Product Data Security

Our Security Commitment

Auditdata serves healthcare organizations worldwide with medical device products and services. Handling sensitive personal data is part of that work, and our security practices reflect what that responsibility requires.

Information Security Management System

Auditdata maintains and continuously improves an Information Security Management System (ISMS) in accordance with the Auditdata Information Security Policy, supporting trustworthy relationships with customers and partners.

The ISMS governs how information security is implemented, maintained, and improved across the organization. It is the mechanism through which organizational and technical security controls are operated and kept effective.

The Auditdata ISMS is certified to ISO/IEC 27001, an international standard for information security management. Certification validates that Auditdata has implemented the controls defined in the standard, including the principles for initiating, implementing, maintaining, and improving information security management.

Read More About Our Compliance
I N F O R M A T I O N S E C U R I T Y M A N A G E M E N T S Y S T E M ISO/IEC 270001

Cloud Hosting and Infrastructure Security

Auditdata’s Audiology Practice Management System, Manage™ is developed using the Microsoft Azure technology in accordance with the Auditdata product development processes compliant and certified with key industry standards such as ISO/IEC 27001 Information Security Management System and ISO/IEC 13485 Quality Management Systems for Medical Devices.

Manage™ is operated by the Auditdata’s Cloud Operations unit included in the ISO 27001 certificate scope.

Manage™ runs in the Microsoft Azure data centers managed and operated by Microsoft Global Foundation Services (GFS). These geographically dispersed data centers also comply with key industry standards, such as ISO/IEC 27001, for security and reliability. They are managed, monitored, and administered by Microsoft operations staff that have years of experience in delivering the world’s largest online services with 24 x 7 continuity.

In addition to datacenter, network, and personnel security practices, Windows Azure incorporates security practices at the application and platform layers to enhance security for application developers and service administrators.

Azure

Data Location

Risk Assessment

Auditdata's choice of cloud provider is supported by a comprehensive Cloud Computing Service Provider Risk Assessment, carried out in accordance with the ENISA Cloud Computing Risk Assessment checklist from the European Union Agency for Cybersecurity. The assessment follows the recommendations of the Danish Data Protection Agency (Datatilsynet) for cloud-based processing of sensitive personal data.

To support customers in evaluating the security of Manage, Auditdata has produced a white paper mapping the essential information security controls in Manage to the ISO 27001 controls. It gives customers detailed information on Auditdata's security policies and procedures, and is available on request at compliance@auditdata.com.

For more on the compliance capabilities of Microsoft Azure, visit the Microsoft Trust Center.

Do You Have Any Questions?

If you have any questions about how we handle information and keep our and your data safe, don’t hesitate to contact our CSO (Chief Security Officer) at securityevent@auditdata.com or fill out the form, and we will get back to you within two working days.