Transcarent Data Security Terms and Conditions

These Transcarent Data Security Terms and Conditions (generally referred to as the “Security Requirements”) is incorporated into and subject to the Agreement by reference. Capitalized terms used herein, but not defined, have the meaning set forth in the Agreement.

  1. Introduction. Transcarent will maintain an information security program designed to protect the confidentiality, availability, and integrity of Customer’s data while performing the Services.

  2. Security Reviews. Customer may conduct a remote documentary review of Transcarent’s security controls no more than once per year. Transcarent may satisfy a security review by providing an independent, industry standard report, such as a SOC 2 report, and other documentation reasonably necessary to support the review. Transcarent will maintain security controls materially consistent with its then-current security documentation and these Security Requirements. If a security review identifies exceptions or deficiencies, the Parties will agree on a reasonable remediation plan consistent with Transcarent’s vulnerability management policies.

  3. Specific Security Requirements.

    1. Security Policy. Transcarent shall maintain written security policies and procedures addressing information security governance, Confidential Information handling, acceptable use, incident management, authentication, access controls, logging and monitoring, and personnel compliance.

    2. Audits, Review, and Monitoring of Transcarent’s Information Security Program. Transcarent shall retain an independent third party to audit its information security policies, practices, and controls at least once every 12 months. The audit must be a SOC2 audit, or other audit comparable to the designated SOC standard. Transcarent may provide the report to Customer as part of an annual Security Review, or otherwise upon reasonable request

    3. Asset and Information Management. Transcarent shall maintain reasonable inventories of Confidential Information, physical computing assets, and software assets used to perform the Services, and shall follow these Security Requirements when storing, accessing, handling, and processing Confidential Information.

    4. Physical and Environmental Security. Transcarent shall maintain reasonable physical and environmental safeguards for facilities under its control where Confidential Information is received, stored, accessed, handled, or processed, including controls for authorized access, visitor management, monitoring, infrastructure protection, and server security appropriate to the sensitivity of the Confidential Information.

    5. Personnel-related Matters. Transcarent shall maintain personnel security measures for Personnel with access to Confidential Information, including background checks where permitted by Applicable Law, security training, procedures for granting and revoking access, and a code of conduct or ethics policy.

    6. Communications, Encryption and Operations.

      1. Transcarent shall perform regular backups sufficient to restore Services within agreed service levels or, if no service levels apply, within a commercially reasonable time.

      2. Transcarent shall encrypt Confidential Information at rest and in transit over public networks using industry standard encryption processes appropriate to the sensitivity of the Confidential Information, including full-disk encryption for desktops and laptops on which Confidential Information is stored or processed.

      3. Transcarent may only transmit, transfer, or provide Confidential Information to those third parties, including its subcontractors, partners, other business associates of Customer, or others who may have a need to know the information, in order for Transcarent to provide the Services under the Agreement and as may be permitted by applicable law.

      4. When erasing or destroying Confidential Information, Transcarent shall employ data destruction procedures that meet or exceed the National Institute of Standards and Technology ("NIST") Special Publication 800-88 Guidelines for Media Sanitization.

      5. Transcarent shall maintain commercially reasonable malware detection and prevention on systems that receive, store, access, transmit, or process Confidential Information.

      6. Transcarent shall maintain commercially reasonable perimeter and infrastructure security controls, including firewalls, anti-malware, intrusion prevention or detection, and other appropriate protection technologies.

      7. Transcarent shall maintain regular patch management and system maintenance for systems that receive, store, access, transmit, or process Confidential Information.

      8. For production environments that use virtualized infrastructure to receive, store, access, transmit, or process Confidential Information, Transcarent shall maintain commercially reasonable virtualization security controls, including hardening, monitoring, secure management protocols, secure handling of virtual images and snapshots, and guest OS isolation.

  4. Access and Authentication.

    1. Transcarent shall authorize personnel access to Confidential Information based on job requirements and need to know, review personnel access rights quarterly, and maintain reasonable controls to prevent unauthorized access to Confidential Information.

    2. To the extent available, supported by the Services and Customer’s configuration, and requested by Customer, Transcarent shall support industry standard Single Sign-on (“SSO”). If Customer elects to use or require its own SSO, Customer is responsible for user provisioning, de-provisioning, authentication, and identity management within Customer’s identity provider.

    3. If SSO is not used, Transcarent will use Access Credentials and manage password usage, creation, storage, and protection in accordance with industry standards.

  5. Application Development and Testing.

    1. Transcarent shall maintain secure development practices, including security within the systems development life-cycle, secure coding standards, and automated secure code reviews for externally-facing Services and Transcarent-developed software used as part of the Services.

    2. Transcarent shall maintain a vulnerability management program and conduct vulnerability scans at least every 30 days for Services that receive, store, access, transmit, or process Confidential Information.

    3. Transcarent shall retain a reputable independent third party to conduct penetration tests at least annually for externally-facing Services that receive, store, access, transmit, or process Confidential Information.

    4. Upon Customer’s reasonable request, Transcarent shall confirm in writing that it has performed the required vulnerability scans and penetration tests. Transcarent shall promptly correct material adverse findings in accordance with its vulnerability management policies.

  6. Third Party Access.

    1. Before a third party may access Confidential Information, Transcarent shall take reasonable steps to confirm that the third party maintains appropriate security measures and is bound by written obligations designed to protect Confidential Information in accordance with Applicable Law and this Exhibit. Transcarent shall maintain a third-party risk management program that includes periodic security review of such third parties.

    2. Transcarent shall be responsible and directly liable to Customer for third-party acts and omissions, including any failure by a third party to comply with these Security Requirements or any act or omission causing Transcarent to be out of compliance with the Agreement, including these Security Requirements.

    3. Transcarent shall maintain a reasonable inventory of personnel and subcontractors authorized to access Confidential Information, including the purpose, access method, protection method, and categories of Confidential Information made available.

  7. Information Security Incident Management.

    1. Transcarent shall establish, test, and maintain a written information security incident response plan that includes processes for evidence preservation, regulatory or law enforcement coordination as appropriate, and forensic analysis.

    2. For purposes of these Security Requirements, “Security Incident” means confirmed unauthorized access to, acquisition, disclosure, alteration, destruction, or loss of Confidential Information affecting Transcarent, its third parties, or the Services. Transcarent shall notify Customer of a Security Incident promptly, but no later than five (5) business days after Transcarent confirms that a Security Incident occurred, which may follow an internal investigation. Following closure of the Security Incident, Transcarent shall provide a report to Customer describing the Security Incident, root cause if known, corrective actions taken, and planned measures to reduce recurrence.

    3. Transcarent shall provide Security Incident notices by email to Customer’s primary contact or other designated contact provided to Transcarent in writing.

  8. Business Continuity Plan.

    1. Transcarent shall maintain a Business Continuity Plan (“BCP”) designed to mitigate events that could materially impact the Services.

    2. The BCP must include documented recovery plans and contingency strategies designed to support delivery of the Services in accordance with the Agreement during business, personnel, data transmission, communication, system, weather, public health, political, or operational disruptions.

    3. The BCP must include appropriate alternative resources, which may include alternative business locations, redundant resources, off-site backups, network diversity, alternative communications or systems, alternative vendors or service providers, or other reasonable alternatives.

    4. Transcarent shall promptly notify Customer when Transcarent invokes its BCP due to an event that could materially adversely impact the Services.

    5. Transcarent shall continue to provide the Services to the extent reasonably possible if Customer activates its own BCP or moves to an interim site, including during contingency operations plan tests.