1. Statement of Commitment
EMStool LLC is committed to protecting the confidentiality, integrity, and availability of all information it handles in the course of developing and supporting Cadence — including protected health information (PHI) that transits or is processed by the platform on behalf of client organizations. This commitment applies at every level of the company and is owned by ownership, not delegated to a single control or document.
This statement is the top-level anchor for EMStool's information security program. It does not restate the individual policies below — it establishes that they exist as one coherent program with a single owner and a single review cycle, rather than a set of disconnected documents.
2. Scope
This policy covers all systems, code, and processes involved in building, operating, and supporting Cadence, including EMStool's own infrastructure (development and demo environments) and the security expectations placed on every client deployment. EMStool is a Business Associate providing software to client organizations, who are themselves the HIPAA Covered Entities responsible for their own workforce and clinical operations — see the Workforce Training Policy (HIPAA-SEC-005) for how this distinction is applied throughout the program.
3. Objectives
- Protect PHI at rest and in transit through encryption, access control, and audit logging.
- Detect and respond to security incidents promptly, with a documented, tested response plan.
- Maintain business continuity through tested, encrypted, regularly verified backups.
- Manage third-party vendor risk through a maintained vendor security register.
- Keep every policy below current, versioned, and actually reflective of what the code and infrastructure do — not aspirational text.
4. Governance
The Security Officer (see Security Officer Designation, HIPAA-SEC-001) owns this policy and every document listed below. All policy documents are version-controlled in a private git repository with full edit history. This policy is reviewed annually, or immediately after any material change to EMStool's infrastructure, vendor relationships, or deployment model.
5. Governing Documents
The following documents together make up EMStool's information security program. Each is independently versioned; this statement ties them together as one program rather than duplicating their content.
- Security Officer Designation (HIPAA-SEC-001)
- Sanctions Policy (HIPAA-SEC-002)
- Physical Security Policy (HIPAA-SEC-003)
- Incident Response Runbook (IRP-2026-01)
- Workforce Training Policy (HIPAA-SEC-005)
- Breach Notification Procedure
- Change Management Policy (CMP-2026-01)
- Encryption Key Rotation Policy (KRP-2026-01)
- PHI Retention & Deletion Policy (HIPAA-SEC-009)
- Workforce Access Offboarding Checklist (HIPAA-SEC-010)
- Acceptable Use Policy (HIPAA-SEC-011)
- Vendor Security Register (HIPAA-SEC-012)
- Patient Records Request Procedure (HIPAA-SEC-008)
- Business Continuity & Disaster Recovery Plan (BCP-2026-01)
- Risk Analysis (ongoing asset/vendor inventory)
- Internal Audit Program (IAP-2026-01)
6. Enforcement
Non-compliance with any governing document above is addressed per the Sanctions Policy. For a one-engineer team, the primary enforcement mechanism is that every policy is tested against actual practice during the Internal Audit Program's quarterly review, not left to self-attestation alone.
Security Officer Signature
Jacob Russell — Security Officer, EMStool LLC
Date Reviewed
July 16, 2026