M ManySignal

Compliance — HIPAA

HIPAA Security Rule monitoring — control by control

ManySignal maps to every HIPAA Security Rule administrative, physical, and technical safeguard — from §164.308(a)(1) risk analysis to §164.312(b) audit controls. BAA available. OCR breach notification export built in.

What HIPAA requires in plain language

Administrative Safeguards (§164.308)

Security management process, assigned security responsibility, workforce training, information access management, and evaluation of security programme effectiveness. The largest category of HIPAA requirements.

Technical Safeguards (§164.312)

Access control (unique user IDs, emergency access), audit controls (§164.312(b) — the most commonly cited in OCR enforcement), integrity controls, and transmission security. The category most directly addressed by monitoring platforms.

Breach Notification Rule (§164.400-414)

Notification to individuals within 60 days, to HHS/OCR annually (or immediately for 500+ breaches), and to media for 500+ state breaches. The notification must include specific information about the breach scope and PHI categories involved.

Control mapping — HIPAA to ManySignal capabilities

Control ReferenceControl NameManySignal Capability
§164.308(a)(1)(ii)(D) Information System Activity Review Automated log review across EHR, network, and identity systems — daily audit log analysis with anomaly alerting
§164.308(a)(5)(ii)(C) Log-in Monitoring Workforce login event monitoring with failed attempt baselining, MFA bypass detection, and off-hours access alerts
§164.310(d)(2)(iii) Accountability Entity graph tracks every access event to hardware, systems, and data by workforce identity
§164.312(a)(1) Access Control Privileged access anomaly detection — access by users outside their assigned patient cohort, access outside role scope
§164.312(b) Audit Controls Full audit log collection from EHR (Epic, Cerner, Meditech), network, and identity systems. Tamper-resistant log storage with 7-year retention
§164.312(c)(1) Integrity PHI modification anomaly detection — bulk updates, record deletion, and audit log tampering detected in real time
§164.312(e)(1) Transmission Security Encryption-in-transit monitoring — alerts on PHI transmitted via unencrypted protocols
§164.314(a)(2)(i) Business Associate Contracts Third-party access monitoring — BA system connections baselined and monitored for anomalous PHI access
§164.404 Breach Notification to Individuals 60-day notification countdown, affected individual count tracking, notification letter pre-population from incident data
§164.406 Notification to Media 500+ individual threshold tracking per state — automated alert when breach size crosses media notification threshold
§164.408 Notification to Secretary (HHS/OCR) Annual reporting log compiled from case records — OCR breach notification form pre-populated

Evidence and audit export path

OCR breach report export

One-click export generating a pre-populated HHS OCR breach notification form from incident data. Includes: breach discovery date, affected individual count by state, PHI categories exposed, and safeguards in place at time of breach.

HIPAA audit log package

Per-incident evidence package containing all §164.312(b) audit logs relevant to the incident — timestamped, entity-attributed, and tamper-evident. Formatted for attorney review and OCR investigation response.

Continuous monitoring report

Monthly report documenting §164.308(a)(1)(ii)(D) information system activity review — covering all monitored systems, anomalies detected, alerts fired, and cases opened in the period.

Certification and audit status

ManySignal operates in HIPAA-eligible AWS infrastructure. Our SOC 2 Type II report (available under NDA at [email protected]) covers the security controls that underpin HIPAA compliance. BAA is available at /legal/baa. ManySignal's HIPAA compliance programme is reviewed annually by an independent HIPAA consultant.

Shared responsibility

ManySignal is responsible for:

  • Security of the ManySignal platform infrastructure
  • BAA obligations assumed as a Business Associate
  • Accuracy and completeness of monitoring evidence
  • Encryption in transit and at rest within the platform
  • Staff access controls and training

Customer (Covered Entity / BA) is responsible for:

  • Configuring ManySignal for their specific environment and PHI scope
  • Acting on alerts and implementing recommended remediation
  • Executing breach notification obligations under HIPAA
  • Maintaining HIPAA security policies and workforce training
  • Risk analysis and risk management programme (§164.308(a)(1))

HIPAA compliance — auditor questions

Does ManySignal sign a Business Associate Agreement (BAA)?

Yes. ManySignal executes BAAs with all healthcare customers before any PHI is processed. The BAA is available at /legal/baa. Healthcare customers are deployed in HIPAA-eligible AWS infrastructure with AES-256 encryption at rest and TLS 1.3 in transit. PHI is never used for AI model training or shared with third parties.

How does ManySignal address the HIPAA Breach Notification Rule specifically?

HIPAA's Breach Notification Rule (§164.400-414) requires covered entities to notify affected individuals within 60 days of discovering a breach, notify HHS/OCR, and — for breaches affecting 500+ residents in a state — notify prominent media. ManySignal's case management starts the 60-day countdown at discovery, tracks the affected individual count by state, and triggers media notification reminders when state thresholds are crossed.

Which EHR systems does ManySignal integrate with for §164.312(b) audit control coverage?

ManySignal has native integrations for Epic (via Clarity audit tables and Epic Syslog Audit Trail), Oracle Health/Cerner (Audit Log API), Meditech Expanse (syslog + CEF), and Allscripts/Veradigm. For other EHR platforms, the universal log pipeline ingests syslog and CEF formats. Coverage gaps — EHR platforms not yet connected — are reported in the audit control coverage dashboard.

How does ManySignal provide evidence for HIPAA §164.308(a)(1)(ii)(D) — Information System Activity Review?

§164.308(a)(1)(ii)(D) requires regular review of information system activity — audit logs, access reports, and security incident tracking reports. ManySignal automates this by: continuously analysing all logs (not just sampling), flagging anomalies in real time, and generating weekly activity summary reports that can serve as evidence of the required periodic review. Audit packages are time-stamped and tamper-evident.

What is ManySignal's shared responsibility model for HIPAA?

ManySignal is responsible for: the security of the ManySignal platform infrastructure, the BAA obligations it assumes as a Business Associate, and the accuracy of the monitoring evidence it provides. The Covered Entity (or Business Associate customer) is responsible for: configuring ManySignal correctly for their environment, acting on the alerts and evidence ManySignal provides, implementing the remediation actions recommended in investigation reports, and executing their breach notification obligations.

Request the BAA and start a HIPAA deployment

Execute the BAA, connect your EHR audit logs, and have HIPAA §164.312(b) audit controls evidenced within your first week.