• Sign Up, It's Free
  • Get Our Newsletter Plans & Pricing
    Generic selectors
    Exact matches only
    Search in title
    Search in content
    Post Type Selectors
  • Categories
    • Hybrid Work
    • Video Conferencing
    • Cloud Calling
    • Collaboration Devices
    • Innovation
    • Customer Experience
    • Event Management
  • Hybrid Work
  • Video Conferencing
  • Cloud Calling
  • Collaboration Devices
  • Innovation
  • Customer Experience
  • Event Management
 
  • Blog home
  • >
  • Video Conferencing
  • >
  • Protecting Your Webex Healthcare Data
Collaboration, Video Conferencing

Protecting Your Webex Healthcare Data

Mar 30, 2020 — Raisa Trifanov

Compliant World-Class Collaboration

As the healthcare industry moves towards a new era of patient and employee engagement, more people are experiencing innovative ways to connect with their healthcare providers. Whether its remote video consults with doctors, messaging your provider for quick questions, or checking in on loved ones from a distance, everyone wants to know, is my data secure? At Cisco Webex, we take our customers’ data security seriously and we are dedicated to providing world-class collaboration that is simple, scalable, and designed to meet your HIPAA compliance needs. Healthcare Data

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. healthcare law that establishes requirements for the use, disclosure, and safeguarding of individually identifiable health information. It applies to doctors’ offices, hospitals, health insurers, and other healthcare companies with access to patients’ protected health information (PHI).

How Do Cisco’s Webex Services Enable HIPAA Compliance?

Cisco has conducted a HIPAA self-assessment on Cisco Webex services (Teams, Meetings, Control Hub, and Webex for Developers). This self-assessment is based on a shared responsibility model where the Cisco Webex services platform is responsible for maintaining customer data including Confidentiality, Privacy, and Security. In line with the HIPAA Security Rule, Cisco implements all the addressable specifications that are relevant to Cisco Webex services. These are segmented into three safeguards – Administrative, Physical, and Technical.

Cisco HIPAA Compliance and Data Privacy Protecting Your Healthcare Data| Doctor explaining symptoms on a Webex while other nurse receives information on iPad

1. Administrative

The administrative safeguard covers standards that relate to the administration for the Webex platform by Cisco such as, but not limited to, security management processes, assigning security responsibilities, ensuring workforce security, incident reporting procedures, periodic evaluations, and more. The Cisco Webex cloud security team has established formal policies, standards, and procedures relevant to the design and operations of controls over Cisco Webex services. These policies and procedures prevent unauthorized access to Webex data, ensure reporting and management of potential security issues, and protect your PHI through a contingency plan for disasters and the like.

2. Physical 

The physical safeguard covers physical access (limited and authorized) to electronic information systems. To meet this standard, Cisco Webex services use Cisco owned data centers, co-location data centers, or Cloud Service Providers (CSP). Each data center is certified (ISO/IEC 27001:2013 certification) to ensure the location has a facility security plan, access control and validation, maintenance records, protections from power failures, and other utility disruptions. Cisco also has a Business Associate Agreement (BAA) with each CSP. Being a global platform, Cisco Webex services are hosted throughout multiple locations, ensuring the loss of a single location will not cause data or functionality loss.

3. Technical 

The technical safeguard covers the utilization of Webex services and address standards such as access and audit controls, integrity, authentication, and transmission security. Cisco distinguishes a user’s identity between their “real identity” and their “obfuscated identity”. For each user, Cisco Webex services generate a random 128-bit universally unique identifier (UUID), which is the user’s obfuscated identity. Similarly, for enterprises, Cisco Webex services utilize a random 128-bit “organization ID” as the obfuscated identity of each enterprise. These obfuscations are then used everywhere possible such as in message routing and cloud internal inquires.

Additionally, the PHI that is transmitted when using Webex services is encrypted from client devices to the Cisco Webex services cloud using Transport Layer Security (TLS), and all media in Cisco Webex services, such as voice, video, and desktop share, is transmitted using Secure Real-Time Transport Protocol (SRTP). Not only is content encrypted, but the end-to-end encryption services also helps to prevent data from being altered or destroyed in transit or at rest in an unauthorized manner. There are additional policies in place that enable user and enterprise privacy choices such as single-sign-on, directory synchronization, device permissions, proximity features, and more. For a detailed review of Cisco Webex services’ safeguard standards, please review the Cisco HIPAA compliance white paper. For access to the Cisco HIPAA self-assessment, reach out to your local account team.

Conclusion

Everyone has the right to data privacy. Whether you are a patient, doctor, medical staff, or insurer, the protection of personal data is critical.  By enabling policies and guidelines that adhere to security, privacy, confidentiality, availability, and integrity we can enable users to safely experience a new world of healthcare, on an unprecedented scale. Users of Webex services can feel secure knowing their messaging, voice, and video data are protected.

Need a BAA?

Click here to initiate a BAA.

New to Cisco?

Cisco Products and Solutions can be ordered directly or through our global network of certified partners. Locate a Cisco Certified Partner using our Partner Locator. Contact Us at 1-800-553-6387 Products and Services menu Option 1-2

For more information on how Cisco secures customer data across technologies,
visit the Cisco Trust Center.
Welcome to a new world of collaboration possibilities.


Learn More

  • Webex customers have more control of their privacy and security
  • 4 reasons the Webex Platform leads collaboration security
  • Healthcare Moments that Matter
  • Improving healthcare by accelerating digital transformation

Webex by Cisco achieves Thailand ETDA certification
Mar 24, 2023 — Rahul Dubey

Improve Incident Response with a Collaboration Platform You Can Trust
Mar 23, 2023 — Niraj Gopal

New ways to get work done with Webex for iPad
Mar 22, 2023 — Jeetu Patel

Experience Webex innovations at Enterprise Connect 2023 
Mar 21, 2023 — Geoffrey Huang

Technology milestones: The story of five key technologies and their impacts on 2023—and beyond.
Mar 16, 2023 — Tanuj Goyal

Connect With Us
  • This newsletter is for you.

    Our monthly newsletter, The Collaboratory, features fresh insights from collaboration experts, plus tips & trends, new product announcements, and the latest on the biggest events of the year. Sign up to stay in the loop!

Webex logo
Get started for free.
Additional features, storage, and support start at just one low price.
Sign Up, It's Free See Plans & Pricing
Small Business
  • Pricing
  • Webex App
  • Meetings
  • Calling
  • Messaging
  • Screen Sharing
Enterprise
  • Webex Suite
  • Calling
  • Meetings
  • Messaging
  • Slido
  • Webinars
  • Events
  • Contact Center
  • Experience Management
  • imimobile
  • Security
  • Control Hub
Devices
  • Headsets
  • Cameras
  • Desk Series
  • Room Series
  • Board Series
  • Phone Series
  • Accessories
Solutions For
  • Education
  • Healthcare
  • Government
  • Finance
  • Sports & Entertainment
  • Frontline
  • Nonprofits
  • Startups
  • Hybrid Work
  • Integrations
  • Developers
Resources
  • Downloads
  • Help Center
  • Join a Test Meeting
  • Online Classes
  • Accessibility
  • Inclusivity
  • Live & On-Demand Webinars
  • Webex Community
  • News & Innovations
Company
  • Cisco
  • Contact Support
  • Contact Sales
  • Webex Blog
  • Webex Thought Leadership
  • Webex Merch Store
  • Careers
  • Webex Leap
© Cisco and/or its affiliates. All Rights Reserved.
  • Terms & Conditions
  • Privacy Statement
  • Cookies
  • Trademarks
  • English
    • Chinese (Simplified)
    • Chinese (Traditional)
    • French
    • German
    • Italian
    • Japanese
    • Korean
    • Portuguese (Brazil)
    • Spanish
  • English
  • 简体中文 (Chinese (Simplified))
  • 繁體中文 (Chinese (Traditional))
  • Français (French)
  • Deutsch (German)
  • Italiano (Italian)
  • 日本語 (Japanese)
  • 한국어 (Korean)
  • Português (Portuguese (Brazil))
  • Español (Spanish)