HIPAA, finished by agents.

Sixty controls across the administrative, physical and technical safeguards, the organizational requirements and the documentation rule. Agents collect them, test them and keep them current.

60

controls

5

safeguard groups

66

cross-mappings

8

policies

One safeguard, counted everywhere it applies.

HIPAA carries 66 cross-mappings into the other eleven frameworks. Fifteen land on SOC 2, ten on Thailand PDPA, six on ISO 27001. The encryption and access evidence a safeguard needs is the same evidence those controls need, so an agent collects it once.

The policies, already drafted.

The policy writer drafts each document against the systems you connected, a second agent reviews it, and you approve. HIPAA needs 8.

  • Privacy Policy

    Establishes the requirements for protecting patient health information.

  • Security Policy

    Technical and administrative safeguards for electronic PHI.

  • Access Control Policy

    Controls for accessing systems that hold PHI, and the audit controls over them.

  • Breach Notification Policy

    Procedures for detecting, reporting and responding to PHI breaches.

  • Business Associate Policy

    Requirements for the business associates who handle PHI on your behalf.

  • Workforce Training Policy

    Security awareness and training requirements for workforce members.

  • Contingency Plan Policy

    Data backup, disaster recovery and emergency mode operations.

  • Data Disposal Policy

    Procedures for the secure disposal of PHI and the media that held it.

Before you start.

Covered entity or business associate?
Either. The seeded control set spans the Security Rule safeguards, the organizational requirements at 164.314 and the documentation rule at 164.316, so the same workspace fits a provider and a vendor handling PHI for one.
Is the risk analysis part of it?
Yes. 164.308(a)(1)(ii)(A) is a seeded control like any other: the agents gather the inputs, the finding is recorded against the control and the risk treatment lives beside it.
Do the agents read patient data?
No. They read configuration and control evidence from the systems you connect: access lists, encryption settings, logging and backup configuration. They do not read the records those systems hold.

From zero to audit-ready in 30 days

Connect your systems and the HIPAA controls start filling in on the first heartbeat.

  1. 01

    Connect

    Point Zero2Do at your cloud, code hosting and identity provider. Nothing to install.

  2. 02

    Agents run

    On a schedule, from day one: evidence gets collected against every control in scope, policies get drafted and tests get run.

  3. 03

    Approve

    You review what the agents produced and answer the few questions only you can answer.