Forums/General Support Resources/Frequently Asked Questions

is Fuze Meeting HIPAA Compliant?

Greg Saiz
posted this on July 29, 2011 15:19

While Fuze Meeting is not specifically designed for healthcare or medical record storage, we do provide best in class security for all customer accounts.  If you are regulated by HIPAA and using Fuze Meeting to share HIPAA-regulated records, we suggest using screen share and disabling recording so no permanent records are retained.  By request, we can also configure accounts such that uploaded content is purged when a meeting is ended.  In this way, HIPAA regulated companies may comply with guidelines related to the storage of medical records.

Additionally, we ensure your account is fully secured by these features:  http://www.fuzemeeting.com/web-conferencing/secure-online-meetings

TECHNOLOGY SECURITY

Our customers trust Fuze Meeting to present confidential documents and assets. We earned that trust with technology to keep meeting information and content secure and confidential. The FuzeBox platform provides:

  • SSL Session Encryption for all web and mobile clients - All Fuze Meeting sessions utilize SSL to ensure encryption between participants and the Fuze Meeting service.
  • SAS70 Type II Audited Data Storage - Your information is secure in the FuzeBox Cloud. Don't take our word for it, our storage service provider successfully completed a Statement on Auditing Standards No. 70 (SAS70) Type II Audit, and has obtained a favorable unbiased opinion from its independent auditors. Please contact us if you'd like more information.
  • Password Protection - Customer passwords are not stored in our database. Instead we keep the product of a cryptographic hash function that makes extracting your password practically impossible.
  • Fuzebox components use signed code and a third-party certificate provided by VeriSign.

APPLICATION SECURITY

If you've built Fort Knox security but leave the front door open, what's the point? Surprisingly, some of the legacy names in online collaboration have done just that with meetings published on web pages, no explicit attendee accept dialogs, etc. We've taken a different approach. Think of these features as the "armed guard" at the entrance of every Fuze Meeting.

  • Unique, random, unpublished URLs for each meeting instance - Persistent meeting rooms are an invitation to hackers. Each new Fuze Meeting gets a randomly generated URL string to thwart brute force hacking.
  • Host must explicitly accept/reject each attendee - You wouldn't let a stranger walk in to your office without a knock at the door right? Fuze Meeting makes every attendee "knock" and they don't get in unless the host lets them in. Want even more security? Give your attendees a "phrase of the day" and require it in their name when they join.
  • Visual confirmation of phone participants - Fuze Meeting displays Caller ID, Skype ID or the VOIP ID of every meeting participant so you know who is listening at all times. Want even more protection? Read on.
  • Secure phone conferences via Fuze In - If visual confirmation isn't enough, you can use our Fuze In feature to explicitly dial your participants in to a meeting.
  • Audio Room Lock Feature - Want to make sure nobody else joins the audio portion of your meeting? After everyone connects, you can lock the room to prevent unauthorized access.
  • Meeting Replay and Content Link are password secured - Our commitment to security doesn't end with your meeting. Fuze Meeting Replays (recordings) are password protected by default.
  • Permission based experience - host, presenter, attendee - All actions are permitted only to the Host of the meeting. Host can promote Attendee to a Presenter, which gives the Attendee the ability to lead portions of the meeting until Host revokes their permissions.