Risk analysis
45 CFR 164.308(a)(1)(ii)(A)Conduct an accurate and thorough assessment of the risks to the confidentiality, integrity and availability of electronic protected health information.
Platform risk assessment maintained in the HIPAA compliance module and reviewed at least annually and after any material architectural change. Automated security scanning runs continuously against the hosted database and application.
Your responsibility: Record your own site-level and workforce risk assessment against this register.
Workforce security and authorisation
45 CFR 164.308(a)(3)Ensure workforce members have appropriate access to ePHI and prevent access by those who do not.
Every record is scoped to a single company workspace with row-level security. Roles (owner, admin, member) and, in EvidenceOS, per-site membership limit access to the participants a user is responsible for.
Your responsibility: Keep the user list current and remove leavers on their last working day.
Information access management — minimum necessary
45 CFR 164.308(a)(4)Restrict access and disclosure of ePHI to the minimum necessary for the purpose.
Direct identifiers are detected and removed by default at import; clinical records are coded by subject identifier. Cross-product transfers (for example a registry complaint sent to QualityOS) carry coded, minimum-necessary data only.
Security awareness and training
45 CFR 164.308(a)(5)Implement a security awareness and training programme for all workforce members.
HIPAA awareness training is tracked as a controlled training record with assignment, completion and effectiveness evidence.
Your responsibility: Assign the HIPAA awareness curriculum to every workforce member with access to the console.
Security incident procedures
45 CFR 164.308(a)(6)Identify, respond to and document security incidents and their outcomes.
Security findings are triaged in an append-only security register with disposition, rationale and the clearing user recorded.
Contingency plan
45 CFR 164.308(a)(7)Establish data backup, disaster recovery and emergency mode operation plans.
Managed Postgres with point-in-time recovery and automated daily backups; object storage is replicated. Recovery objectives are documented in the contingency plan record.