Research Hive Policies and Procedures
100 - Table of Contents
Revised 9.1.17 Research Hive Policies and Procedures Table of Contents
101 - Database Credential Coding Policy
Revised 1.5.17
This policy states the requirements for securely storing and retrieving database usernames and passwords (i.e., database credentials) for use by a program that will access a database running on one of Research Hive's networks.
Software applications running on Research Hive's networks may require access to one of the many internal database servers. In order to access these databases, a program must authenticate to the database by presenting acceptable credentials. If the credentials are improperly stored, the credentials may be compromised leading to a compromise of the database.
102 - Employee Sanctions Policy
Revised 1.5.17
The purpose of this policy is to address non-compliance with the HIPAA policy requirements governing the confidentiality of electronic protected health information (ePHI).
103 - Telephone Call Policy
Revised 5.4.17
Research Hive, LLC is committed to conducting business in compliance with the Telephone Consumer Protection Act (TCPA) and all applicable laws, regulations and organization policies. The organization has adopted this policy to outline the requirements for making telephone calls to potential and current customers.
104 - Email Transmission Security Policy
Revised 5.4.17
The scope of this policy covers the technical security measures that the organization will implement to guard against unauthorized access to or modification of ePHI that is being transmitted over an electronic communications network or via any form of removable media.
105 - Mobile Device Security Policy
Revised 1.2.17
Research Hive has a requirement to protect its information assets in order to safeguard its customers, intellectual property and reputation. This document outlines a set of practices and requirements for the safe use of mobile devices.
106 - Incident Response Policy
Original 1.5.16
The scope of this policy and procedure covers the response to and reporting of security incidents, including the identification of and response to suspected or known security incidents, the mitigation of the harmful effects of known security incidents, to the extent possible, and the documentation of security incidents and their outcomes.
107 - Encryption and Data Integrity Policy
Original 1.5.16
The scope of this policy is to outline the appropriate data authentication measures that the organization must implement to ensure that ePHI is not improperly altered or destroyed. Data authentication is the process used to validate data integrity, verify that the data sent is the same data that is received and ensure the integrity of data stored and retrieved.
108 - Code of Business Conduct and Ethics
Revised 1.5.17
This Code of Ethics (the “Code”) is designed to help you keep these values in sight as you conduct business on Research Hive’s behalf.
While the Code covers a broad range of activities and provides numerous examples of actions and situations that are either prohibited or acceptable, it cannot address every ethical or difficult situation that may arise.
109 - BDR Overview
Revised 1.13.20
Research Hive (RH), LLC is a lean organization with a 100% geographically dispersed, mobile workforce which currently has no reliance on any one physical facility location. Due to this, our business continuity requirements are at its core, basic, solely reliant on the ability of staff to access a reliable internet connection and maintain cell-phone coverage. All critical Research Hive organizational documents and resources are synchronized in real-time to cloud storage (powered by Office 365, SharePoint Online and OneDrive). All work laptops are backed up on a routine basis. This allows the Research Hive staff to maintain 3 copies of critical documents and resources at all times, one copy on secured, local workstations, one copy synchronized to the Microsoft cloud and one copy backed up to a hard drive that is continually rotated through staff hands.
All RH client data is managed via AWS, the details of which are available in this policy document.
110 - Pharma and CRO Access Policy
Original 3.1.17
The scope of this policy is to outline the appropriate measures in place to segregate access to Research Hive’s databases from Sponsors and their vendors (CRO’s), specifically in regards to protected health information provided by the Site.
111 - IT Use Policy
Revised 1.5.17
The use of Research Hive network information systems, including computers, fax machines, and all forms of Internet/intranet access, is for Practice business and for authorized purposes only. Brief and occasional personal use of the electronic mail system or the Internet is acceptable as long as it is not excessive or inappropriate, occurs during personal time (lunch or other breaks), and does not result in expense or harm to the Practice or otherwise violate this policy.
112 - Password Policy
Original 1.5.16
Database authentication credentials are a necessary part of authorizing application to connect to internal databases. However, incorrect use, storage and transmission of such credentials could lead to compromise of very sensitive assets and be a springboard to wider compromise within the organization.
113 - CFR Part 11 Compliance Policy and Outline
Revised 1.5.17
Final Omnibus Rule applies to all entities (covered entities and business associates) that handle, store, manage, or transmit PHI.
Title 21, Chapter I, Subchapter A, Part 11, Subpart B (CFR Part 11)
114 - HIPAA Compliance Policy and Outline
Revised 4.18.17
Final Omnibus Rule applies to all entities (covered entities and business associates) that handle, store, manage, or transmit PHI.
45 CFR §160.300, 45 CFR §164.104(b), 45 CFR § 164.302.