Compliance — HIPAA
HIPAA Security Rule monitoring — control by control
ManySignal maps to every HIPAA Security Rule administrative, physical, and technical safeguard — from §164.308(a)(1) risk analysis to §164.312(b) audit controls. BAA available. OCR breach notification export built in.
What HIPAA requires in plain language
Administrative Safeguards (§164.308)
Security management process, assigned security responsibility, workforce training, information access management, and evaluation of security programme effectiveness. The largest category of HIPAA requirements.
Technical Safeguards (§164.312)
Access control (unique user IDs, emergency access), audit controls (§164.312(b) — the most commonly cited in OCR enforcement), integrity controls, and transmission security. The category most directly addressed by monitoring platforms.
Breach Notification Rule (§164.400-414)
Notification to individuals within 60 days, to HHS/OCR annually (or immediately for 500+ breaches), and to media for 500+ state breaches. The notification must include specific information about the breach scope and PHI categories involved.
Control mapping — HIPAA to ManySignal capabilities
| Control Reference | Control Name | ManySignal Capability |
|---|---|---|
| §164.308(a)(1)(ii)(D) | Information System Activity Review | Automated log review across EHR, network, and identity systems — daily audit log analysis with anomaly alerting |
| §164.308(a)(5)(ii)(C) | Log-in Monitoring | Workforce login event monitoring with failed attempt baselining, MFA bypass detection, and off-hours access alerts |
| §164.310(d)(2)(iii) | Accountability | Entity graph tracks every access event to hardware, systems, and data by workforce identity |
| §164.312(a)(1) | Access Control | Privileged access anomaly detection — access by users outside their assigned patient cohort, access outside role scope |
| §164.312(b) | Audit Controls | Full audit log collection from EHR (Epic, Cerner, Meditech), network, and identity systems. Tamper-resistant log storage with 7-year retention |
| §164.312(c)(1) | Integrity | PHI modification anomaly detection — bulk updates, record deletion, and audit log tampering detected in real time |
| §164.312(e)(1) | Transmission Security | Encryption-in-transit monitoring — alerts on PHI transmitted via unencrypted protocols |
| §164.314(a)(2)(i) | Business Associate Contracts | Third-party access monitoring — BA system connections baselined and monitored for anomalous PHI access |
| §164.404 | Breach Notification to Individuals | 60-day notification countdown, affected individual count tracking, notification letter pre-population from incident data |
| §164.406 | Notification to Media | 500+ individual threshold tracking per state — automated alert when breach size crosses media notification threshold |
| §164.408 | Notification to Secretary (HHS/OCR) | Annual reporting log compiled from case records — OCR breach notification form pre-populated |
Evidence and audit export path
OCR breach report export
One-click export generating a pre-populated HHS OCR breach notification form from incident data. Includes: breach discovery date, affected individual count by state, PHI categories exposed, and safeguards in place at time of breach.
HIPAA audit log package
Per-incident evidence package containing all §164.312(b) audit logs relevant to the incident — timestamped, entity-attributed, and tamper-evident. Formatted for attorney review and OCR investigation response.
Continuous monitoring report
Monthly report documenting §164.308(a)(1)(ii)(D) information system activity review — covering all monitored systems, anomalies detected, alerts fired, and cases opened in the period.
Certification and audit status
ManySignal operates in HIPAA-eligible AWS infrastructure. Our SOC 2 Type II report (available under NDA at [email protected]) covers the security controls that underpin HIPAA compliance. BAA is available at /legal/baa. ManySignal's HIPAA compliance programme is reviewed annually by an independent HIPAA consultant.
Shared responsibility
ManySignal is responsible for:
- Security of the ManySignal platform infrastructure
- BAA obligations assumed as a Business Associate
- Accuracy and completeness of monitoring evidence
- Encryption in transit and at rest within the platform
- Staff access controls and training
Customer (Covered Entity / BA) is responsible for:
- Configuring ManySignal for their specific environment and PHI scope
- Acting on alerts and implementing recommended remediation
- Executing breach notification obligations under HIPAA
- Maintaining HIPAA security policies and workforce training
- Risk analysis and risk management programme (§164.308(a)(1))
HIPAA compliance — auditor questions
Does ManySignal sign a Business Associate Agreement (BAA)?
Yes. ManySignal executes BAAs with all healthcare customers before any PHI is processed. The BAA is available at /legal/baa. Healthcare customers are deployed in HIPAA-eligible AWS infrastructure with AES-256 encryption at rest and TLS 1.3 in transit. PHI is never used for AI model training or shared with third parties.
How does ManySignal address the HIPAA Breach Notification Rule specifically?
HIPAA's Breach Notification Rule (§164.400-414) requires covered entities to notify affected individuals within 60 days of discovering a breach, notify HHS/OCR, and — for breaches affecting 500+ residents in a state — notify prominent media. ManySignal's case management starts the 60-day countdown at discovery, tracks the affected individual count by state, and triggers media notification reminders when state thresholds are crossed.
Which EHR systems does ManySignal integrate with for §164.312(b) audit control coverage?
ManySignal has native integrations for Epic (via Clarity audit tables and Epic Syslog Audit Trail), Oracle Health/Cerner (Audit Log API), Meditech Expanse (syslog + CEF), and Allscripts/Veradigm. For other EHR platforms, the universal log pipeline ingests syslog and CEF formats. Coverage gaps — EHR platforms not yet connected — are reported in the audit control coverage dashboard.
How does ManySignal provide evidence for HIPAA §164.308(a)(1)(ii)(D) — Information System Activity Review?
§164.308(a)(1)(ii)(D) requires regular review of information system activity — audit logs, access reports, and security incident tracking reports. ManySignal automates this by: continuously analysing all logs (not just sampling), flagging anomalies in real time, and generating weekly activity summary reports that can serve as evidence of the required periodic review. Audit packages are time-stamped and tamper-evident.
What is ManySignal's shared responsibility model for HIPAA?
ManySignal is responsible for: the security of the ManySignal platform infrastructure, the BAA obligations it assumes as a Business Associate, and the accuracy of the monitoring evidence it provides. The Covered Entity (or Business Associate customer) is responsible for: configuring ManySignal correctly for their environment, acting on the alerts and evidence ManySignal provides, implementing the remediation actions recommended in investigation reports, and executing their breach notification obligations.
Request the BAA and start a HIPAA deployment
Execute the BAA, connect your EHR audit logs, and have HIPAA §164.312(b) audit controls evidenced within your first week.