Does Athena Security support vendor security, privacy, and cybersecurity assessments?
.
Yes. Athena Security supports vendor security assessments, privacy reviews, cybersecurity due diligence, HIPAA security reviews, and third-party risk assessments for hospitals, healthcare organizations, K–12 schools, government organizations, and enterprise customers.
Athena Security is SOC 2 Type II attested and maintains a security and privacy program designed to support HIPAA compliance for healthcare customers.
How does Athena Security protect PII, PHI, student information, and other sensitive customer data?
Athena Security is designed to minimize privacy and cybersecurity risk, particularly for hospitals, healthcare organizations, schools, and other environments where PII, PHI, student information, or other sensitive information may be processed.
Athena encrypts applicable sensitive customer data, including PII and PHI, throughout the platform. For supported workflows, Athena uses FIPS 140-3 compliant hardware and cryptographic protections at the data-entry device.
Sensitive information is encrypted before or as it is transmitted to Athena cloud services. Athena’s architecture is designed so that the private decryption key remains on the authorized customer device.
Authorized customer users can access and decrypt applicable information using the appropriate key on the device. Athena employees and Athena’s cloud infrastructure do not have access to the customer’s private decryption key.
This architecture helps reduce cloud-data exposure because encrypted customer information stored in the cloud cannot be decrypted using the cloud data alone without the corresponding private key.
Athena Security maintains two public-facing resources for customers:
Trust Center: trust.athena-security.com
Used for security, privacy, compliance, policy, and audit documentation.
System Status: status.athena-security.com
Used for customer communications regarding system availability, uptime, incidents, maintenance, service interruptions, and verification that Athena services are operational.
How does Athena Security handle data retention?
Data-retention periods are customer configurable.
Customers determine how long applicable information is retained based on their organizational policies, legal requirements, privacy requirements, and operational needs.
Authorized customer administrators can modify retention settings as requirements change, allowing hospitals, schools, and other organizations to align Athena Security with their own data-minimization and retention policies.
How can customers verify Athena Security’s security and compliance posture?
Customers conducting a formal vendor privacy, cybersecurity, HIPAA, or data-security assessment may use the Athena Security Trust Center as the primary source for security and compliance information.
trust.athena-security.com provides information related to:
● SOC 2 Type II
● HIPAA-related security controls
● Privacy and data-protection practices
● Information-security policies
● Cybersecurity controls
● Compliance documentation
● Vendor security and privacy due diligence
● Security testing and risk-management information
How can customers verify that Athena Security systems are operational?
Athena Security maintains a dedicated public system-status site at:
status.athena-security.com
This site is used to communicate with customers and provide visibility into:
● Current system status
● Service availability
● Uptime and operational health
● Scheduled maintenance
● Service interruptions
● Active or resolved incidents
● Customer-facing operational communications
● Verification that Athena services are online and functioning
This provides customers with an independent, public-facing location to review Athena Security’s operational status and service communications.
Security & Compliance: trust.athena-security.com
System Status & Availability: status.athena-security.com
Does Athena Security support HIPAA and hospital vendor security assessments?
Yes. Healthcare organizations may use the Athena Security Trust Center as part of vendor due diligence, cybersecurity reviews, privacy assessments, and HIPAA-related security assessments. Athena Security provides information regarding its SOC 2 Type II attestation, HIPAA-related security controls, encryption, privacy safeguards, risk management, and other security documentation.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article