Yes. The SmartCase site is compliant with HIPAA security guidelines, and business continuity is assured through full redundancy to an off-site location. SmartCase.com utilizes SSL encryption (https) which encrypts all data transferred between the user and the server. Login authentication utilizes membership controls through Microsoft ASP.NET and the latest tools to authenticate and secure the site down to specific pages. Password encryption is used and stored encrypted within database so its unreadable by anyone. There is also password lockout after excessive failed attempts. Password recovery is achieved using the Secret Question & Answer method. Further, there is Subject-level security whereby Subscribers with multiple user accounts can set access for each user to view specific subjects only. SmartCase undergoes and passes penetration testing to ensure tight security on a regular basis. SmartCase.com servers are protected by Checkpoint Firewalls and there are redundant web servers on-site. SmartCase protects data integrity by backing up the database on a nightly basis to disk and tape, which are securely stored off-site. SmartCase.com is also maintained at a Disaster Recovery site in a separate power grid region, which is a fully functioning and up to date site ready to take over should the main server location fail. There are redundant web servers off-site as well.
|