Information Security Program
Modules
Last Updated: September 6, 2025
This document is incorporated in the Order Form between MEDVA and Client and forms part of the Client Agreement. It outlines MEDVA’s Information Security Program, as well as the respective responsibilities of MEDVA and the Client with respect to information security. This document describes security measures used in connection with remote work by Virtual Assistants (Work from Home) and on-site operations in one of MEDVA’s secure facilities to ensure the protection of Client data and compliance with applicable legal and regulatory requirements.
1. Standard Security and Productivity Technologies
As part of its standard service package, MEDVA shall deploy the following technologies for all assigned Virtual Assistants, unless otherwise agreed with Client in writing: (i) time and activity monitoring software and (ii) secure remote access. A description of each tool and MEDVA’s and Client’s responsibilities with respect to these technologies is set forth below.
| Time and Activity Monitoring Software | |
| Overview | MEDVA uses a time-tracking and activity-monitoring platform to enhance visibility, accountability, and productivity in remote work environments. It provides real-time insights into Virtual Assistant activity levels and time allocation. |
| MEDVA Responsibilities | MEDVA will deploy this time and activity monitoring software. Depending on Client’s preferences, the software offers both interactive (user-visible) and silent (background) tracking functionalities to monitor Virtual Assistant work hours and activity and provides Client with access to a real-time dashboard for reviewing time-tracking data, productivity metrics, and work patterns. |
| Client Responsibilities | Client shall collaborate with MEDVA in:
· reviewing productivity data and addressing any trends, anomalies, or performance-related issues identified through the platform; and · using data collected from the platform, where appropriate, as part of ongoing performance management, coaching, or corrective action discussions with assigned Virtual Assistants. |
| Secure Remote Access | |
| Overview | MEDVA uses a secure remote access solution that encrypts network traffic between the Virtual Assistant and Client’s environment. While it provides important security features, additional security enhancements may be required for full HIPAA compliance. |
| MEDVA Responsibilities | MEDVA will:
· configure and deploy secure remote access for all Virtual Assistants to enable secure, encrypted access to approved Client systems, platforms, and applications; · monitor performance and troubleshoot any access or connectivity issues as they arise; and · ensure implementation is aligned with current security best practices and tailored to Client’s access requirements, as communicated in writing to MEDVA by Client. |
| Client Responsibilities | For the secure remote access protections to be effective, Client must:
· provide clear documentation regarding which systems, tools, and resources its Virtual Assistants are authorized to access; · notify MEDVA promptly in writing of any changes to access privileges, internal protocols, or approved applications that may affect the configuration; and · cooperate with MEDVA during the onboarding phase and any system transitions to test and verify secure connectivity and system access. |
2. Optional Security Enhancements
For Clients requiring HIPAA compliance, MEDVA offers additional optional security solutions including an endpoint security and management solution and facial and behavioral monitoring to enhance data security in bring-your-own-device (BYOD) environments. These solutions are mandatory for HIPAA-compliant implementations, are available for an additional fee, and must be explicitly requested by Client through an Order Form with MEDVA. Implementation of these additional security measures is required for MEDVA to serve as a HIPAA business associate. Any optional security enhancements must be documented through an Order Form.
| Endpoint Security & Management Solution | |
| Overview | MEDVA’s endpoint security and management solution is an optional, off-the-shelf software solution that locks down personal Windows devices to create a secure BYOD (Bring Your Own Device) environment. While it implements Zero Trust architecture to isolate work activity and prevent data leakage or unauthorized access, additional security enhancements may be required for HIPAA compliance. |
| MEDVA Responsibilities | For Clients who choose to implement this endpoint security and management solution, MEDVA will:
· deploy a fully encrypted and isolated virtual workspace on the Virtual Assistant’s device to mitigate security risks and protect against unauthorized access or data breaches; · conduct an IT discovery call to understand Client-specific requirements (e.g., tools, platforms, applications) and configure a custom profile for its Virtual Assistants’ secure desktop environment; · monitor the operational status of the secure environment and respond to access or performance issues as they arise; · maintain and update the configuration as necessary to ensure continued compliance with security protocols and support Client-requested system changes; and · provide reasonable technical support to the Client and Virtual Assistants related to the deployment and functionality of the solution. |
| Client Responsibilities | Client shall:
· require its Virtual Assistants to use MEDVA’s endpoint security system when using BYOD devices; · promptly notify MEDVA of any security incidents or device-related issues; · provide MEDVA with necessary access to all required Client-specific systems (e.g., email, EMR, VOIP); · provide MEDVA with installation files or access credentials for any Client applications not natively supported, to enable deployment of the solution; and · notify MEDVA of any new applications/websites that the Virtual Assistants will need to access at least seven (7) business days prior to intended use. |
| Facial and Behavioral Monitoring | |
| Overview | Facial and behavioral monitoring is an optional, off-the-shelf monitoring solution that provides real-time oversight of Virtual Assistant activity. It uses facial recognition and behavioral analysis to detect unauthorized behaviors and support a secure, policy-compliant remote work environment. |
| MEDVA Responsibilities | For Clients who choose to implement facial and behavioral monitoring, MEDVA will:
· deploy and manage facial and behavioral monitoring software to monitor compliance and detect potential security or behavioral violations during active work sessions; · notify Client of any flagged non-compliant behavior, policy breaches, or detected risks observed through the monitoring platform; and · maintain the facial and behavioral monitoring system and provide reasonable technical support related to its functionality and alerts. |
| Client Responsibilities | Client shall:
· require its Virtual Assistants to use the facial and behavioral monitoring system; and · cooperate with MEDVA in investigating and resolving any incidents, alerts, or escalations flagged through facial and behavioral monitoring. |
3. Client Acknowledgment of Responsibility
Clients who choose not to implement the endpoint security and management solution and facial and behavioral monitoring, or comparable security solutions (approved by MEDVA) acknowledge and agree that: (i) their use of MEDVA services will not be HIPAA-compliant; (ii) MEDVA will not enter into a Business Associate Agreement with Client, and (iii) MEDVA is not liable for potential HIPAA violations or data security incidents that occur as a result of insufficient safeguards within Client’s preferred remote environment. By declining these solutions, the Client acknowledges that it remains solely responsible for ensuring its compliance with all applicable data protection and regulatory requirements.
4. Secured Facility On-Premise Security
MEDVA implements the following security measures for Virtual Assistants working from MEDVA’s on-site operation facility.
| STANDARD ENPOINT SECURITY | |
| Endpoint Management Software | |
| Overview | MEDVA’s endpoint management software provides a unified platform for automating patch management, asset management, remote troubleshooting, and endpoint protection. This allows MEDVA, in coordination with its third-party facilities vendor, to maintain visibility and control over all endpoints, implement automated patching, and protect against ransomware while ensuring continuity of endpoint management without disruption to end-user experience. |
| Client Responsibilities | Client is responsible for:
· maintaining endpoint devices; · providing MEDVA with all information reasonably requested to ensure device security; and · promptly reporting any deviations or issues related to endpoint security. |
| Data and Device Security | |
| Overview | MEDVA uses a data and device security and management solution to safeguard devices, applications, and data. This allows MEDVA, in coordination with its third-party facilities vendor, to: (1) detect unauthorized device movements and remotely freeze or wipe compromised devices; and (2) safeguard on-site devices through firmware protection. |
| Client Responsibilities | Client is responsible for reporting and alerting MEDVA within 24 hours of becoming aware of any suspicious activity or compromised devices. |
| NETWORK SECURITY | |
| Firewall-Level Security Controls | |
| Overview | MEDVA, in coordination with its third-party facilities vendor, implements network segmentation policies to monitor and control the flow of network traffic to detect potential breaches and reduce the risk of internal threats. |
| Endpoint Detection and Response (EDR) Software | |
| Overview | MEDVA, in coordination with its third-party facilities vendor, uses CrowdStrike EDR software to monitor and respond to endpoint devices for potential threats, such as malware or ransomware. |
| Network Operations Center (NOC) | |
| Overview | MEDVA’s third-party facilities vendor maintains a Network Operations Center (NOC), providing 24/7 monitoring of MEDVA’s on-site network and server infrastructure. Network performance monitoring and security information and event management solutions are used to oversee network and server performance |
| Client Responsibilities | Client shall promptly report and alert MEDVA within 24 hours of becoming aware of any network-related security incidents. |
| PHYSICAL SECURITY | |
| Overview | Physical security controls, including 24/7 security personnel, biometric access control, and 24/7 CCTV surveillance, protect work environments within MEDVA’s on-site operation facility and are designed to restrict unauthorized access, monitor activity, and support compliance with applicable data protection and security standards. |
| Client Responsibilities | Client shall require their Virtual Assistants to safeguard and keep their entrance credentials confidential to ensure that only authorized personnel access MEDVA-monitored areas and shall promptly report and alert MEDVA within 24 hours of any termination of services or Virtual Assistant removal so that physical site access privileges may be promptly revoked. |
| ZERO TRUST ENVIRONMENT | |
| Overview | MEDVA’s Zero Trust environment uses a software-based solution designed to lock down Windows devices to create a secure, compliant environment. It is used to implement Zero-Trust endpoint security through an isolated, encrypted work environment to prevent unauthorized access to or breaches of Virtual Assistant machines and Client systems. |
| Client Responsibilities | Client shall participate in an IT discovery call with MEDVA to provide Client-specific information regarding the applications and websites that its Virtual Assistants will be required to use, which information will be used to create a Client-specific profile within the Zero Trust environment.
Client shall also: · require its Virtual Assistants to use MEDVA-provided devices and operate within the Zero Trust environment; · promptly report and alert MEDVA within 24 hours of becoming aware of any security incidents or device-related issues; and · provide its VAs with access to all necessary Client-specific systems including but not limited to Client e-mail systems, EMR systems, and VOIP systems. In the case where a Client application is not yet supported within the encrypted work environment and custom packaging is required, Client will provide MEDVA with access to and copies of such application to enable MEDVA to make the application available inside of the secure working environment. Should Client require additional applications or websites to be included in its VAs’ work profile, written request must be made at least seven business (7) days prior to the expected application use date. |
5. Summary of Responsibilities
1. MEDVA
MEDVA is responsible for implementing, maintaining, and managing the security measures set out in this document in accordance with the terms of the Client Agreement. MEDVA provides these security solutions to help ensure that Virtual Assistants’ devices are secure when accessing Client environments. These solutions are limited to the Virtual Assistants’ endpoints and do not provide MEDVA with access to, or control over, any Client systems, networks or, where applicable, cardholder data. MEDVA’s role is to support secure remote work practices for Virtual Assistants and we do not manage, maintain, or monitor any part of your technology environment or data.
2. Client
Client is responsible for adhering to and reinforcing all security policies and guidelines established by MEDVA and for reporting any security concerns or incidents to MEDVA in a timely manner. Client shall require its Virtual Assistants to use the security solutions provided by MEDVA in accordance with this document and shall not permit its Virtual Assistants to bypass such security measures. Client maintains sole responsibility for managing, maintaining, and monitoring its systems, networks, and data.