Security
Empire Gate IPA connects providers and payers in value-based care, which means partners trust us with sensitive information. This page describes, in general terms, how we approach the security of that information and how to report a security concern.
Our commitment
We treat security and privacy as foundational. We work to protect the confidentiality, integrity, and availability of the information entrusted to us by the providers, payers, and patients the network serves.
HIPAA and business associate agreements
This public website is not intended for the submission of protected health information (PHI). PHI exchanged in the course of a partnership is governed by HIPAA and an executed business associate agreement (BAA), not by this page. We enter BAAs with provider and payer partners and require equivalent terms from any subcontractor that handles PHI.
Data safeguards
Where we handle sensitive data, we apply administrative, physical, and technical safeguards, including encryption in transit and at rest, network controls, and logging and monitoring. This public marketing site itself stores no PHI.
Access control
Access to systems that hold member or partner data is granted on a least-privilege basis with unique credentials, and multi-factor authentication is required for partner-facing systems as they come online.
Vendors and subcontractors
We perform diligence on the technology vendors and subcontractors we rely on, and we require business associate agreements wherever PHI is involved.
Reporting a security concern
We welcome reports from security researchers and the public. If you believe you have found a vulnerability or other security issue affecting Empire Gate IPA, please email security@empiregateipa.com with a description of the issue and the steps to reproduce it. Please do not include PHI or real member data in your report. We ask that you give us a reasonable opportunity to address the issue before public disclosure; we will not pursue legal action for good-faith research conducted under these guidelines.
Breach notification
In the event of a security incident affecting protected information, Empire Gate IPA follows its obligations under the HIPAA Breach Notification Rule and applicable New York State law.
Contact
Security questions and reports can be sent to security@empiregateipa.com.