PSS Believes in Securing Your Data
PSS serves many clients who have unique concerns about security of their data and that of their valued customers. Our diverse client base demands that we adopt very comprehensive and strict controls as required under HIPAA, FDA guidelines and other regulatory mandates such as Sarbanes-Oxley or Graham-Leach-Bliley. Even our clients with less sensitive data, having no personally identifiable information other than name and address, are looking to PSS to ensure compliance with their published privacy policies. What in the past may have been perceived as extreme security procedures are now an expectation of the marketplace.
PSS has upgraded security at all levels — physical access to our facilities, training, background checks and data networks. We now offer security options that provide our clients with the appropriate controls to address the types of risk they are expected to prepare for.
Physical Security:
All PSS team members are required to wear and prominently display a photo ID badge at all times.
All points of entry are equipped with electronic access controls requiring either a PIN or badge unless manned by a PSS team member.
All PSS team members are required to have annual security training and sign a blanket confidentiality agreement. Those with access to certain client data also must pass a criminal and credit background check.
A high security, clean desk data entry facility with over 125 workstations is available for clients with such requirements. Entry to the room is controlled and logged by an electronic access control system requiring that an approved ID card is scanned before entry. The room is also equipped with security cameras that are monitored real time and digitally recorded.
Our facility is both DEA and FDA registered.
Document Security:
On site high capacity equipment is used to shred documents containing any form of consumer information, even if just name and address.
Any documents requiring storage are kept under lock and key and logged in/out of storage
Network/Data Security:
A formal security committee oversees all aspects of data security. The committee is responsible for establishing policy, assessment of risks and investigation of any indication of a possible threat. The committee is accountable to the VP/CFO who holds ultimate responsibility for all security.
All access to data is password protected utilizing industry identified best practices to insure access only by those with specific rights to do so.
Data transmissions both in and out can be encrypted. Dedicated encrypted storage is also available.
Sensitive client data has been physically isolated from risk of remote access to our networks while still maintaining such functionality to those clients who require and utilize our on-line reporting tools.
An independent third party consulting firm is used for intrusion testing.
We are confident our systems and controls provide our clients with a secure and safe environment. Please feel free to contact us with questions concerning this issue or any of the many data capture or fulfillment services provided by PSS.