信息 关于 our compliance standards, certifications, controls, and 数据 protection practices
Elderwise is committed to achieving and maintaining compliance with key industry certifications. Our strategic roadmap outlines our journey toward full certification, with timelines tailored to the complexity and requirements of each standard.
Elderwise follows a structured approach to compliance certifications with timelines tailored to each standard's complexity. We prioritize certifications based on market requirements and technical complexity, with our most comprehensive certifications (HITRUST) targeted for Q3 2026, while more focused certifications like ISO 27001 are targeted for completion by Q1 2026.
Creation of policies, procedures, and controls documentation
Assessment of current practices against certification requirements
Deploying necessary controls and remediation activities
Verification of control effectiveness before external assessment
Official certification audit by accredited third parties
Receipt of formal certification and continuous monitoring
While formal certifications are in progress, Elderwise has already implemented key security and privacy controls aligned with healthcare standards. Our approach follows industry-standard continuous compliance methodology, emphasizing automated evidence collection, regular assessments, and security by design.
We provide interim compliance documentation to customers, including security questionnaire responses, SOC 2 readiness assessments, and draft BAAs/DPAs while formal certification is underway.
Following compliance best practices, Elderwise employs continuous monitoring tools to automatically detect and remediate compliance drift, ensuring our systems maintain compliance between formal assessment periods.
规范 PHI 隐私与安全的美国医疗法案。
规范美国医疗机构与业务伙伴对受保护健康信息 (PHI) 的隐私与安全处理。
与处理方签署 BAA,落实 RBAC/MFA/SSO,集中式审计日志,最小权限原则,AES‑256/TLS 1.3 加密,事件响应手册与周期性 HIPAA 培训。
规定合法处理与数据主体权利的欧盟数据保护法规。
EU/EEA 区域的数据保护框架,涵盖合法处理与数据主体权利。
同意采集与审计跟踪、与供应商签署 DPA、隐私内建评审、DSR 流程、必要时进行跨境传输影响评估。
强调同意与目的限制的新加坡数据保护法。
关于同意、目的限制、通知、访问/更正等义务的本地法律。
本地化同意声明、保留策略、访问/更正渠道,并依据 PDPC 指南执行泄露通报程序。
用于信息安全风险管理的国际 ISMS 标准。
关于建立、实施、维护与持续改进 ISMS 的国际标准。
界定 ISMS 范围,建立风险台账与策略/控制映射,开展内部审计并做好认证准备。
对安全控制在一段时间内有效性的鉴证。
基于 AICPA 信任服务准则,对控制有效性进行周期性鉴证。
与 TSC 对标控制,自动化收集证据,持续监控,按季度测试控制并做好外部审计准备。
面向医疗的综合性可认证安全框架。
面向医疗的可认证框架,融合 HIPAA、ISO、NIST 等要求。
定义 PHI 系统范围,适用时继承控制,分阶段推进以获得验证性评估。
新加坡 HSA 的医疗科技/软件监管指引。
针对医疗软件与健康科技解决方案的监管指引。
遵循 HSA 意见,对预期用途与风险控制进行文档化;参考 ISO 14971/IEC 62304。
针对 HIPAA 的泄露通报与执法强化规定。
针对 HIPAA 的泄露通报与执法强化。
事件响应手册、证据保全,以及关于重大性与通报时机的决策树。
现代化的结构化临床数据交换标准。
现代临床数据交换标准。
核心实体采用 FHIR 优先建模,版本化配置文件,OAuth2/OIDC 授权。
医院与实验室广泛使用的医疗消息标准。
在医院与检验机构广泛使用的医疗消息标准。
按需提供 HL7 v2.x 适配、内部模型标准化与安全传输。
医疗器械质量管理体系 (QMS) 标准。
面向医疗器械全生命周期的质量管理标准。
在相关软件模块逐步引入 QMS;如适用,配合器械分级及监管路径。
面向负责任 AI 治理的 AI 管理体系标准。
覆盖 AI 全生命周期的责任治理框架。
将既有控制映射至 AI 风险,建立透明度文档与指标,完善模型治理流程。
Elderwise is committed to maintaining the highest standards of data protection and regulatory compliance in healthcare technology, with a progressive certification roadmap for completion between Q3 2025 and Q4 2026.
Data Protection Officer:dpo@elderwise.ai
EU Representative (Art. 27 GDPR):eu-rep@elderwise.ai
APAC Representative:apac-rep@elderwise.ai
Security Team:security@elderwise.ai
Vulnerability Reporting:security-alerts@elderwise.ai
Elderwise's phased certification timeline:
Elderwise Healthcare Compliance Commitment:
Our compliance strategy follows Vanta's recommended "security by design" principles, embedding healthcare compliance requirements into our development process from inception to deployment. We recognize that healthcare data security directly impacts patient outcomes and provider efficiency, so our approach integrates technical safeguards with clinical workflow considerations to create a secure environment that enhances rather than impedes care delivery. Our compliance program emphasizes both regulatory adherence and the ethical responsibility we have to protect sensitive health information.