With so much information flying back and forth through cyberspace how do you know your information is secure? This is an especially important question for those in the medical field that deal with patient information and fall under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). There are a few things that a consumer should look for when trying to decide on a virtual pbx provider.
Administrative Procedures – A virtual pbx provider should have documented, formal practices to protect data and limit access to files. Most virtual pbx providers will have policies that allow access to voice and fax messages for the purpose of maintenance, customer service, repair, and backup, or in response to legal inquiries or warrants that legally force the disclosure of the messages or documents from courts or government agencies.
Physical Safeguards – A virtual pbx provider should be able to protect data from fire, other natural and environmental hazards and intrusion. A provider should have measures in place that include an industry standard fire safety system, off-site backups, and industry standard security systems to protect Personal Health Information from physical vulnerabilities.
Technical Security Services – a virtual pbx provider should have measures in place to protect information and control individual access to information. There are usually 3 ways to access documents in a virtual pbx system and each one should have their own independent security measures.
Technical Security Mechanisms – A virtual pbx provider should be able to guard against unauthorized access or loss of data over the communications network. Data storage systems should implement industry standard fault tolerant measures to prevent data loss due to storage media failure. Databases and storage systems should be protected by battery backup technology to protect against potential data loss due to power failures. In addition, servers should use a measure comparable to FreeBSD UNIX to prevent unauthorized access and data security compromise.
It can sometimes seem impossible to make sure your, and your clients, information is secure. However, there are security measures available to safeguard information sent through cyberspace. You just need to make sure the provider you decide to do business with takes the steps to implement them.