Compliance

HIPAA & GDPR

Live control posture across the HIPAA Security Rule, GDPR Articles 25, 28, 32, and PIPL Article 38.

Controls compliant
127/128
Open findings
1
Encryption coverage
100%
Jurisdictions
12
HIPAA Security Rule · §164.308-316
CitationControlEvidenceStatus
164.308(a)(1)Security Management ProcessRisk analysis 2026-Q1 · acceptedCompliant
164.308(a)(3)Workforce SecurityBackground checks + Okta SCIMCompliant
164.308(a)(4)Information Access ManagementRBAC matrix v4.2 · ABAC overlayCompliant
164.308(a)(5)Security Awareness & Training98% completion · refreshed Q1Compliant
164.308(a)(6)Security Incident ProceduresRunbook last drill 2026-04-22Compliant
164.310(a)(1)Facility Access ControlsBadge + biometric at DCCompliant
164.312(a)(1)Access Control · technicalMFA + SSO enforced 100%Compliant
164.312(b)Audit ControlsImmutable WORM logs · 7yr retentionCompliant
164.312(c)(1)IntegritySHA-256 Merkle hourly verificationCompliant
164.312(d)Person/Entity AuthenticationSAML 2.0 + WebAuthnCompliant
164.312(e)(1)Transmission SecurityTLS 1.3 · mTLS internalCompliant
164.316(b)Documentation & RetentionPolicy v8 review overdue 12dAction required
Data residency
US (HIPAA)us-east-1, us-west-2
EU (GDPR)eu-central-1 (Frankfurt)
UK (UK GDPR)eu-west-2 (London)
China (PIPL)cn-north-1 (separate plane)
Singapore (PDPA)ap-southeast-1
Australia (Privacy Act)ap-southeast-2
BAAs / DPAs in force
AWS · BAA #BAA-2024-0182
Stripe · DPA v2024.3
Okta · BAA + DPA
Datadog · BAA #DD-2024-088
MongoDB Atlas · BAA + DPA
Anthropic · BAA + DPA
Open items
Policy v8 review
§164.316(b) requires 6-yr review cycle. Overdue by 12 days.
SOC 2 Type II renewal
On track · auditor field work scheduled Jul 8-22.