Common use of Secure FTP Clause in Contracts

Secure FTP. ¨ For non-automated (user) interaction with the XIFIN SFTP site, XIFIN recommends the free SFTP client Filezilla: ▇▇▇▇://▇▇▇▇▇▇▇▇▇-▇▇▇▇▇▇▇.▇▇▇/ ¨ For automated interaction with the XIFIN SFTP site, we recommend the free OpenSSH client for Windows or Unix. ¨ Java will need to be installed to run the Order Entry application; this can be found for free on: ▇▇▇▇://▇▇▇▇.▇▇▇.▇▇▇/javase/downloads/ Select the JDK 6.0 Update 20 or later XIFIN, Inc. ¿12225 ▇▇ ▇▇▇▇▇▇ ▇▇▇▇, ▇▇▇▇▇ ▇▇▇¿▇▇▇ ▇▇▇▇▇, ▇▇ ▇▇▇▇▇¿▇▇▇: ▇▇▇-▇▇▇-▇▇▇▇ ¿▇▇▇.▇▇▇▇▇.▇▇▇ Agreement: iRhythm Technologies, Inc. 23 of 34 ¨ Connection Security • Dual firewalls with fail-over configuration • Redundant switches with separate VLANs and ACLs enforcing security • Port and network address translations through firewalls and load balancers • Non-secure web connections are redirected to a secure website • Only allow SSH protocol version 2 for file transfers and only with public key authentication • SFTP connections are restricted to the file transfer directory only • Logins are allowed only through the application GUI (i.e., we do not allow interactive logins directly to servers) • Can restrict interactive access to specific IP addresses if requested • HTTPS 128 bit encrypted SSL secure tunnel connections required • SSH/SFTP connection requires a minimum of 1024 bit encryption • Network traffic is logged and routinely monitored ¨ Password Access Security Users access the System through a combination of user names and passwords: • User names and passwords are case sensitive • Passwords must be at least 8 characters long and contain at least one alpha and one numeric value. • After 5 unsuccessful attempts, a user account is locked and must be unlocked by a supervisor or administrator before it can be accessed again. • Users are required to change their password every 90 days. XIFIN, Inc. ¿12225 ▇▇ ▇▇▇▇▇▇ ▇▇▇▇, ▇▇▇▇▇ ▇▇▇¿▇▇▇ ▇▇▇▇▇, ▇▇ ▇▇▇▇▇¿▇▇▇: ▇▇▇-▇▇▇-▇▇▇▇ ¿▇▇▇.▇▇▇▇▇.▇▇▇ Agreement: iRhythm Technologies, Inc. 24 of 34 Outsourced Billing Client Requirements

Appears in 2 contracts

Sources: Services Agreement (iRhythm Technologies, Inc.), Services Agreement (iRhythm Technologies, Inc.)

Secure FTP. ¨ For non-automated (user) interaction with the XIFIN SFTP site, XIFIN recommends the free SFTP client Filezilla: ▇▇▇▇://▇▇▇▇▇▇▇▇▇-▇▇▇▇▇▇▇.▇▇▇/ ¨ For automated interaction with the XIFIN SFTP site, we recommend the free OpenSSH client for Windows or Unix. ¨ Java will need to be installed to run the Order Entry application; this can be found for free on: ▇▇▇▇://▇▇▇▇.▇▇▇.▇▇▇/javase/downloads/ Select the JDK 6.0 Update 20 or later XIFIN, Inc. ¿12225 ¨ ▇▇▇▇▇ ▇▇ ▇▇▇▇▇▇ ▇▇▇▇, ▇▇▇▇▇ ▇▇▇¿¨▇▇▇ ▇▇▇▇▇, ▇▇ ▇▇▇▇▇¿▇▇▇92130¨tel: ▇▇▇-▇▇▇-▇▇▇▇ ¿¨▇▇▇.▇▇▇▇▇.▇▇▇ Agreement: iRhythm Technologies, Inc. 23 of 34 ¨ Connection Security • Dual firewalls with fail-over configuration • Redundant switches with separate VLANs and ACLs enforcing security • Port and network address translations through firewalls and load balancers • Non-secure web connections are redirected to a secure website • Only allow SSH protocol version 2 for file transfers and only with public key authentication • SFTP connections are restricted to the file transfer directory only • Logins are allowed only through the application GUI (i.e., we do not allow interactive logins directly to servers) • Can restrict interactive access to specific IP addresses if requested • HTTPS 128 bit encrypted SSL secure tunnel connections required • SSH/SFTP connection requires a minimum of 1024 bit encryption • Network traffic is logged and routinely monitored ¨ Password Access Security Users access the System through a combination of user names and passwords: • User names and passwords are case sensitive • Passwords must be at least 8 characters long and contain at least one alpha and one numeric value. • After 5 unsuccessful attempts, a user account is locked and must be unlocked by a supervisor or administrator before it can be accessed again. • Users are required to change their password every 90 days. XIFIN, Inc. ¿12225 ¨ ▇▇▇▇▇ ▇▇ ▇▇▇▇▇▇ ▇▇▇▇, ▇▇▇▇▇ ▇▇▇¿¨▇▇▇ ▇▇▇▇▇, ▇▇ ▇▇▇▇▇¿▇▇▇92130¨tel: ▇▇▇-▇▇▇-▇▇▇▇ ¿¨▇▇▇.▇▇▇▇▇.▇▇▇ Agreement: iRhythm Technologies, Inc. 24 of 34 Outsourced Billing Client Requirements

Appears in 1 contract

Sources: Services Agreement (iRhythm Technologies, Inc.)