Athena Security Vendor Security Assessment, Privacy & Data Security FAQ

Modified on Tue, Sep 8 at 4:12 PM

Does Athena Security support vendor security, privacy, and cybersecurity assessments?

.

Yes. Athena Security supports vendor security assessments, privacy reviews, cybersecurity due diligence, HIPAA security reviews, and third-party risk assessments for hospitals, healthcare organizations, K–12 schools, government organizations, and enterprise customers.


Athena Security is SOC 2 Type II attested and maintains a security and privacy program designed to support HIPAA compliance for healthcare customers.

How does Athena Security protect PII, PHI, student information, and other sensitive customer data?

Athena Security is designed to minimize privacy and cybersecurity risk, particularly for hospitals, healthcare organizations, schools, and other environments where PII, PHI, student information, or other sensitive information may be processed.

Athena encrypts applicable sensitive customer data, including PII and PHI, throughout the platform.  For supported workflows, Athena uses FIPS 140-3 compliant hardware and cryptographic protections at the data-entry device.

Sensitive information is encrypted before or as it is transmitted to Athena cloud services. Athena’s architecture is designed so that the private decryption key remains on the authorized customer device.

Authorized customer users can access and decrypt applicable information using the appropriate key on the device. Athena employees and Athena’s cloud infrastructure do not have access to the customer’s private decryption key.

This architecture helps reduce cloud-data exposure because encrypted customer information stored in the cloud cannot be decrypted using the cloud data alone without the corresponding private key.

Athena Security maintains two public-facing resources for customers:

Trust Center: trust.athena-security.com
Used for security, privacy, compliance, policy, and audit documentation.

System Status: status.athena-security.com
Used for customer communications regarding system availability, uptime, incidents, maintenance, service interruptions, and verification that Athena services are operational.

How does Athena Security handle data retention?

Data-retention periods are customer configurable.

Customers determine how long applicable information is retained based on their organizational policies, legal requirements, privacy requirements, and operational needs.

Authorized customer administrators can modify retention settings as requirements change, allowing hospitals, schools, and other organizations to align Athena Security with their own data-minimization and retention policies.

How can customers verify Athena Security’s security and compliance posture?

Customers conducting a formal vendor privacy, cybersecurity, HIPAA, or data-security assessment may use the Athena Security Trust Center as the primary source for security and compliance information.

trust.athena-security.com provides information related to:

 SOC 2 Type II

 HIPAA-related security controls

 Privacy and data-protection practices

 Information-security policies

 Cybersecurity controls

 Compliance documentation

 Vendor security and privacy due diligence

 Security testing and risk-management information


How can customers verify that Athena Security systems are operational?

Athena Security maintains a dedicated public system-status site at:

status.athena-security.com

This site is used to communicate with customers and provide visibility into:

 Current system status

 Service availability

 Uptime and operational health

 Scheduled maintenance

 Service interruptions

 Active or resolved incidents

 Customer-facing operational communications

 Verification that Athena services are online and functioning

This provides customers with an independent, public-facing location to review Athena Security’s operational status and service communications.

Security & Compliance: trust.athena-security.com
System Status & Availability: status.athena-security.com


Does Athena Security support HIPAA and hospital vendor security assessments?


Yes. Healthcare organizations may use the Athena Security Trust Center as part of vendor due diligence, cybersecurity reviews, privacy assessments, and HIPAA-related security assessments. Athena Security provides information regarding its SOC 2 Type II attestation, HIPAA-related security controls, encryption, privacy safeguards, risk management, and other security documentation.


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article