Compliance

HIPAA scanning aid

Map technical safeguard gaps on connected systems — RLS, authentication, storage, secrets, and ingest redaction — so healthcare teams can find vulnerabilities before they ship.

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) is a United States federal law that sets national standards for protecting the privacy and security of individually identifiable health information (PHI). It is enforced by HHS OCR and applies to covered entities and their business associates.

HIPAA requires administrative, physical, and technical safeguards. Secure Raven automates a subset of the technical safeguards (access, audit signals, integrity-related function risks, authentication coverage, and transmission headers) on systems you connect. Settings includes a vendor BAA inventory so teams can record determinations. Workforce training and facility controls are not automated here.

Secure Raven is a scanning and evidence aid. It is not a HIPAA certification, does not replace a Privacy Officer, Security Officer, or legal counsel, and does not mean a customer or Secure Raven itself is HIPAA compliant.

Key Facts

Governing Body
HHS / OCR
Scope
Protected Health Information
Safeguards
Administrative, Physical, Technical
Secure Raven today
Technical gaps + BAA inventory
Penalties
Up to $1.5M per violation
Product

What Secure Raven maps for HIPAA

Scanning and evidence on systems you connect — not a certification or attestation.

Access-control gaps

HIPAA Hawk flags tables without RLS, USING(true) write policies, and PHI-named tables missing a tenant boundary key.

Encryption and secrets

Detects plaintext credential columns and public buckets, including bucket names that suggest PHI. Envelope encryption is used for your connected credentials in Secure Raven.

Ingest redaction signals

If a probe event payload looks like SSN, card, or PHI field names, ingest redacts it and HIPAA Hawk opens a finding. Raw restricted values are not stored.

Release-blocking severity

Critical and high hawk findings are treated as release blockers in the product severity model. Medium items (probe missing, PHI-capable schema) require review, not automatic ship-stop.

Mapped technical controls

Each hawk finding cites 164.312 access, audit, integrity, authentication, or transmission — plus 164.308 risk analysis and 164.314 BAA inventory gaps.

Vendor BAA inventory

Settings → BAAs records vendor name, ePHI exposure, and BAA status. HIPAA Hawk flags missing or expired determinations. This is not a legal BAA, a contract vault, or a 72-hour breach program.

Controls

Controls we cover

Mapped, monitored, or supported labels — not an attestation that you or Secure Raven passed HIPAA.

ControlIDStatus
Access Controls
§164.312(a)
automated
Audit Controls
§164.312(b)
monitored
Integrity Controls
§164.312(c)
automated
Authentication
§164.312(d)
automated
Transmission Security
§164.312(e)
supported
Security Management
§164.308(a)
supported
Facility Access
§164.310(a)
supported
Security Awareness
§164.308(a)(5)
supported
Business Associate Contracts
§164.314(a)
monitored
3
Safeguard Categories
20
Hawk checks (incl. BAA)
RLS+
Access + storage scans
Aid
Not a certification

Find HIPAA technical gaps before they ship

Connect a system, install the hawk probe, and run HIPAA Hawk. This is a scanning aid — not a certification.