Security Q and A for Noah ES

Security Q and A for Noah ES


Noah ES Network Diagram

Please see the descriptions of the numbered points.


Business Topics

Q: Does HIMSA provide an SLA (Service Level Agreement) with Noah ES?

A: The Noah ES Terms of Service does not guarantee a specific benchmark but rather states that HIMSA intends that Noah ES will have an availability of at least 99 % of the time. See Noah ES Service Status for a list of historical issues.

Q: Does HIMSA provide specific terms regarding recovery time during unexpected larger issues?

A: HIMSA does not, but please see section 6 above. The system is currently designed to be fully operational in 2 hours or less.

Q: Does HIMSA provide HIPAA/GDPR/Security training for each new HIMSA employee as well as periodically for all other members of your workforce?

A: Yes

Q: Does HIMSA require non-disclosure agreements (NDAs) or confidentiality agreements with third-party vendors if confidential, sensitive, or Personally Identifiable Information (PII) will be disclosed?

A: Yes

Q: Does HIMSA require all employees to sign a confidentiality (non-disclosure) agreement as a condition of employment?

A: Yes

Q: How frequently does HIMSA assess the risk of your subcontractors?

A: At least annually

Q: Does Noah ES use Online Tracking technologies to collect information about users that interact with your application? (e.g. Google Analytics, Meta Pixel, Hotjar, Mixpanel, etc.)?

A: No

Q: Does HIMSA incorporate security (i.e. controls, processes, training) as part of your Software Development Lifecycle?

A: Yes

Q: Does Noah ES have an Artificial Intelligence (AI) component?

A: No

Technical

Q: Where is Noah ES data processed and stored

A: see section 6 of the network diagram

Q: Does Noah ES support a hybrid setup where my Noah ES database can be hosted within my network or Azure Cloud account that my organization controls?

A: No, this is not supported.

Q: Does Noah ES require a desktop client application

A: Yes, see part 2 in the above network diagram. The Noah ES client-supported versions and support operating systems can be found here

Q: Who is responsible for keeping the Noah ES client software versions up to date?

A: The customer is.

Q: What network URLs need to be whitelisted for Noah ES to function?

A: See Internet Connection, Firewall and Browser Requirements

Identity and Access Management

Q: Who is responsible for provisioning customer user accounts?

A: The customer is. Please see The Noah ES Portal

Also, see Managing User Levels and Permissions

Noah ES provided user account authentication (local)

By default, Noah ES provides a user authentication system based on a username (email address) and a password (see the password requirements to the right).

Noah ES also provides Enabling MFA (Multi Factor Authentication) as an included service.

Q: Does Noah ES require passwords to be rotated or require users to change their passwords on a regular automated schedule?

A: No.

Q: Can an administrator for the Noah ES account force password resets?

A: Yes, please see Forgotten Password for Noah ES.

HIMSA recommends that you set users to use MFA or to consider optional integration with MS Entra ID and other Open ID Connected-based identity systems, offered at no additional Noah ES cost, see:

 

Noah ES Local account password requirements

Passwords will be required to be strong, defined as:

  • Minimum 8 characters in length

  • Maximum 64 characters in length

Additionally, the password must contain characters from 3 of the following points

  • Uppercase characters of European languages (A through Z, with diacritic marks, Greek and Cyrillic characters)

  • Lowercase characters of European languages (a through z, sharp-s, with diacritic marks, Greek and Cyrillic characters)

  • Base 10 digits (0 through 9)

  • Nonalphanumeric characters: ~!@#$%^&*_-+=`|(){}[]:;"'<>,.?/

  • Any Unicode character is categorized as an alphabetic character but is not uppercase or lowercase. This includes Unicode characters from Asian languages

Monitoring

Noah ES Provides an extensive log called the Activity Log. The Activity Log is available via the Noah ES Portal and can be exported via a CSV file format. This log records items such as:

  • User activity (Login, Logout, Failed login, adding and editing users, MFA enabled, disabled)

  • user assignment to different permission levels

  • changes to the definitions of permissions levels

  • Exporting and importing data

  • Patient record activity, adding, viewing, deleting

The activity log entries are kept for one year and then deleted.

Q: Does HIMSA take the responsibility to review the activity log for suspicious activity for a Noah ES customer

A: No

Notifications for important events are emailed to all Noah ES Administrators:

  • First time Noah ES Account Access

  • User login from a new device

  • Exporting patients out of Noah ES

  • User permissions elevated

  • User group permissions changed

  • The first time Noah ES API app is enabled

  • Noah ES API App access levels edited

Vulnerability Management

Q: Has a third party conducted a penetration test on your product or service within the last year?

A: Yes

Q: Does HIMSA use a documented or formal change/release management process?

A: Before any change is made, HIMSA ensures that the problem is properly understood by clear and easy-to-understand text. The development team investigates possible solutions. Product and Project Management and the Development team conduct a security risk analysis on the proposed solution.

Once the security review is complete, QA implements and tests the solution in a non-production environment. Once it is proven to address the issue, the solution is published in the production environment.