Allscripts Security Program
At Allscripts, we are extremely vigilant when it comes to protecting the confidentiality, integrity and availability of the sensitive information with which we have been entrusted.
Security Team Vision:
To protect the security of corporate, employee, client and other confidential information; ensure that it is available for use; build confidence in the integrity of information; foster a culture that values security through promoting security awareness and providing guidance on security expectations and goals.
Allscripts takes a risk-based approach to security, regularly re-evaluating the latest risks in the ever-changing security landscape.
For more information on the Allscripts Security Program, please reference the following resources:
Allscripts maintains a robust compliance environment based on leading industry standards. To validate our security controls and foster continuous improvement, Allscripts engages in many certification and independent reviews for our products and service offerings. These activities span across both product and geographical regions and include, but are not limited to, ISO 27001:2013 certification, ISO 9001:2015 reviews, SOC 2, Type 2 reports, EHNAC and EPCS certifications.
Certified Allscripts products contain security features to meet applicable requirements under the ONC Certification Rule. These include authentication and access control, as well as authorization, auditing and encryption features.
Security requirements outlined in the ONC Certification Rule are a base, and many Allscripts products have features that go beyond these requirements. Furthermore, Allscripts employs a secure development lifecycle incorporating risk-based threat modeling, automated code reviews and security testing.
Allscripts Hosting Security
Allscripts hosting security teams maintain tools and processes for ensuring the security of data in Allscripts hosting centers. The tools include firewalls, intrusion detection/prevention systems, proactive vulnerability scanning, backup and disaster recovery procedures, as well as physical security controls. The Allscripts Security Operations Center (SOC) monitors Allscripts networks, systems and databases around the clock for security events.
For more information on the security controls for a product, please visit the individual product pages on Allscripts.com or contact your Allscripts Outcome Executive. If you have any questions, please contact the Allscripts Security Team at:
Allscripts Healthcare, LLC
305 Church at North Hills St
Raleigh, NC 27609
Attention: Chief Security Officer
PandSCompliance (at) allscripts (dot) com
Discover how, together, we can expand the possibilities at your own organisation today—all through the power of Allscripts partnership, solutions and services.