Government, military, and industry regu lations generally do not mandate the application of a specific type or level of data protection, as technological advances are constantly developing more quickly than laws can be written. LifeCard Plans™ however, does follow, and in some instances exceeds, current NSA, Military, and Government privacy and security protocols, ensuring that client documents and medical information are protected by the newest technology available.

There are two ways data needs to be protected:

• when being transferred, uploaded, and downloaded, and
• when in storage on servers

Here are the technical specifics on how LifeCard Plans™ safeguards information in these areas:

Data Transfer Protection

• HTTPS/SSL (Secure Sockets Layer) Encryption
• LifeCard Plans™ uses secure encryption at all levels including ordering pages.
• Extended Validation SSL SGC-Enabled Certificate
• Advanced Encryption Standard (AES) 256-bit Encryption Data Storage Protection
• World’s Leading Technology in Datacenter Service
• Dedicated Firewalls
• AES-256 Database and Document Encryption
• NIST/FIPS 140-2 approved CVMP Cryptographic Modules
• NIST 800-53 Compliant Key Management Infrastructure

Datacenter Information- Rackspace Hosting

Our data centers are engineered to the standards required to support the Rackspace
Network. They are designed and maintained without compromise for security
or redundancy. Ever.

Physical Security

• Keycard protocols, biometric scanning protocols and round-the-clock interior and
exterior surveillance monitor access to every one of our data centers.
• Only authorized data center personnel are granted access credentials to
our data centers. No one else can enter the production area of the datacenter
without prior clearance and an appropriate escort.
• Every data center employee undergoes multiple and thorough background
security checks before they’re hired.
Precision Environment
• Every data center’s HVAC (Heating Ventilation Air Conditioning) system is
N+1 redundant. This ensures that a duplicate system immediately comes
online should there be an HVAC system failure.
• Every 90 seconds, all the air in our data centers are circulated and filtered
to remove dust and contaminants.
Conditioned Power
• Should a total utility power outage ever occur, all of our data centers’
power systems are designed to run uninterrupted, with every server receiving
conditioned UPS (Uninterrupted Power Supply) power level networks.

