Learn more about the Dentsply Sirona Windows 11 Security Package to continue ensuring security and compatibility of your Dentsply Sirona devices.
In developing these technical and organizational measures, Dentsply Sirona has taken into consideration the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons and on basis of company-wide regulations. These measures ensure an appropriate level of security, as detailed below.
Note that most of the Customer Personal Data is processed through the SureSmile Software. Personal data processed outside the Software is generally limited to identifiers, manufacturing specifications, and/or order tracking.
1.1 Physical Access Control
The purpose of the physical access control in place is to prevent unauthorized access to facilities where personal data is processed.
The following security measures are in place at facilities where Customer Personal Data is processed:
Note that the SureSmile Software itself is hosted by Amazon Web Services, which provides similar physical security measures.
1.2 Electronic Access Control
The purpose of the electronic access control is to prevent unauthorized access to systems that process personal data.
The following security measures are implemented by the SureSmile Software::
Note that the SureSmile Software includes tools such as role-based access controls and user activity logging to help practices manage their own users.
1.3 Internal Access Control
The purpose of internal access control is to ensure that persons who use systems where personal data is stored only have access the parts of the system they need for the fulfillment of their duties.
The following security measures are in place::
1.4 Isolation Control
The purpose of the isolation control is to ensure that data collected for different purposes can be processed separately.
The following provisions are implemented by the SureSmile Software:
1.5 Pseudonymisation
The purpose of pseudonymisation is to protect the personal data by ensuring that the personal data cannot be associated with a specific data subject without the assistance of additional information.
Provisions related to pseudonymisation include:
2.1 Data Transfer Control
The purpose of the data transfer control is to ensure that personal data cannot be read, copied, changed or deleted in an unauthorized way during an electronic transfer, physical transportation or storage on a data storage medium.
The following provisions are implemented::
All practice and Patient data is encrypted at rest;
2.2 Data Entry Control
The purpose of the data entry control is to verify retroactively whether and by whom personal data was entered, changed, or deleted from a data processing system..
The SureSmile Software logs system access and change history. These logs are available to the practices, as they enter, modify, and delete personal data most frequently. The SureSmile team can assist as necessary.
3.1 Availability Control
The purpose of the availability control is to ensure that personal data is protected against accidental destruction or loss.
The following security measures are implemented by the SureSmile team, using functionality available from Amazon Web Services, the cloud hosting provider for the SureSmile system:
3.2 Rapid Recovery
The purpose of the rapid recovery control is to ensure that in case of disruption, the stored data will be made available again as soon as possible.
The following security measures are implemented by the SureSmile team, some of which use functionality available from Amazon Web Services, the cloud hosting provider for the SureSmile system:
4.1 Data Protection Management
The purpose of data protection management is to ensure that appropriate technical and organizational measures have been identified and implemented.
Dentsply Sirona has a centralized data protection organization, which defines goals, duties, competencies and responsibilities regarding data privacy:
4.2 Incident Response Management
The purpose of incident response management is to ensure that cybersecurity incidents are identified and responded to appropriately.
Technical and organizational measures related to incident management include:
4.3 Data Protection by Design and Default
The purpose of this section is to ensure that the security of personal data is considered and is the default configuration when developing new products and services.
Data Protection by Design and by Default is achieved through the following measures:
4.4 Engaging Third Parties
The purpose of this section is to ensure that personal data, which is processed by third parties, will not be processed without clear and unambiguous contractual arrangements.
To achieve this purpose, the following organizational measures are implemented: