Security & Compliance Policy

Introduction

MedixGate critical resources, such as databases, patient information, client data, and private employee information are areas that must be protected from intrusion and inappropriate use or disclosure. Systems themselves must be set up and routinely updated so they prevent intrusion and other malicious activities.

The purpose of these policies is to ensure that all individuals utilizing MedixGate's resources understand their responsibility for reducing the risk of compromise and for taking appropriate security measures to protect them. Everyone at MedixGate has a responsibility to assist with the implementation and enforcement of these policies.

MedixGate will take appropriate action for any failure to comply with these policies, and for any failure to take corrective action when notified of a violation of these policies.

Internal Controls Policy

1.1 Purpose

The purpose of this policy is to ensure that any action taken by the Board of Directors, executives, senior management, and other parties, support the achievement of company goals and objectives; ensure adherence to company rules and policies; promote operational efficiency and effectiveness; minimize risks and protect assets; ensure the accuracy, reliability, and integrity of company information and records; promote economical and efficient use of financial and other resources; and ensure compliance with all applicable contract requirements, regulations, and laws.

1.2 Scope

The Internal Control Policy is relevant to all company employees, temporary employees, contractors, consultants, vendors, service providers, partners, affiliates, Third Parties, or any other person or entity operating on behalf of MedixGate. Internal control roles vary depending on the employee/vendor role and level of responsibility.

1.3 Internal Control Structure

MedixGate internal control structure consists of five components: (1) control environment, (2) risk assessment, (3) control activities, (4) information and communication, and (5) monitoring.

1.3.1 Control Environment

MedixGate's internal control environment is established by the company's Board of Directors and Executive Team and supported by departmental directors, program managers, and supervisors. The Board and Executive Team is responsible for establishing policies that promote ethics, integrity, and competence, and shape company practices and employee behavior.

Department directors, managers, and supervisors are responsible for establishing and maintaining internal controls within their departments by executing control policies and procedures established by Senior Management.

The aim is to create an environment and culture where the attitude and actions of all employees and Third-Party Vendors are consistent with the company's philosophy and operational approaches.

1.3.2 Risk Assessment

Risk assessment activities are conducted to identify the range of potential threats and vulnerabilities the company faces; their likelihood of such threats and risks occurring; the impact of such risks and threats to the company; and controls and actions needed to mitigate, manage, and respond to such risks.

1.3.3 Control Activities

MedixGate's internal control activities consist of policies, procedures, and processes that help ensure company objectives are carried out, prevent, or reduce risks and threats from occurring, detect errors and acts of non-compliance, and correct errors that have been detected. Control activities fall within the following categories:

Policies.

Policies are implemented to establish allowed and unallowed activities and behaviors.

Procedures, Processes, and Workflows.

Processes and workflows are developed to direct and control how certain operations and activities are to be carried out.

Authorization

All transactions and activities carried out by employees, vendors, and agents operating on behalf of MedixGate must be properly authorized. Company job descriptions as well as Third-Party contracts/service level agreements are provided to authorize individuals to perform certain activities and to execute certain transactions within limited parameters. In addition, policies are put in place to specify those activities or transactions that need supervisory approval before they are performed or executed. Persons authorizing any transaction or activity must have the delegated authority to issue such an authorization, and such authorization must be aligned with company policies and practices.

Segregation of Duties

Duties are segregated among different people to reduce the risk of error or inappropriate action.

Performance Reviews.

Various levels of reviews are conducted to ensure that all transactions are activities consistent with company policies and practices.

Reconciliation.

Transactions and records are cross-checked to ensure that the information reported is accurate.

Restricted Access to Company Assets and Resources.

Access to physical resources, liquid assets, vital documents, critical systems, and confidential information, are restricted and safeguarded against unauthorized acquisition, use, or disposition.

1.3.4 Information and Communication

MedixGate policies and procedures are designed to ensure that accurate, reliable, relevant, and quality information is identified, captured, and communicated in a manner that results in the achievement of internal control objectives.

All new policies and procedures and/or updates and revisions, are communicated to employees and Third-Party Vendors where applicable, in a timely manner.

1.3.5 Monitoring

Internal control systems and processes are periodically reviewed by Internal Control Managers, Senior Management, and the Compliance Oversight Committee of the Board of Directors. The monitoring process is designed to ensure that internal control activities are carried out properly and in a timely manner sufficient to ensure the effectiveness of the internal controls. Monitoring will include spot checks of transactions or basic sampling techniques to gain a reasonable level of confidence that all internal controls are functioning as intended.

1.4 Internal Control Management

Managing MedixGate's internal control system is the responsibility of the Board of Directors, the Executive Team, Senior Management, and designated Internal Control Managers.

1.4.1 Board of Directors and Executive Team

The Board of Directors and Executive Team is responsible for establishing adequate policies and procedures to ensure effective internal controls.

1.4.2 Senior Management

Department heads and managers are responsible for communicating company policies and procedures to the staff and vendors, and monitoring compliance with those policies and practices.

1.4.3 Internal Control Managers

Internal Control Managers are responsible for ensuring that transactions and activities under their watch comply with company policies and procedures, contractual requirements, and relevant laws and regulations.

1.5 Internal Control Training

All employees, volunteers, interns, and third-party vendors involved in MedixGate business affairs must receive training on the internal control policies and procedures of MedixGate, within 30 days of hire/contracting, and annually thereafter.

1.6 Internal Control Adherence

All employees, volunteers, interns, and Third-Party Vendors involved in MedixGate business affairs must be provided with a copy of this policy and provide a signed attestation that they have reviewed this policy, understand this policy, and will be compliant with the policy.

Failure to follow this policy can result in disciplinary action as provided in the Employee Handbook, Third Party contracts, and vendor agreements. Disciplinary action for not following this policy may include employment termination, dismissal for interns and volunteers, or termination of contracts or vendor agreements. Additionally, individuals may be subject to civil and criminal prosecution.

1.7 Internal Controls Violations

Any violation of an internal control policy or procedure must be promptly reported to the IT Department at support@MedixGate.com.

1.8 Questions About This Policy

If you have questions about this policy, please contact the IT Department at support@medixgate.com.

1.9 Internal Controls Review

All internal control policies and procedures must be reviewed semi-annually by Senior Management and needed changes must be recommended to the Executive Team.

Scroll to Top