Security & compliance

For more than 10 years, Apogee CX has supported regulated healthcare and insurance programs. Here is how we protect member data today, and where our certification roadmap is headed.

HIPAA program

Business Associate Agreement, designated Privacy and Security Officer, documented risk assessments, and a breach notification plan in place, backed by 100% HIPAA-compliant infrastructure and agent training.

HITRUST

HITRUST e1/i1 assessment on our near-term roadmap, followed by r2 certification.

SOC 2 Type II

SOC 2 readiness assessment on our near-term roadmap, followed by the Type II observation period.

PCI DSS

Payment card controls for client programs where agents handle payments.

Controls built into our operation

Whether agents work at our Glen Allen, Virginia center or remotely across the US, every program runs on controlled, monitored systems.

Secure Glen Allen facility

  • Clean-desk production floor with no phones, bags, or paper at stations
  • Lockers at the floor entrance
  • Badge access with logged entry
  • CCTV with 90+ days of retention
  • Visitor sign-in and escorts

Protected technology

  • Locked-down desktops with USB and printing disabled
  • Screen-capture blocking and data loss prevention
  • Multi-factor authentication on every system
  • Endpoint detection and 24/7 security monitoring
  • Network segmented by client

Trusted people

  • Background checks and drug screening for every agent
  • Annual HIPAA and security training with signed attestations
  • US-based agents and US-only data handling

Planning a vendor security review?

We welcome site visits and security reviews. Contact us to schedule a walkthrough of our Glen Allen, Virginia facility and to request our security documentation under NDA.