Data Security Policy of BURG Translations

BURG Translations Data Security Policy

At BURG Translations, we prioritize the security and confidentiality of our clients’ information. Our robust Information Security Management System (ISMS) is designed to protect your data and ensure the highest standards of information security. This commitment is formalized through our ISO/IEC 27001:2022 certification, demonstrating our adherence to internationally recognized security practices.

ISO/IEC 27001:2022 certification badge for BURG TranslationsWe handle various types of sensitive information including Protected Health Information (PHI) under HIPAA, educational records under FERPA, and other Personally Identifiable Information (PII) requiring specialized security controls and compliance measures.

Our Security Framework

Information Security Management System (ISMS)

Our comprehensive ISMS provides the foundation for our security practices, ensuring:

  • Confidentiality: Information is accessible only to authorized individuals
  • Integrity: Information is altered only by authorized individuals in permitted ways
  • Availability: Information is accessible to authorized individuals when needed

ISO/IEC 27001:2022 Certification

Our commitment to security excellence is validated through our ISO/IEC 27001:2022 certification, which covers our core operational processes. This certification:

  • Demonstrates our adherence to international security standards
  • Validates our systematic approach to managing sensitive information
  • Provides assurance of our ongoing commitment to security best practices

To view our ISO 27001:2022 certificate, please contact: security@burgtranslations.com

Data Security Practices

Data Transfer

We implement stringent measures to secure data during transfer:

  • Protected Health Information (PHI): Transmitted through BURG-approved encrypted channels using current TLS standards or other approved secure transfer methods, consistent with applicable HIPAA and contractual requirements.
  • Educational Records: Transferred through BURG-approved encrypted channels consistent with applicable FERPA, contractual, and institutional requirements
  • General PII and Sensitive Documents: Encrypted transmission for all legal, government, immigration, and business documents
  • Encrypted email communications for sensitive information via Microsoft’s access rights management
  • Secure web form configured for the collection of client-submitted PHI under BURG’s HIPAA safeguards and applicable Business Associate Agreements
  • Secure file transfers via OneDrive, SharePoint, or client-provided SFTP servers
  • Omission of sensitive information from email subject lines and body content

Data Storage

Our secure storage solutions ensure data remains protected:

  • Multi-layered Security: AES-256 encryption for all stored sensitive information including PHI, educational records, and general PII
  • Access Controls: Strict role-based access controls limiting information access to authorized personnel based on data type and client requirements
  • FERPA Compliance: Educational records stored with additional protections meeting FERPA requirements and institutional security standards
  • HIPAA Compliance: PHI stored in dedicated secure environments meeting all HIPAA technical safeguards
  • Multi-factor authentication and strong password requirements for all system access
  • Regular data backups and Data Loss Prevention (DLP) policies
  • Segregated storage environments for different data classification levels

Data Destruction

We maintain secure destruction processes for data that is no longer required:

  • HIPAA Compliance: Securely destroyed according to BURG’s documented retention schedule, applicable Business Associate Agreements, client instructions, and legal requirements
  • Educational Records: Destroyed according to applicable client contracts, institutional policies, legal requirements, and BURG’s documented retention schedule
  • General PII: Secure destruction of all personally identifiable information following industry best practices
  • Physical records are securely shredded, and electronic media is sanitized or destroyed according to BURG’s documented media sanitization procedures, aligned where applicable with NIST SP 800-88 Revision 2.
  • Detailed record maintenance documenting date and method of disposal for all data types
  • Certificate of destruction provided when required by client contracts or regulatory requirements

Data Security Governance

Governance Responsibilities

BURG’s Information Security and Privacy Officer coordinates the Information Security Management System and BURG’s applicable HIPAA security and privacy compliance program and serves as BURG’s designated HIPAA Security Official.

The Technology Department implements and operates technical safeguards. Department managers, system owners, and process owners implement and maintain controls within their areas of responsibility.

The Executive Team approves policies, provides resources, oversees the program, and accepts material residual risk. Independent internal auditors evaluate the effectiveness of the ISMS and applicable controls.

Risk Management

Our approach to security risk management includes:

  • Regular risk assessments to identify potential vulnerabilities
  • Implementation of appropriate controls to mitigate identified risks
  • Ongoing monitoring and improvement of security measures
  • Compliance with legal, regulatory, and contractual requirements

Incident Management

We have established procedures for managing security incidents:

  • Clear reporting channels for security incidents or weaknesses
  • Prompt investigation and resolution of reported incidents
  • Documentation and review of incidents to prevent recurrence
  • Regular testing of incident response procedures

Policy Compliance

We ensure adherence to our security policies through:

  • Regular security awareness training for all team members
  • Periodic audits and assessments of policy compliance
  • Clear consequences for policy violations, up to and including termination
  • Support for implementation and continual improvement of security measures

Data Security Objectives

We have established objectives to continuously improve our security posture:

  • Reducing security incidents through proactive risk management
  • Enhancing team members’ security awareness through regular training
  • Ensuring reliability of services with an annual 99% uptime target
  • Maintaining our ISO/IEC 27001:2022 certification and continually improving the Information Security Management System

Frequently Asked Questions

Information Security Program

Yes. BURG maintains an established and approved information security program. The Information Security and Privacy Officer coordinates the program and the Information Security Management System. The Technology Department operates technical controls, process and system owners maintain controls within their areas, and the Executive Team provides oversight and approval.

BURG assigns defined information security responsibilities across the Information Security and Privacy Officer, Technology Department, process and system owners, Executive Team, and independent internal auditors. This structure provides clear accountability and appropriate separation of duties.

Yes. Our Information Security Policy is approved by our CEO and communicated to all team members. It establishes the requirements that allow us to maintain and continuously improve our information security management system.

Data Security Risk Management

Our security risk management program follows the methodology outlined in our Risk Assessment and Risk Treatment Policy. This includes asset identification, impact analysis, risk assessment, implementation of controls, and monitoring of control effectiveness. Risks are assessed periodically and when significant changes occur.

Yes. The Executive Team approves the risk management framework and accepts material residual risk. The Information Security and Privacy Officer coordinates risk assessments and maintains the risk register. Technology, department managers, and process and system owners identify, assess, and treat risks within their areas of responsibility.

Policy Management

Yes. Our policies are reviewed at least annually to ensure continued alignment with organizational changes and compliance with ISO/IEC 27001:2022 standards and HIPAA regulations.

BURG maintains a comprehensive set of information security policies, including but not limited to:

  • Information Security Policy
  • Information Transfer Policy
  • Information Classification Policy
  • IT Security Policy
  • Password Policy
  • Network Vulnerability Detection Policy
  • Threat Intelligence Policy
  • Risk Assessment and Risk Treatment Policy
  • Incident Management Policy

Access Control

Access to systems and data is granted strictly based on role, department, and specific business need. Team members are assigned to predefined access groups that align with their responsibilities, and permissions are restricted to the minimum necessary to perform their duties.

Access to sensitive data such as Protected Health Information (PHI) and Personally Identifiable Information (PII) is limited to personnel who have a direct and legitimate business need—such as project managers overseeing healthcare-related work.

All access permissions are subject to regular reviews to ensure continued relevance and to prevent unauthorized or excessive access. These controls are enforced as part of BURG’s Access Control Policy and support compliance with ISO/IEC 27001:2022 and HIPAA requirements.

Systems and Application Security

BURG uses a proactive approach to vulnerability management, including regular vulnerability scans, threat intelligence monitoring, and security assessments. Identified vulnerabilities are evaluated for risk based on potential impact and likelihood, and are prioritized accordingly. Remediation actions are tracked through a formal risk treatment process in accordance with ISO/IEC 27001:2022 and HIPAA requirements.

Yes. BURG maintains a documented patch management process to ensure timely application of security updates and software patches. Critical and high-risk vulnerabilities are patched within defined timeframes, based on severity and business impact. The patching process includes testing in a controlled environment before deployment to minimize operational disruption.

Yes. BURG has implemented a formal change management process that governs how changes to systems, applications, and infrastructure are proposed, reviewed, approved, and implemented. All changes are assessed for security, compliance, and operational impact. Documentation and rollback procedures are maintained to ensure traceability and minimize risk.

Incident Management

Yes. Our Incident Management Procedure is published and accessible to all team members and covers reporting, assessment, containment, mitigation, recovery, and follow-up.

Security and privacy incidents may be reported to the Technology Department or the Information Security and Privacy Officer by phone, email, IT ticket, or instant message.

The Technology Department leads technical containment, remediation, and system recovery. The Information Security and Privacy Officer coordinates incident classification, documentation, HIPAA and privacy assessments, analysis of client and regulatory notification obligations, corrective actions, and management reporting in alignment with our ISMS.

Data Privacy and Protection

Yes. We take data privacy very seriously across all sectors we serve. Our practices comply with HIPAA regulations for healthcare information, FERPA requirements for educational records, and applicable privacy laws for all personally identifiable information (PII).

We retain client data only as long as necessary to fulfill the purpose for which it was collected or to comply with legal, regulatory, or internal policy requirements. Specific retention periods include:

  • Client project data, including PHI: Retained according to BURG’s documented retention schedule, applicable client contracts or Business Associate Agreements, legal requirements, and documented business need.
  • HIPAA-required compliance documentation: Retained for at least six years from the date of creation or the date it was last in effect, whichever is later.
  • Educational records: Retained according to applicable client contracts, institutional policies, legal requirements, and BURG’s documented retention schedule
  • Financial information: 10 years (following financial record requirements)

Training and Awareness

Yes. Information security awareness training is part of our onboarding process. Additionally, regular security awareness initiatives are conducted to maintain a strong security culture.

Supplier Management

Suppliers must implement and maintain security controls appropriate to the sensitivity of the information they access or process. Before receiving confidential or regulated information, suppliers must enter into contracts containing applicable security and privacy requirements.

Any supplier or subcontractor that creates, receives, maintains, or transmits PHI on BURG’s behalf must enter into a Business Associate Agreement before receiving PHI.

BURG performs risk-based assessments and oversight to confirm continued compliance with applicable contractual, HIPAA, and ISO/IEC 27001:2022 requirements.

All potential suppliers undergo a vetting process that includes background and education checks for individuals involved in service delivery, particularly linguists and translators. BURG also evaluates the supplier’s qualifications and experience in the relevant domain.

As part of the assessment, prospective translation vendors are required to complete a sample translation. This is reviewed by a qualified reviewer for linguistic accuracy, subject-matter expertise, and adherence to project specifications.

In addition, BURG assesses the supplier’s ability to comply with security requirements, including data protection measures aligned with HIPAA and ISO/IEC 27001:2022 standards. Only those who meet both quality and security criteria are approved and added to BURG’s trusted supplier network.

Compliance and Certification

Yes. Clients may request a copy of our ISO/IEC 27001:2022 certificate by contacting our Information Security and Privacy Officer at security@burgtranslations.com.

Violations of security policies are taken seriously and are addressed in accordance with BURG Translations’ Sanction Policy. All incidents of non-compliance are reviewed based on their nature and severity. Disciplinary actions may range from retraining and written warnings to suspension or termination, depending on the circumstances.

Contact Information

For questions or concerns regarding BURG’s data security practices, please contact our Information Security and Privacy Officer at security@burgtranslations.com.
________________________________________________________________________________________

Effective Date: July 24, 2026
Last Updated: July 24, 2026