Skip to content

Improve HIPAA addressable and resilience evidence#1236

Open
Peter7896 wants to merge 1 commit into
UnitOneAI:mainfrom
Peter7896:peter7896/hipaa-addressable-resilience
Open

Improve HIPAA addressable and resilience evidence#1236
Peter7896 wants to merge 1 commit into
UnitOneAI:mainfrom
Peter7896:peter7896/hipaa-addressable-resilience

Conversation

@Peter7896
Copy link
Copy Markdown

Summary

  • add HIPAA addressable-specification decision evidence so missing encryption is evaluated as Conditional Compliance only when risk rationale, equivalent alternatives, approval, and review evidence are documented
  • add destructive-malware backup resilience checks for immutable/offline copies, backup-admin separation, restore testing, and wiper scenario evidence
  • expand remote-work physical safeguard gates and add HITECH recognized security practice / safe-harbor evidence mapping
  • add BAA supply-chain visibility checks for right-to-audit/assurance, subcontractor disclosure, breach-notice SLA, return/destruction, and downstream flowdown tracking

Scope

This addresses #1106 and is intentionally complementary to #1089: it does not rework the BAA inventory flow, but adds granular evidence gates requested in the review.

Closes #1106

Validation

  • git diff --check (only existing Windows LF-to-CRLF warning)
  • verified markdown code fence count is even (8)
  • verified issue-specific markers for Conditional Compliance, destructive malware resilience, remote work safeguards, HITECH safe-harbor evidence, and right-to-audit supply-chain checks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] hipaa-review: add 2026 state-sponsored wiper threats and granular BAA evidence gates

1 participant