Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titlePatch management

Patient Knows Best’s patch management process Patients Knows Best pushes security updates fast and consistentlywithin patch remediation objectives. Upon finding an issue in the production environment PKB evaluate to determine the impact. If an issue highlights a significant disruption to functionality or performance of the system or is considered a potential clinical/IG risk then a patch/release is scheduled as soon as a fix is ready. For critical issues downtime may occur during the day otherwise the fix will be scheduled in the evening when usage is lower.

Expand
titleSecure Development Lifecycle

Patients Know Best’s approach includes peer review, automated testing, and static code analysis prior to deployment into production.

Responsive software development means new features, resiliency improvements , and bug fixes arrive bi-weekly (or more frequently in the case of critical patching), and seamlessly.

Patients Know Best practices Agile software development, with a general lifecycle enforced by CI/CD controls. Customer data is never used as part of development lifecycle and testing.

...

Expand
titleBusiness continuity and disaster recovery

Patient Knows Patients Know Best's Business Continuity and Disaster Recovery (BCDR) strategy is a proactive and comprehensive plan designed to ensure uninterrupted operations and data protection. Data security is a top priority, with encryption and access controls in place. Regular testing and validation are performed and reviewed and approved annually.