Page Properties | ||||||||
---|---|---|---|---|---|---|---|---|
| ||||||||
|
Patients Know Best is NHS Data Security and Protection Toolkit (DSPT) and Cyber Essentials Plus certified, ISO27001 compliant and follows the strict information handling requirements of these standards.
...
Expand | ||
---|---|---|
| ||
Patient Knows Best’s patch management process Patients Knows Best pushes security updates fast and consistentlywithin patch remediation objectives. Upon finding an issue in the production environment PKB evaluate to determine the impact. If an issue highlights a significant disruption to functionality or performance of the system or is considered a potential clinical/IG risk then a patch/release is scheduled as soon as a fix is ready. For critical issues downtime may occur during the day otherwise the fix will be scheduled in the evening when usage is lower. |
Expand | ||
---|---|---|
| ||
Patients Know Best’s approach includes peer review, automated testing, and static code analysis prior to deployment into production. Responsive software development means new features, resiliency improvements , and bug fixes arrive bi-weekly (or more frequently in the case of critical patching), and seamlessly. Patients Know Best practices Agile software development, with a general lifecycle enforced by CI/CD controls. Customer data is never used as part of development lifecycle and testing. |
...
Expand | ||
---|---|---|
| ||
The Patients Know Best platform is is deployed as a multi-tenant, Software as a Service architecture is run on fault-tolerant servers at Google Cloud Platform (GCP). In addition to managed services for Patient Knows Patients Know Best infrastructure, GCP provides physical security and environmental protection controls, including the use of secure perimeter defence systems, comprehensive camera coverage, biometric authentication, and a 24/7 guard staff. In addition, they enforce a strict access and security policy at data centres, ensuring all staff are trained to be security minded. For more information see here |
Expand | ||
---|---|---|
| ||
Patient Knows Patients Know Best's Business Continuity and Disaster Recovery (BCDR) strategy is a proactive and comprehensive plan designed to ensure uninterrupted operations and data protectionresilience. Data security availability is a top priority, with encryption and access controls in placePKB architecture ensures data resilience and we maintain maintain full redundancy for critical services. Regular testing and validation are performed and , reviewed and approved annually. |