Security Policy

The trust of our clients is Hygeia's most precious asset. Therefore, the security of your personal, patient and financial information is one of our highest priorities. The following questions and answers describe the systems that Hygeia has developed to provide our clients one of the highest levels of security in our industry.

How secure is my information?

Hygeia has made a significant investment in leading-edge security software, systems, and procedures to offer you a safe and secure Internet environment and protect your information. While no security system is absolutely impenetrable, we are constantly reviewing, refining, and upgrading our security infrastructure as new tools or techniques become available.

We go to great lengths to protect your account from your very first interaction with Hygeia. For example, the Hygeia Secure Partner Portal requires you to enter a valid User Name and Password before permitting you access to see any personal or financial information. This site also encrypts all the information that the server and your browser exchange. If you are inactive for an extended period of time, the site will log you off and you will need to reenter your User Name and Password.

Hygeia also utilizes state of the art firewall and intrusion detection technology to prevent unauthorized access to your private information. The public Web servers are physically segregated from the servers that contain your financial and patient data (our Application Servers, which reside behind an additional firewall), and cannot be accessed directly from the Web. Access is allowed only through well-defined scripts and is firewall-controlled. Internally, client information is specially protected through industry standard, HIPAA-Compliant security mechanisms and policies.

Why are cookies important?

The Hygeia Web site uses a common technique, HTTP-header cookies, to identify one page request from another. These cookies do not contain any personal or account identifying (e.g., password) information. They merely allow the site to recognize a page request that comes from someone who has already logged on. The information is stored temporarily in memory and is available only during the course of a session. The information is removed once you log out or close down your browser. Some browsers can be configured to warn the user whenever a site sends it a cookie. If your browser provides an edit message asking you to accept or reject the use of cookies, you should accept. The site will not work without them.

What is encryption?

Encryption is used to protect messages from eavesdropping, tampering, or message forgery over the Internet. It is a mathematical process that transforms a message in order to conceal its meaning.

How does Hygeia use encryption?

It is the policy of Hygeia Corporation to encrypt the transmission of all personal, patient or financial Web-based information that is transmitted between our site and your browser. The security standard SSL (Secure Sockets Layer) is used to implement this. SSL is the leading standard for securing World Wide Web transmissions. It is also supported by the leading browsers, Netscape Navigator* 1.1 and above and Microsoft Internet Explorer* 2.0 and above.

How can I tell that SSL is in effect?

The URL (Internet address) of a secure document begins with HTTPS://. The additional "S" on the end of the familiar HTTP indicates a secure channel to the server. Every secure page on Hygeia's Web site has been secured with a digital certificate. This is shown via the "site certificate" that sits on all secure pages. To view this certificate, click on the image of the closed lock or the solid key on the bottom bar of your browser window. A small frame displaying site security information will appear. If you use Internet Explorer, click on the word 'Subject' to verify the Web site. Click on 'Issuer' to verify the site certification authority. If you use Netscape, click on the "View Certificate" button to see information on the subject and issuer.

How secure is SSL?

SSL can use keys of various sizes. The larger the key length, the greater the number of possible combinations, the more difficult the decryption challenge, and the more secure the message. While this site will provide the maximum level of encryption supported by your browser, those wishing to maximize the security of their Web activities are encouraged to obtain a browser with 128-bit SSL encryption. These browsers are available for downloading at home from either Netscape* or Microsoft* at no cost except connect time. However, by United States law, these browsers are available to U.S. and Canadian citizens or permanent residents only.

Why do I need to use a particular browser?

To maximize the privacy of your information and provide a consistent visual presentation, a relatively current and capable browser is required. The browser requirement for this site is Netscape Navigator* 4.0 and above, or Microsoft Internet Explorer* 4.0 and above. These browsers have been used to extensively test this site to ensure that the pages display and behave in a predictable manner. Other browsers may work if they have the required browser features; however, this site has not been tested or certified for other browsers. For example, the browser must support JavaScript, Cookies, and Secure Sockets Layer (SSL), an encryption standard for browsers. For enhanced security, we recommend using a browser version that uses 128-bit SSL encryption. Note: If you are an AOL user, you will also need to use one of the minimum required browsers. You may need to download one of the approved browsers to use the Hygeia site

Our public site is optimized for use with Internet Explorer 4.0 and above, but can also be viewed with Netscape Navigator 4.0 and above.

Our Partners Portal incorporates advanced XML-based technology that requires the use of Internet Explorer.

What responsibility do I need to take as a client?

Although Hygeia does everything possible to ensure security, clients have their own set of responsibilities in providing security for their accounts. User names and passwords must be kept secret. Make sure that no one is watching when you enter your user name or passwords. It is also important to remember to log out of the Hygeia Secure Partner Portal and even exit the browser when leaving the computer. Certain companies may offer to provide services to you by accessing your accounts through our site. If Hygeia does not have a relationship with the company that provides the proper protocol for access, the security of your account can be at risk. Moreover, that company's use of your user Id and password will be governed by their policies. Anytime you disclose your identifying information to third parties, you are creating greater risk of unauthorized use or access for which Hygeia cannot take responsibility.

Hygeia has a six character minimum password length. After submitting an incorrect user id and/or password three times, you will be locked out. In addition, after 55 minutes of inactivity on Hygeia secure pages, you will be logged out. To restart your session, you will need to login again. As a further precautionary measure, if you forget your password, you will have to send a signed form to Hygeia to have a new password issued to you.

If you are using broadband Internet access (cable or DSL), we recommend that you use a personal firewall since broadband Internet access is "always on" and puts your PC and any information it may contain at risk from hackers. You should also use a virus-screening program with up to date virus definitions to minimize the risk of malicious code or Trojan horses on your computer.