The sector's security needs
Why seek independent assurance?
The Canadian Cyber Centre identifies sensitive information and disruption of important processes as concerns for healthcare organizations. Suppliers contribute to that exposure through the data they receive and the systems their customers rely on. Complade's examples in this sector include healthcare procurement, benefits administration and digital health services.
Read the sector sourceChoosing a certification
Information security management
ISO/IEC 27001
ISO/IEC 27001 is relevant where a provider needs systematic information security management across services, suppliers and customer obligations. Certification assesses that management system, giving buyers evidence beyond a description of individual security tools.
ISO/IEC 27001 certification processBaseline cybersecurity requirements
CyberSecure Canada
CyberSecure Canada is relevant when a healthcare supplier needs independent assessment of baseline cybersecurity practices. Buyers can consider the certificate as part of their supplier review, checking that the activities they rely on are within scope.
CyberSecure Canada certification processWhen do both make sense?
Both can be appropriate when customers specify different certification requirements. A shared set of controls may contribute to both, but the scope and requirements of each must be checked separately.
Complade considers whether audit activities can be coordinated during application review. Audit time and fees are confirmed in the proposal.
Examples from the Complade Certification Registry
Open each record to check the standard, status and scope. These examples are not endorsements of the organizations' products or services.
Define your scope
Application review starts with your activities and responsibilities. Be ready to answer these questions:
- What health, benefits or procurement information is included?
- Which services and suppliers support its processing?
- Does the proposed scope cover the service the customer is evaluating?
Sources and Complade's role
The sources explain sector concerns. Their connection to the certifications discussed is Complade's analysis; these organizations do not endorse Complade or necessarily require these certifications.
Complade provides independent certification audits. We do not provide implementation consulting, readiness consulting or internal audits. Certification concerns conformity with the applicable requirements within a defined scope; it does not guarantee the absence of incidents.
Verify Complade's accreditation · Understand the audit process