Data Security
Protecting Health Information at Every Layer
Health information is among the most sensitive information a person can share. Biomarks.ai is being built with security as a core consideration across the collection, processing, storage and sharing of health information.
As an early-stage technology company, our security program will continue to develop as Biomarks grows. We believe it is important to distinguish between security practices currently implemented and certifications or independent assurance programs that may be pursued in the future.
Security by Design
Our objective is to consider security throughout the development lifecycle rather than treating it as something added after a product has been built.
This includes considering what information needs to be collected, who needs access to it, how access should be controlled, how information is transmitted and stored, and when information should be deleted or de-identified.
Access to Health Information
Biomarks is designed around the principle that access to sensitive information should be limited to people and systems that have an appropriate reason to access it. As the platform develops, access permissions and user roles are intended to help separate individual, clinician and organizational access to information.
Protecting Data
Biomarks uses and continues to develop technical and organizational measures intended to protect personal and health information against unauthorized access, loss, misuse, alteration or disclosure. The specific safeguards used by Biomarks will continue to evolve as our infrastructure, products and security program mature.
Third-Party Technology
Modern cloud platforms depend on specialist infrastructure, software and technology providers. Where third parties process information on behalf of Biomarks, we consider the nature of the information involved and the role of the provider. As Biomarks grows, vendor security and privacy assessment will form an increasingly important part of our security program.
Data Minimization
One of the simplest ways to reduce information security risk is not to collect information unnecessarily. Biomarks aims to collect and process information that is relevant to providing its services and health intelligence functionality.
Security Incidents
No online platform can guarantee absolute security. Biomarks intends to maintain processes for identifying, investigating and responding to security incidents and to meet applicable notification obligations where a data breach occurs.
Our Security Journey
We are building Biomarks for a future in which clinicians, healthcare organizations and individuals can confidently use the platform with sensitive health information. As the company grows, we expect our security program to become increasingly formalized through documented controls, risk assessments, testing, staff training and appropriate independent assurance.
We will only display certifications or security credentials once Biomarks has actually obtained them.
Security isn’t a badge. It’s an ongoing responsibility.
