HIPAA, finished by agents.
Sixty controls across the administrative, physical and technical safeguards, the organizational requirements and the documentation rule. Agents collect them, test them and keep them current.
60
controls
5
safeguard groups
66
cross-mappings
8
policies
One safeguard, counted everywhere it applies.
HIPAA carries 66 cross-mappings into the other eleven frameworks. Fifteen land on SOC 2, ten on Thailand PDPA, six on ISO 27001. The encryption and access evidence a safeguard needs is the same evidence those controls need, so an agent collects it once.
The policies, already drafted.
The policy writer drafts each document against the systems you connected, a second agent reviews it, and you approve. HIPAA needs 8.
Privacy Policy
Establishes the requirements for protecting patient health information.
Security Policy
Technical and administrative safeguards for electronic PHI.
Access Control Policy
Controls for accessing systems that hold PHI, and the audit controls over them.
Breach Notification Policy
Procedures for detecting, reporting and responding to PHI breaches.
Business Associate Policy
Requirements for the business associates who handle PHI on your behalf.
Workforce Training Policy
Security awareness and training requirements for workforce members.
Contingency Plan Policy
Data backup, disaster recovery and emergency mode operations.
Data Disposal Policy
Procedures for the secure disposal of PHI and the media that held it.
Before you start.
- Covered entity or business associate?
- Either. The seeded control set spans the Security Rule safeguards, the organizational requirements at 164.314 and the documentation rule at 164.316, so the same workspace fits a provider and a vendor handling PHI for one.
- Is the risk analysis part of it?
- Yes. 164.308(a)(1)(ii)(A) is a seeded control like any other: the agents gather the inputs, the finding is recorded against the control and the risk treatment lives beside it.
- Do the agents read patient data?
- No. They read configuration and control evidence from the systems you connect: access lists, encryption settings, logging and backup configuration. They do not read the records those systems hold.
From zero to audit-ready in 30 days
Connect your systems and the HIPAA controls start filling in on the first heartbeat.
- 01
Connect
Point Zero2Do at your cloud, code hosting and identity provider. Nothing to install.
- 02
Agents run
On a schedule, from day one: evidence gets collected against every control in scope, policies get drafted and tests get run.
- 03
Approve
You review what the agents produced and answer the few questions only you can answer.