Compliance

Compliance

HIPAA and PCI DSS support for practices and businesses that get assessed on how they handle other people’s data.
Compliance

Compliance is evidence, not intention

Every framework asks the same underlying question: can you show that the control was in place, working, and monitored, on the date in question. Having good security and being able to prove it are different problems, and the second one is what an assessment tests.

HIPAA

For medical, dental and therapy practices whose systems hold protected health information, and for the vendors who touch it.
Access control and audit logging
Who can reach records, and a durable record of who actually did.
Encryption at rest and in transit
Covering workstations, servers, backups and email carrying patient data.
Business associate agreements
In place with every vendor able to touch protected data, including your IT provider.
Risk analysis
Documented, periodic, and revisited when systems change rather than filed once.

PCI DSS

For any business that stores, processes or transmits card data, which includes most retail, hospitality and professional services.
Network segmentation
Payment traffic separated from general business traffic, which also shrinks what is in scope.
Patching to the standard
Critical fixes applied inside the window the standard sets, with evidence of when.
Access restriction
Card data reachable only by roles that need it, with unique credentials per person.
Annual self assessment
The questionnaire completed accurately, with the technical evidence to stand behind each answer.

What an assessor actually asks for

An asset inventory
Every device and system touching regulated data. Most failures start with something nobody knew was there.
Written policy
Acceptable use, access control, incident response and retention, dated and reviewed.
Evidence of monitoring
Logs showing controls ran, and that alerts were seen by someone rather than accumulating unread.
Proof of restore
Not that backups exist, but that a restore was performed and verified on a known date.
Training records
Who was trained, on what, and when. Usually the fastest gap to close.
Vendor agreements
Signed, current, and covering every third party with access to regulated data.

Gap assessment

Where you stand against the framework today, written plainly, with each gap ranked by risk rather than listed alphabetically.

Remediation

Closing the technical gaps, and producing the documentation that shows the control exists and is monitored.

Ongoing evidence

Compliance decays. Continuous monitoring and periodic review keep the evidence current instead of rebuilt in a panic each year.

Assessment coming up, or just not sure where you stand?

A gap assessment gives you an honest answer and a ranked list, before someone else produces one for you.