HIPAA scanning aid
Map technical safeguard gaps on connected systems — RLS, authentication, storage, secrets, and ingest redaction — so healthcare teams can find vulnerabilities before they ship.
What is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) is a United States federal law that sets national standards for protecting the privacy and security of individually identifiable health information (PHI). It is enforced by HHS OCR and applies to covered entities and their business associates.
HIPAA requires administrative, physical, and technical safeguards. Secure Raven automates a subset of the technical safeguards (access, audit signals, integrity-related function risks, authentication coverage, and transmission headers) on systems you connect. Settings includes a vendor BAA inventory so teams can record determinations. Workforce training and facility controls are not automated here.
Secure Raven is a scanning and evidence aid. It is not a HIPAA certification, does not replace a Privacy Officer, Security Officer, or legal counsel, and does not mean a customer or Secure Raven itself is HIPAA compliant.
Key Facts
- Governing Body
- HHS / OCR
- Scope
- Protected Health Information
- Safeguards
- Administrative, Physical, Technical
- Secure Raven today
- Technical gaps + BAA inventory
- Penalties
- Up to $1.5M per violation
What Secure Raven maps for HIPAA
Scanning and evidence on systems you connect — not a certification or attestation.
Access-control gaps
HIPAA Hawk flags tables without RLS, USING(true) write policies, and PHI-named tables missing a tenant boundary key.
Encryption and secrets
Detects plaintext credential columns and public buckets, including bucket names that suggest PHI. Envelope encryption is used for your connected credentials in Secure Raven.
Ingest redaction signals
If a probe event payload looks like SSN, card, or PHI field names, ingest redacts it and HIPAA Hawk opens a finding. Raw restricted values are not stored.
Release-blocking severity
Critical and high hawk findings are treated as release blockers in the product severity model. Medium items (probe missing, PHI-capable schema) require review, not automatic ship-stop.
Mapped technical controls
Each hawk finding cites 164.312 access, audit, integrity, authentication, or transmission — plus 164.308 risk analysis and 164.314 BAA inventory gaps.
Vendor BAA inventory
Settings → BAAs records vendor name, ePHI exposure, and BAA status. HIPAA Hawk flags missing or expired determinations. This is not a legal BAA, a contract vault, or a 72-hour breach program.
Controls we cover
Mapped, monitored, or supported labels — not an attestation that you or Secure Raven passed HIPAA.
Find HIPAA technical gaps before they ship
Connect a system, install the hawk probe, and run HIPAA Hawk. This is a scanning aid — not a certification.