When Zephyr Health needed help keeping sensitive Patient Health Information secure, they turned to Bishop Fox.
As an analytics start-up serving the healthcare industry, Zephyr Health needed a solid data security plan and program that they could demonstrate to their clients to better develop and maintain their customers’ trust.
Zephyr Health approached us to do a policy review and gap analysis against security certifications. Through our consultation process, we determined that the issue was customer-driven.
Specifically, Zephyr Health’s customers were asking them what they were doing for security, both at a macro (ISO 27001 compliance) and a micro (user authentication) level. We realized they needed to become compliant with a new security standard in order to better develop and maintain their customers’ trust.
Our analysis showed that the appropriate security framework for Zephyr Health would be the Service Organization Controls (SOC2), with emphasis on Security and Confidentiality Trust Principles due to several factors, including:
Zephyr Health’s concerns were unique, due to the industries they served. They wanted to not only implement a framework of security management and controls, but also provide peace of mind.
Bishop Fox worked in partnership with Zephyr Health, providing expertise in customizing the new policy, process, and technical controls to appropriately mitigate the risks to customers. We also implemented new procedures and a proof of control process to protect Zephyr Health and their clients. And, due to the strong relationship between our teams, the transition process moved very quickly.
"Zephyr Health passed their SOC2 certification within six months from starts to finish, and with no quality findings by external auditors."
--Rob Ragan, Partner, Bishop Fox
Both teams focused in customizing the new policy, process, and technical controls to appropriately mitigate the risks to customers. They also implemented new procedures and a proof of control process to protect Zephyr Health and their clients' data. And, due to the strong collaboration between our companies, the transition process moved very quickly.
"We continue to enjoy the benefits of the SOC2 implementation; thank you again for your help."
--William King, CEO at Zephyr Health
Customers have reported they feel confident Zephyr Health takes their role as a data custodian seriously, and can have more strategic conversations about solving their customers’ business challenges without security being a cause for concern.
Zephyr Health helps Life Sciences companies organize and visualize health care data to better connect therapies to patients in need. As an analytics start-up serving the healthcare industry, Zephyr Health needed a solid data security plan and program that they could demonstrate to their clients.
Like many new businesses, they wanted to focus on company security in a more methodical way. And, as a small, but growing company, Zephyr Health needed the ability to accurately answer customer inquiries about their security practices.
The Right Dose: A Health Tech Provider Puts It's Systems to the Test
A healthcare technology company moving to SaaS needed to validate its multi-tenant cloud platform, secure connected device provisioning, and maintain visibility across a growing attack surface. Bishop Fox delivered an architecture assessment and continuous testing program to help them build with confidence.
Securing Smart Home Technology in Decentralized Global Enterprise
How do you secure millions of connected homes with limited security resources? Explore how a global smart residential technology provider partnered with Bishop Fox to continuously identify real threats, eliminate critical vulnerabilities, and strengthen security across applications, networks, and cloud environments.
No Blind Spots, No Clicks: Laurel Validates Its Attack Surface and Human Defenses
Learn how Laurel, an AI-powered work intelligence platform, partnered with Bishop Fox to validate its security defenses through continuous attack surface monitoring and a sophisticated social engineering assessment—achieving zero clicks across 48 targeted employees and a single low-severity finding over nine months.