Aikyam Identity Platform's posture and philosophy around data security align with the larger organizational goal of encrypting sensitive data within Optum systems to ensure confidentiality, integrity, and compliance with regulatory and contractual obligations. This supports Optum’s commitment to protecting health information and other sensitive data across all environments.
Scope
This applies to all data stored (at rest) and transmitted (in transit) within Optum systems, including internal applications, partner portals, health exchange platforms, and third-party providers.
Data security requirements
Encryption at rest: All sensitive data stored in databases, file systems, backups, and cloud storage must be encrypted using contemporary cryptographic methods that are recognized as strong and compliant with industry standards. This requirement applies not only to databases but also to the underlying storage layers, ensuring that data remains unreadable even if accessed directly from the file system. Certain secrets are stored in a way that even administrators cannot view the plaintext values.
Encryption in transit: All data transmitted between partner systems, applications, and external providers must use network protocols to ensure confidentiality and integrity during transmission (e.g., TLS, SSL-based protocols).
Key management
Key storage:Encryption keys are stored in secure vaults with strict access controls.
Key rotation: Encryption keys are rotated periodically or after a defined number of uses, depending on the requirements of the specific use case.
Ownership: Master keys are owned at the tenant level and used to encrypt data keys. This ensures each tenant’s data remains isolated and cannot be accessed by others.
Compliance alignment
Optum’s data security practices are designed to align with multiple regulatory frameworks and industry standards:
MARS-E (Minimum Acceptable Risk Standards for Exchanges): Applicable to health insurance exchanges, MARS-E defines baseline security controls for protecting sensitive health data. Optum ensures encryption requirements for data at rest and in transit meet or exceed these standards.
HIPAA (Health Insurance Portability and Accountability Act): HIPAA mandates the protection of Protected Health Information (PHI). Optum implements encryption as a key safeguard to maintain confidentiality and integrity of PHI across all systems and integrations.
FISMA (Federal Information Security Management Act): FISMA requires federal agencies and their partners to implement robust security measures, including encryption, for sensitive information. Optum aligns with FISMA principles for systems handling government-related health data.
Roles and responsibilities
Security governance team: Approves exceptions and oversees compliance.
Engineering teams: Implement encryption standards in applications and systems.
Vulnerabilities and threats
Continuous monitoring and mitigation for emerging vulnerabilities and threat vectors.
Exceptions
Any exceptions to this policy must be documented and approved by Optum’s security governance teams.
Review and updates
This security posture is regularly reviewed and updated to respond to evolving situations.
Note: Some compliance certifications may be in progress or considered “soft-compliant.” Optum continuously monitors regulatory changes to maintain alignment.