EMStool LLC — Cadence MIH Scheduling Platform

Information Security Policy Statement

Policy #: ISMS-2026-01 Effective Date: July 16, 2026 Version: 1.0 Next Review: July 16, 2027

1. Statement of Commitment

EMStool LLC is committed to protecting the confidentiality, integrity, and availability of all information it handles in the course of developing and supporting Cadence — including protected health information (PHI) that transits or is processed by the platform on behalf of client organizations. This commitment applies at every level of the company and is owned by ownership, not delegated to a single control or document.

This statement is the top-level anchor for EMStool's information security program. It does not restate the individual policies below — it establishes that they exist as one coherent program with a single owner and a single review cycle, rather than a set of disconnected documents.

2. Scope

This policy covers all systems, code, and processes involved in building, operating, and supporting Cadence, including EMStool's own infrastructure (development and demo environments) and the security expectations placed on every client deployment. EMStool is a Business Associate providing software to client organizations, who are themselves the HIPAA Covered Entities responsible for their own workforce and clinical operations — see the Workforce Training Policy (HIPAA-SEC-005) for how this distinction is applied throughout the program.

3. Objectives

4. Governance

The Security Officer (see Security Officer Designation, HIPAA-SEC-001) owns this policy and every document listed below. All policy documents are version-controlled in a private git repository with full edit history. This policy is reviewed annually, or immediately after any material change to EMStool's infrastructure, vendor relationships, or deployment model.

5. Governing Documents

The following documents together make up EMStool's information security program. Each is independently versioned; this statement ties them together as one program rather than duplicating their content.

6. Enforcement

Non-compliance with any governing document above is addressed per the Sanctions Policy. For a one-engineer team, the primary enforcement mechanism is that every policy is tested against actual practice during the Internal Audit Program's quarterly review, not left to self-attestation alone.

Security Officer Signature
Jacob Russell — Security Officer, EMStool LLC
Date Reviewed
July 16, 2026