, customer controls, and incident-response processes intended to reduce and manage security risk.

Administrative controls

04

Policies, ownership, and operating discipline.

Administrative safeguards provide the organizational structure through which security responsibilities are assigned, risks are evaluated, access is governed, incidents are addressed, and controls are maintained.

Security ownership

Elizian assigns responsibility for security-related policies, risk decisions, control administration, incident coordination, vendor review, and customer-security communications.

Risk management

Security risks and vulnerabilities are evaluated in relation to the services, information, infrastructure, integrations, users, and external dependencies involved.

Workforce access

Access is assigned according to role and business need. Workforce members are expected to protect credentials, follow applicable policies, report suspected incidents, and use information only for authorized purposes.

Security awareness

Relevant personnel receive security and privacy guidance appropriate to their duties and access.

Change management

Material changes to software, infrastructure, integrations, permissions, and production configurations are subject to controlled implementation practices.

Vendor oversight

Service providers with access to Elizian information or systems are evaluated according to the nature of their role, access, and risk.

Incident preparation

Elizian maintains processes for receiving reports, investigating suspected events, coordinating response, restoring services, and making required notifications.

Continuity planning

Critical dependencies, recovery needs, backups, restoration, and communications are incorporated into continuity planning.

Technical controls

05

Controls designed to protect access, data, and platform activity.

  • Unique user accounts.
  • Role-based access.
  • Configurable permissions.
  • Authentication controls.
  • Session-management controls.
  • Administrative access restrictions.
  • Encrypted transmission.
  • Protected data storage.
  • Secure integration methods.
  • Audit and activity records.
  • Environment separation.
  • Security-event visibility.
  • Backup protection.
  • Controlled software deployment.
  • Input validation.
  • Error and exception handling.
  • Protection against unauthorized automated access.

The precise controls available or required may depend on the customer environment, integration model, contracted configuration, data involved, and technical implementation.

Infrastructure protection

06

Shared responsibility across Elizian and its infrastructure providers.

Elizian uses managed technology and cloud infrastructure to operate its services. Physical data-center controls are generally maintained by the relevant hosting providers, while Elizian remains responsible for appropriately configuring and administering the services under its control.

  • Controlled administrative access.
  • Environment separation.
  • Infrastructure configuration.
  • Backup management.
  • Device and account protection.
  • Secure remote access.
  • Media and information handling.
  • Provider responsibility boundaries.
  • Service availability dependencies.

Elizian does not represent that it directly operates or physically controls every data center used by its infrastructure providers.

Access control

07

Access should reflect role, responsibility, and legitimate need.

Elizian uses identity and access controls designed to help ensure that users can access only the information and functions appropriate to their authorized role.

Unique accounts

Users should access Elizian through individual credentials rather than shared accounts.

Role-based permissions

Customers can assign permissions according to operational responsibility and configured roles.

Customer administration

Authorized customer administrators may manage users, role assignments, account status, and access within their organization.

Authentication

Authentication requirements may include passwords, single sign-on, multifactor authentication, or other controls appropriate to the deployment.

Provisioning and deprovisioning

Access should be added, changed, or removed when a user’s role or employment status changes.

Least privilege

Access should be limited to the minimum information and functionality reasonably required for authorized responsibilities.

Auditability

Material authentication, account, administrative, and workflow events may be recorded to support accountability and investigation.

Customer responsibility

Customers are responsible for assigning appropriate administrators, promptly disabling unauthorized users, protecting customer-managed credentials, and reviewing permissions within their control.

Data protection

08

Safeguards for information in transit, at rest, and in use.

Elizian applies data-protection controls according to the information, processing activity, system, integration, and deployment involved.

Data in transit

Supported web traffic and system exchanges are protected using secure transmission protocols appropriate to the implementation.

Data at rest

Stored information is protected through infrastructure and application controls appropriate to the data and storage service involved.

Secure integrations

Elizian may support APIs, secure file transfer, single sign-on, encrypted web connections, and other approved exchange methods.

Access limitation

Information is made available according to configured roles, customer instructions, workflow purpose, and applicable agreements.

Data minimization

Customers and users should avoid submitting information that is not needed for the configured workflow or service.

Backup protection

Backups are subject to access, infrastructure, and retention controls appropriate to their function.

Sensitive information

Healthcare, identity, credential, and other sensitive information requires heightened care and should not be submitted through general public marketing forms.

Secure development

09

Security considered throughout the software lifecycle.

Elizian incorporates security considerations into design, development, testing, deployment, maintenance, and remediation.

  • Security requirements for material features.
  • Controlled access to development environments.
  • Separation of development and production environments.
  • Review of material code changes.
  • Dependency and library management.
  • Protection of credentials and secrets.
  • Testing before release.
  • Controlled production deployment.
  • Defect and vulnerability tracking.
  • Logging and error review.
  • Change records.
  • Rollback and corrective-action processes.
  • Security consideration for integrations.
  • Review of customer-specific configuration.

Security practices evolve as Elizian, its technology, threats, and customer requirements change.

Vulnerability management

10

Identify, prioritize, remediate, and verify.

Elizian uses a risk-based process for identifying and addressing vulnerabilities affecting systems under its control.

  1. 01

    Identification

    Potential issues may be identified through testing, monitoring, vendor notifications, dependency review, customer reports, workforce reports, or external security researchers.

  2. 02

    Validation

    Reported issues are evaluated to confirm applicability, reproducibility, affected systems, and potential impact.

  3. 03

    Prioritization

    Issues are prioritized based on severity, exploitability, exposure, data involved, business impact, and available mitigations.

  4. 04

    Remediation

    Corrective action may include patches, configuration changes, code changes, access restrictions, compensating controls, or service-provider action.

  5. 05

    Verification

    Material remediations are reviewed or tested to confirm that the identified issue has been addressed.

  6. 06

    Documentation

    Relevant findings, ownership, actions, decisions, and closure evidence are maintained according to internal procedures.

Operational visibility

11

Accountability requires evidence of material activity.

Elizian is designed to record relevant platform, account, workflow, and administrative events in support of security, operations, troubleshooting, accountability, and contractual reporting.

  • Authentication activity.
  • Failed sign-in attempts.
  • Account creation and deactivation.
  • Role and permission changes.
  • Administrative actions.
  • Workflow status changes.
  • Case ownership changes.
  • Data-exchange events.
  • Communication events.
  • Escalation activity.
  • Configuration changes.
  • System errors.
  • Security-relevant events.

Log content, availability, retention, and customer access depend on the deployment, event type, contractual requirements, security purpose, and applicable law.

Incident response

12

A structured process for suspected security events.

Elizian evaluates suspected security events according to their nature, affected systems, information involved, customer impact, contractual obligations, and applicable legal requirements.

  1. 01

    Receive and identify

    Establish the initial facts and affected service.

  2. 02

    Triage and classify

    Assess urgency, scope, and potential impact.

  3. 03

    Contain where appropriate

    Limit further exposure or disruption.

  4. 04

    Investigate

    Determine cause, systems, information, and parties involved.

  5. 05

    Preserve relevant evidence

    Maintain information needed for analysis and accountability.

  6. 06

    Correct or mitigate

    Apply appropriate technical or operational action.

  7. 07

    Restore affected services

    Return systems to responsible operation.

  8. 08

    Notify responsible parties when required

    Coordinate contractual and legal communications.

  9. 09

    Document findings and actions

    Maintain an accountable response record.

  10. 10

    Review lessons and corrective measures

    Use findings to improve safeguards and readiness.

Where protected health information or customer-controlled information is involved, notification and cooperation responsibilities may also be governed by the applicable Business Associate Agreement, customer agreement, or other signed documentation.

Resilience

13

Preparing for disruption and responsible recovery.

  • Critical-service identification.
  • Infrastructure dependencies.
  • Backup processes.
  • Restoration procedures.
  • Service-provider dependencies.
  • Recovery prioritization.
  • Internal and customer communication.
  • Incident coordination.
  • Continuity review.
  • Restoration validation.
  • Post-event improvement.

Specific availability commitments, response times, recovery objectives, and service levels are defined in applicable customer agreements when provided.

Third-party risk

14

Service providers are evaluated according to access and responsibility.

Elizian may use service providers to support hosting, communications, identity, support, analytics, file management, integration, monitoring, and other operational functions.

  • Vendors are evaluated based on their service and access.
  • Access should be limited to authorized purposes.
  • Relevant confidentiality and security obligations are addressed contractually.
  • Material incidents are subject to reporting and coordination obligations where applicable.
  • Provider access may be reviewed or removed.
  • Subprocessor information may be provided to qualified customers where appropriate.
  • Elizian remains responsible for its own vendor-selection and oversight obligations.

Confidential vendor-security materials are provided only through appropriate enterprise review channels.

Request the Current Subprocessor List

Healthcare information

15

Healthcare-data responsibilities depend on the service and relationship.

Elizian may process protected health information on behalf of healthcare customers when the applicable service, relationship, and agreement require it. In those circumstances, MyWoosah Inc. may act as a business associate and enter into a Business Associate Agreement defining the permitted uses, safeguards, reporting responsibilities, and other applicable obligations.

HIPAA does not apply to all information collected by Elizian. Public website inquiries, ordinary business contact information, marketing preferences, and similar information are not automatically protected health information.

Healthcare customers remain responsible for their own duties as covered entities, health plans, healthcare providers, government programs, or other regulated organizations.

Users should not submit patient, member, clinical, authorization, referral, or other protected health information through general public website forms.

View Privacy Information

Shared responsibility

16

Security is a shared responsibility.

Customer responsibilities

  • Selecting appropriate administrators.
  • Protecting user credentials.
  • Assigning roles carefully.
  • Removing access promptly.
  • Securing customer-managed devices and systems.
  • Maintaining customer-side integrations.
  • Providing accurate configuration requirements.
  • Training users.
  • Reviewing suspicious activity.
  • Reporting suspected incidents promptly.
  • Submitting information only when authorized.
  • Following applicable privacy and healthcare obligations.
  • Avoiding PHI in public forms.
  • Managing downloaded or exported information securely.

Elizian responsibilities

  • Operating platform controls under its management.
  • Maintaining appropriate access restrictions.
  • Protecting Elizian-managed systems.
  • Evaluating security risks.
  • Addressing vulnerabilities.
  • Managing service providers.
  • Coordinating incident response.
  • Supporting contractual security requirements.
  • Providing relevant security information to qualified customers.

Enterprise evaluation

Security information for qualified enterprise evaluations.

Qualified customers and prospects may request security materials relevant to their evaluation and proposed deployment. Availability may depend on confidentiality requirements and the current status of the requested document.

  • Enterprise Security Overview
  • Architecture and Data-Flow Summary
  • Access-Control Overview
  • Business Continuity Summary
  • Incident-Response Overview
  • Subprocessor List
  • Security Questionnaire
  • Business Associate Agreement template, where applicable
  • Insurance documentation, where approved
  • Independent-assessment materials, if and when available

Responsible reporting

Report a suspected security issue.

If you believe you have identified a security vulnerability, unauthorized access, suspicious activity, or another security concern involving Elizian, contact the security team promptly.

Contact the Security Team

Include the following information when available:

  1. 01Contact information.
  2. 02Affected page, service, or environment.
  3. 03Description.
  4. 04Reproduction steps.
  5. 05Date and time observed.
  6. 06Potential impact.
  7. 07Supporting screenshots or logs.
  8. 08Whether data may have been exposed.

Do not access, alter, download, destroy, retain, or publicly disclose information that does not belong to you.

Elizian by MyWoosah

Trust must be supported by controls, accountability, and evidence.

Elizian works with enterprise customers to define the security responsibilities, access model, integration controls, documentation, and operating safeguards appropriate to each deployment.