Skip to main content

Shared Security Responsibility with Gardiant Works

Updated over a year ago

It is critical to understand Gardiant’s shared responsibility model including which tasks and responsibilities are handled by Gardiant, and which tasks and responsibilities are handled by you.

Gardiant’s responsibilities

Your responsibilities

Accounts & Identity

  • Provide mechanisms for account management

  • Provide opt-in multi-factor authentication

  • Ensure accounts are not shared

  • Opt into multi-factor authentication as appropriate[1]

  • Deactivate accounts when people leave your organization

Data Access

  • Provide granular permissions controls

  • Notify you of any suspected or known data breach

  • Grant the least permissions needed for an individual to perform their work

  • Notify Gardiant of any suspected or known data breach

Data Integrity & Accessibility

  • Create and maintain backups of data housed by Gardiant

  • Capture and retain audit logs

  • Notify you of scheduled outages and other service changes

  • Request and review audit logs as appropriate[1]

  • Maintain proper functional operation of all workstation equipment including connectivity to the internet

Data Security

  • Encrypt all data transmitted between your network/devices and Gardiant’s systems

  • Encrypt all data stored in Gardiant’s systems

  • Adhere to all HIPAA/HITECH rules

  • Enter into a Business Associate Agreement (BAA) with you

  • Ensure your devices and network traffic are encrypted as appropriate[1]

  • Ensure antivirus and firewalls are in place and up to date

  • Train your staff how to protect their data

  • Adhere to all HIPAA/HITECH rules (including security and notices) as appropriate[1]

  • Ensure Business Associate Agreements (BAAs) are in place with all providers that handle ePHI (electronic protected health information)

Physical Security

  • Ensure the physical security of Gardiant’s hosted infrastructure

  • Maintain the physical security of Gardiant staff’s devices

  • Maintain possession of and the physical security of your staff’s devices

Microsoft 365

  • Assist in license management and allocation

  • Functional configuration to facilitate customer support channels and Gardiant-created productivity tools

  • Adhere to your customer agreement with Microsoft

  • Ensure configuration and services as appropriate[1]

[1] Appropriateness should be determined by you, according to your statutory, contractual, and other obligations.

Please see below Word or PDF versions with the same information.

For any questions or concerns, send a message to [email protected].

Did this answer your question?