Manual

CAARS 2 Manual

Chapter 3: Compliance


Compliance

MHS holds privacy to be of primary importance throughout its business practices and is committed to the confidentiality, availability, and safeguarding of all personal information collected. MHS is committed to a Trust Framework that governs how we interact with the data that we are entrusted with. The MHS Trust Framework has 4 pillars: ethics, stewardship, transparency, and accountability (see https://mhs.com/digital-trust for details). As a part of these pillars, MHS adheres to the regulations set out by the Health Insurance Portability and Accountability Act (HIPAA; CDC and the U.S. Department of Health and Human Services, 2003) and the Personal Information Protection and Electronic Documents Act (PIPEDA; Office of the Privacy Commissioner of Canada, 2020). In addition, MHS is Family Educational Rights and Privacy Act (FERPA; United States Code, 2017), ISO/IEC 27001:2013 (ISO 27001), and System and Organization Controls 2 (SOC 2) certified. MHS also ensures the security and integrity of personal information through a variety of physical, technical, and organizational measures. These integral elements are regularly reviewed and updated to ensure the security and protection of all personal information. These actions significantly reduce the chance of loss, unauthorized access, inappropriate disclosure, and unauthorized use of personal information.

< Back Next >