Protect
Safeguards designed to protect information, software, infrastructure, integrations, credentials, and customer-configured environments.
Enterprise Security
Elizian is designed to support high-stakes healthcare workflows in which confidentiality, integrity, availability, accountability, and responsible access are essential. Our security approach combines administrative, technical, infrastructure, and organizational safeguards appropriate to the information, services, and customer environments involved.
Elizian’s controls are designed to protect the platform, reduce unauthorized access, support auditability, and help customers operate configured workflows responsibly. Specific contractual safeguards, implementation requirements, and security obligations may vary by customer deployment.
Enterprise control architecture
Identity
Role-based access
Encrypted exchange
Application controls
Audit and monitoring
Backup and recovery
Safeguards designed to protect information, software, infrastructure, integrations, credentials, and customer-configured environments.
Identity, permissions, role-based access, documented configuration, change control, and customer-administrator oversight.
Logging, security-event review, vulnerability identification, operational monitoring, and escalation of suspected misuse or compromise.
Incident response, backup, continuity planning, restoration processes, communication, and corrective action.
Security by design
Elizian’s security approach begins with understanding the systems, users, data, integrations, workflows, and organizations involved in each deployment. Safeguards are selected and configured according to the service, information sensitivity, customer requirements, contractual commitments, and identified risks.
No information system can be guaranteed completely secure. Elizian therefore uses layered safeguards, monitoring, governance, customer controls, and incident-response processes intended to reduce and manage security risk.
Administrative controls
Administrative safeguards provide the organizational structure through which security responsibilities are assigned, risks are evaluated, access is governed, incidents are addressed, and controls are maintained.
Elizian assigns responsibility for security-related policies, risk decisions, control administration, incident coordination, vendor review, and customer-security communications.
Security risks and vulnerabilities are evaluated in relation to the services, information, infrastructure, integrations, users, and external dependencies involved.
Access is assigned according to role and business need. Workforce members are expected to protect credentials, follow applicable policies, report suspected incidents, and use information only for authorized purposes.
Relevant personnel receive security and privacy guidance appropriate to their duties and access.
Material changes to software, infrastructure, integrations, permissions, and production configurations are subject to controlled implementation practices.
Service providers with access to Elizian information or systems are evaluated according to the nature of their role, access, and risk.
Elizian maintains processes for receiving reports, investigating suspected events, coordinating response, restoring services, and making required notifications.
Critical dependencies, recovery needs, backups, restoration, and communications are incorporated into continuity planning.
Technical controls
The precise controls available or required may depend on the customer environment, integration model, contracted configuration, data involved, and technical implementation.
Infrastructure protection
Elizian uses managed technology and cloud infrastructure to operate its services. Physical data-center controls are generally maintained by the relevant hosting providers, while Elizian remains responsible for appropriately configuring and administering the services under its control.
Elizian does not represent that it directly operates or physically controls every data center used by its infrastructure providers.
Access control
Elizian uses identity and access controls designed to help ensure that users can access only the information and functions appropriate to their authorized role.
Users should access Elizian through individual credentials rather than shared accounts.
Customers can assign permissions according to operational responsibility and configured roles.
Authorized customer administrators may manage users, role assignments, account status, and access within their organization.
Authentication requirements may include passwords, single sign-on, multifactor authentication, or other controls appropriate to the deployment.
Access should be added, changed, or removed when a user’s role or employment status changes.
Access should be limited to the minimum information and functionality reasonably required for authorized responsibilities.
Material authentication, account, administrative, and workflow events may be recorded to support accountability and investigation.
Customers are responsible for assigning appropriate administrators, promptly disabling unauthorized users, protecting customer-managed credentials, and reviewing permissions within their control.
Data protection
Elizian applies data-protection controls according to the information, processing activity, system, integration, and deployment involved.
Supported web traffic and system exchanges are protected using secure transmission protocols appropriate to the implementation.
Stored information is protected through infrastructure and application controls appropriate to the data and storage service involved.
Elizian may support APIs, secure file transfer, single sign-on, encrypted web connections, and other approved exchange methods.
Information is made available according to configured roles, customer instructions, workflow purpose, and applicable agreements.
Customers and users should avoid submitting information that is not needed for the configured workflow or service.
Backups are subject to access, infrastructure, and retention controls appropriate to their function.
Healthcare, identity, credential, and other sensitive information requires heightened care and should not be submitted through general public marketing forms.
Secure development
Elizian incorporates security considerations into design, development, testing, deployment, maintenance, and remediation.
Security practices evolve as Elizian, its technology, threats, and customer requirements change.
Vulnerability management
Elizian uses a risk-based process for identifying and addressing vulnerabilities affecting systems under its control.
Potential issues may be identified through testing, monitoring, vendor notifications, dependency review, customer reports, workforce reports, or external security researchers.
Reported issues are evaluated to confirm applicability, reproducibility, affected systems, and potential impact.
Issues are prioritized based on severity, exploitability, exposure, data involved, business impact, and available mitigations.
Corrective action may include patches, configuration changes, code changes, access restrictions, compensating controls, or service-provider action.
Material remediations are reviewed or tested to confirm that the identified issue has been addressed.
Relevant findings, ownership, actions, decisions, and closure evidence are maintained according to internal procedures.
Operational visibility
Elizian is designed to record relevant platform, account, workflow, and administrative events in support of security, operations, troubleshooting, accountability, and contractual reporting.
Log content, availability, retention, and customer access depend on the deployment, event type, contractual requirements, security purpose, and applicable law.
Incident response
Elizian evaluates suspected security events according to their nature, affected systems, information involved, customer impact, contractual obligations, and applicable legal requirements.
Establish the initial facts and affected service.
Assess urgency, scope, and potential impact.
Limit further exposure or disruption.
Determine cause, systems, information, and parties involved.
Maintain information needed for analysis and accountability.
Apply appropriate technical or operational action.
Return systems to responsible operation.
Coordinate contractual and legal communications.
Maintain an accountable response record.
Use findings to improve safeguards and readiness.
Where protected health information or customer-controlled information is involved, notification and cooperation responsibilities may also be governed by the applicable Business Associate Agreement, customer agreement, or other signed documentation.
Resilience
Specific availability commitments, response times, recovery objectives, and service levels are defined in applicable customer agreements when provided.
Third-party risk
Elizian may use service providers to support hosting, communications, identity, support, analytics, file management, integration, monitoring, and other operational functions.
Confidential vendor-security materials are provided only through appropriate enterprise review channels.
Request the Current Subprocessor ListHealthcare information
Elizian may process protected health information on behalf of healthcare customers when the applicable service, relationship, and agreement require it. In those circumstances, MyWoosah Inc. may act as a business associate and enter into a Business Associate Agreement defining the permitted uses, safeguards, reporting responsibilities, and other applicable obligations.
HIPAA does not apply to all information collected by Elizian. Public website inquiries, ordinary business contact information, marketing preferences, and similar information are not automatically protected health information.
Healthcare customers remain responsible for their own duties as covered entities, health plans, healthcare providers, government programs, or other regulated organizations.
Users should not submit patient, member, clinical, authorization, referral, or other protected health information through general public website forms.
Shared responsibility
Enterprise evaluation
Qualified customers and prospects may request security materials relevant to their evaluation and proposed deployment. Availability may depend on confidentiality requirements and the current status of the requested document.
Responsible reporting
If you believe you have identified a security vulnerability, unauthorized access, suspicious activity, or another security concern involving Elizian, contact the security team promptly.
Contact the Security TeamDo not access, alter, download, destroy, retain, or publicly disclose information that does not belong to you.
Elizian by MyWoosah
Elizian works with enterprise customers to define the security responsibilities, access model, integration controls, documentation, and operating safeguards appropriate to each deployment.