EHR Downtime Solution / Security
Security and architecture review for hospital downtime continuity.
This trust-centre overview gives hospital security, privacy and procurement teams a practical path to assess a CodeDark deployment. It is a starting point for a customer-specific security review—not a certification claim or substitute for due diligence.
Security review areas
Access management
Review authentication, role-based permissions, least-privilege roles and access lifecycle procedures for the proposed deployment.
Device authorisation
Define which devices are permitted, who administers them, and the physical and technical controls required by hospital policy.
Data protection
Review encryption at rest and in transit, data storage locations, key-management responsibilities and secure configuration expectations.
Auditability
Review audit logging, monitoring, access review and evidence-retention requirements with the implementation team.
Resilience
Discuss backup, recovery, local operating requirements and the procedures for restoration following a downtime event.
Incident response
Align escalation contacts, notification expectations, customer responsibilities and incident-response procedures before go-live.
Information for vendor review
Security teams can request architecture information, a deployment discussion, a completed security questionnaire where available, Business Associate Agreement availability, data retention requirements and a current subprocessor discussion. Penetration testing, SOC 2 status and other assurance materials should be described only from current, documented evidence.
Data-flow discussion
During discovery, the parties should document the approved data flows: authorised user and device access; locally available workflow data; any permitted device-to-device communication; storage and retention controls; restoration; and the customer-approved reconciliation process. This shared design record makes a downtime deployment easier to assess and govern.
Report a security concern
For a security questionnaire, vulnerability disclosure or security concern, contact globalsales@codedarkhealth.com and include a secure reply contact. Do not include sensitive patient information in an initial email.