The views expressed in this blog are those of the owner and do not reflect the views or opinions of the owner’s employer. All content provided on this blog is for informational purposes only. The owner of this blog makes no representations as to the accuracy or completeness of any information on this site or found by following any link on this site. The owner will not be liable for any errors or omissions in this information nor for the availability of this information. The owner will not be liable for any losses, injuries, or damages from the display or use of this information. This policy is subject to change at any time. The owner is not an attorney, and nothing posted on this site should be construed as legal advice. Litigation Support Tip of the Night does not provide confirmation that any e-discovery technique or conduct is compliant with legal, regulatory, contractual or ethical requirements.
New tips for paralegals and litigation support profesionals are posted to this site each night. Click on the blog headings for better detail.
4 days ago
Data Encrypted at Rest in Relativity
RelativityOne encrypts data at rest on servers so attackers cannot read the data without encryption keys.
FedRAMP, HIPAA, and other regulations may require data at rest encryption. Relativity uses the Microsoft Azure platform which according to this white paper meets, “more than 70 international and industry-specific compliance standards, such as ISO 27001, SOC 2, Type II, HIPAA, and FedRAMP, as well as country- specific standards like Australia IRAP, UK G-Cloud, and Singapore MTCS.”
Note that the HIPAA Security Rule does not actually require encryption but it does make it an 'addressable implementation' which means that it may be found that it is reasonable and appropriate to encrypt data. If not, alternative measures can be taken.
FedRAMP's Control Specific Contract Clauses, which provides language to be used in the provisions of contracts addressing cloud security, states that, "Cloud Service Providers pursuing a FedRAMP authorization will have to support the capability to encrypt data-at-rest; however, contract clauses should indicate any specific agency requirements for data encryption."