Summary
HealthPro has successfully achieved SOC 2 Type II attestation, demonstrating that the security controls supporting Hanwha Vision’s cloud services are effectively designed and operating over time.
HealthPro implements comprehensive security measures and controls to protect customer data and maintain the security and reliability of its cloud services.
This article provides an overview of the cybersecurity measures and controls implemented in HealthPro. For more detailed information, refer to the Hanwha Vision Security & Compliance Hub.
SOC 2 Type II
System and Organization Controls (SOC 2) is an independent examination framework for controls related to security, availability, processing integrity, confidentiality, and privacy. SOC 2 Type II evaluates not only the design of these controls but also their operating effectiveness over a specified period of time.
Hanwha Vision’s key cloud services, including Cloud Portal, OnCloud, HealthPro, and OnCAFE, have successfully achieved SOC 2 Type II attestation.
SOC 2 Type II attestation demonstrates Hanwha Vision’s ongoing commitment to maintaining effective security controls and protecting customer data across its cloud services.
Unlike SOC 2 Type I, which evaluates the design and implementation of controls at a specific point in time, SOC 2 Type II also evaluates whether those controls operate effectively throughout the audit period.
For additional information about Hanwha Vision’s SOC 2 Type II attestation and other security and compliance initiatives, please visit the Hanwha Vision Security & Compliance Hub.
Data Security
HealthPro is designed with security controls that protect customer data throughout the cloud service environment.
Security measures are implemented to safeguard data from unauthorized access, modification, disclosure, or loss, and to maintain appropriate protection throughout the data life cycle.
HealthPro applies security controls across:
- Data protection
- Access control
- Authentication and authorization
- Secure communications
- System monitoring
- Security incident management
- Vulnerability management
These controls are part of Hanwha Vision’s broader approach to maintaining the security of its cloud services.
Data Encryption
HealthPro employs encryption technologies to protect data in transit and at rest.
Secure communication protocols are used when data is transmitted between supported devices, HealthPro Bridge, and Hanwha Vision cloud services.
Encryption and security controls help reduce the risk of unauthorized access to customer data during transmission and storage.
Access Control
HealthPro provides role- and permission-based access controls to help organizations manage access to their resources.
Administrators can assign appropriate permissions based on user responsibilities, ensuring that users have access only to the information and functionality required for their roles.
Authentication and authorization controls are also used to prevent unauthorized access to HealthPro resources.
Secure Communication
HealthPro uses secure communication mechanisms to protect connections between users, devices, HealthPro Bridge, and cloud services.
Encrypted communication protects sensitive information and credentials from unauthorized interception while data is being transmitted across networks.
Monitoring and Security Management
Hanwha Vision maintains security monitoring and operational controls designed to identify and respond to potential security events.
SOC 2 Type II assesses the operating effectiveness of relevant controls over an audit period, providing independent assurance that applicable controls are not only designed appropriately but also operating effectively.
Hanwha Vision continues to maintain and improve its security practices as part of its ongoing cloud security and compliance program.
Vulnerability Management
Hanwha Vision maintains processes for identifying, assessing, and addressing security vulnerabilities affecting its products and cloud services.
Security vulnerabilities are evaluated according to established security processes, and appropriate mitigation or remediation measures are implemented based on the assessed risk.
Hanwha Vision also provides security-related information and resources through its Security & Compliance Hub.
Security & Compliance Resources
For the latest information about Hanwha Vision’s cybersecurity practices, compliance achievements, security documentation, penetration-testing information, and related policies, visit the Hanwha Vision Security & Compliance Hub.
The Security & Compliance Hub currently provides information covering areas such as SOC 2 Type 2, ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 42001:2023, IEC 62443, FIPS, Common Criteria, Cyber Essentials, and other security and compliance programs, along with security guides and penetration-test reports.
Additional Information
For more information about HealthPro cybersecurity or assistance with security-related questions, contact your Hanwha Vision representative or customer support team.