Mar 13, 2023
6 ways Noyo is raising the bar for data security
At Noyo, we help our customers maintain the trust they’ve worked so hard to build by providing them with industry-leading data security protocols, processes, and most importantly, partnership. Here are 6 ways we keep their most sensitive data safe.
Ashley Medina
Whether you work for an insurance carrier, a benefits platform, or a brokerage, you know it takes years to build trust with partners and customers.
At Noyo, we help our customers maintain the trust they’ve worked so hard to build by providing them with industry-leading data security protocols, processes, and most importantly, a partnership.
Here are six reasons why our partners trust Noyo with their most sensitive data.
1. We’re SOC 2 Type II audited
SOC 2 Type II reports include the most comprehensive security compliance standards within the Systems and Organization Controls (SOC) framework to demonstrate how effectively and consistently a service organization handles sensitive information. These audits evaluate both the suitability of a company's security controls, in addition to confirming if they remain implemented successfully over an extended period of time.
At Noyo, we go a step further by having a respected, well-recognized third-party audit firm Linford & Company perform annual evaluations and provide feedback on our performance in three important areas.
Security: External auditors use a top-down approach to assess leadership’s effectiveness in establishing, communicating, and maintaining a compliance program, supported by information security policies and ethical standards for personnel. They look at how this permeates throughout the organization, including various technical controls around IT, engineering, and HR processes.
Confidentiality: We rely heavily on a third-party to ensure all our policies and processes effectively maintain the confidentiality of protected health information ( PHI) and personally identifiable information (PII).
Availability: Ensuring our system maintains industry standards for operational uptime is vital to serving our customers and partners. External auditors help validate our business continuity plans and disaster preparedness.
Bringing in auditors to evaluate our practices in an objective manner is a significant investment — one that many competitors don’t make. At Noyo, our product philosophy leverages these annual audits to ensure we’re always learning and investing in continuous security improvements.
2. We go beyond standard HIPAA compliance
Similar to our approach to SOC 2 Type II compliance auditing, we also go the extra mile in ensuring our business processes and security controls align with HIPAA. We engage Techumen, a third-party auditor, to perform an assessment of our ability to understand and follow the HIPAA Security Rule.
By engaging in one we ensure:
- All our core and related security controls align with the Rule.
- We execute business associate agreements (BAAs) for any suppliers that handle our customers’ data.
- Any tools that support our operations (e.g., our customer support ticketing tool) are configured to minimize data exposure.
HIPAA audits typically apply only to certain health organizations like hospitals and integrated delivery networks. At Noyo, we go one step beyond by voluntarily engaging an auditor to look specifically at the HIPAA controls that apply to us. It’s an added measure and a great way for us to get additional feedback we can leverage in our commitment to continuous improvement.
According to the 2022 HIPAA Gap Assessment conducted by Techumen, Noyo is in the top five of organizations in our class in implementing the HIPAA Security Rule.
3. We use short-lived API tokens
An API token is a form of access control that’s similar to the username-and-password combination most of us use every day for email and other applications. Noyo uses the OAuth 2.0 protocol to generate tokens that only remain valid for 10 minutes. This significantly reduces the window for potential damage if a token is compromised.
4. We apply highly granular data access protocols
The sheer amount of data being shared across multiple touchpoints within the benefits ecosystem implies a certain amount of risk. We implement layers of controls to minimize the impact of unauthorized access, allowing us to act swiftly in the event of a security incident.
Our data access protocols include:
- A unified data access model that ties all elements within our system to clear owners and users.
- A cloud infrastructure that deploys and maintains searchable logs.
- An authentication system for all Noyo employees that creates an audit trail and reduces risks.
5. We ensure data is encrypted both at rest and in transit
Noyo protects our customers’ data 24/7, ensuring security whether it’s being stored or transmitted. We use the 256-bit AES encryption algorithm for data at rest and the TLS 1.2+ encryption protocol for data in transit.
Additional Noyo encryption safeguards include:
- An internal monitoring tool for real-time alerts on encryption failures.
- Alerts for security misconfigurations and vulnerabilities.
6. We work with carriers to meet their unique needs
The greatest value Noyo provides in terms of data security comes from our commitment to partnering with carriers. Each carrier has unique needs and levels of risk they face. Once trust is established, it unlocks innovation that otherwise wouldn’t be possible.