/ HIPAA and security

One security baseline across every clinic in scope.

Security variation is what makes a multi-site clinic estate hard to protect and hard to prove. Surya defines the configurations it supports, applies the agreed baseline as each module enters service and keeps a record of the work.

HIPAA compliance remains an organizational responsibility. Surya provides scoped technology controls, operational practices and evidence that support your program.

Find your starting scope

/ HIPAA and security in operation

Make the supported standard easier to prove and protect.

The clinic standard turns safeguards into operating practice. Because Surya defines the configurations it supports, the same controls, records and handling steps apply at every clinic in scope.

Configuration baseline

Supported device configurations and the agreed security baseline are applied when a module enters service, not after the fact.

Access and identity responsibilities

Access to devices and to Surya facilities is controlled and logged. Identity and account authority remain with your organization, with an agreed operating boundary.

Endpoint protection and updates

Endpoint protection and update handling for supported devices are operated within the agreed scope.

Support records

Support requests, troubleshooting and changes inside the supported environment produce an operational record available for review.

Device custody

Devices in Surya's custody are tracked by serial number, and every handoff, return and swap is documented.

Media sanitization

Drives are erased to NIST 800-88 where erasure applies, with a certificate per device, before approved disposition.

Vendor responsibilities

A business associate agreement is available. Clinical application and medical-equipment vendors retain their own responsibilities.

Incident escalation

Issues needing a vendor, a physical action or your approval follow an agreed escalation path with named owners.

HIPAA compliance remains an organizational responsibility. Surya provides scoped technology controls, operational practices and evidence that support your program.

/ Working alongside your current IT

Start without changing everything.

Coexistence works when the boundary is explicit. Before work begins we map the shared dependencies, confirm the access and authority Surya needs, and name who owns each retained system.

One accountable operator per responsibility

A device may depend on several services. Each control or responsibility has a single named owner.

Shared dependencies are mapped first

Identity, network, EHR access, device management and security tools need an agreed operating boundary before anything changes.

Authority and access are confirmed

Surya must hold the access and authority required to deliver the commitments in its own scope.

Licenses are accounted for

Required licensing and entitlements are identified before deployment, not discovered afterwards.

Routing is agreed and tested

We keep an existing help-desk entrance where feasible, or provide a clearly scoped Surya contact path for clinic staff.

Change approval has a route

Changes touching a retained system follow the agreed approval path with the named owner.

Unsupported technology stays with its operator

Anything outside the agreed scope remains the responsibility of the team or provider that operates it today.

Required access, contract boundaries, licenses and provider coordination are assessed before Surya accepts scope. Surya cannot commit to security or uptime for retained systems it does not control.

Where authority stays.

Surya defines and operates the supported technical standard and the agreed service scope. Clinical decisions, business approvals and data authority stay with your organization.

See custody, erasure and examination detail →