Skip to content
Compliance · HIPAA

HIPAA controls and the receipts that map evidence to them.

Every HIPAA control Déjà's control table lists, with the receipt types that map evidence to each. Where none does, the row says so: that control is evidenced outside Déjà. References and titles are from 45 CFR 164.308, the Security Rule's administrative safeguards.

3 of the 4 HIPAA controls listed here have a receipt type that maps evidence to them. The other 1 is evidenced outside Déjà.

01 · Coverage

What a receipt covers, and what is not.

3 of the 4 HIPAA controls listed here have a receipt type that maps evidence to them. The other 1 is evidenced outside Déjà.

The Security Rule's administrative safeguards, 45 CFR 164.308, only, and of those only the standards listed here: the rest of 164.308 is evidenced outside Déjà, and is not listed. The physical safeguards (164.310), the technical safeguards (164.312) and the organisational and documentation requirements (164.314 and 164.316) are not mapped.

Error events and pull-request diffs can carry patient data. What Déjà keeps from each, what it scrubs and what it does not, and what does not fit a health system yet: Healthcare and health tech.

Edition
45 CFR 164.308, the Security Rule's administrative safeguards
Controls listed
4
A receipt type maps evidence
3
Evidenced outside Déjà
1

A receipt is evidence for a control, never the whole of it: the rest of each control is tested outside Déjà.

02 · Every control

HIPAA, in the standard's own words.

Administrative safeguards

3 of 4 with a receipt type

  • 164.308(a)(1)Security management processEvidenced by R1R1-L
  • 164.308(a)(5)Security awareness and trainingEvidenced outside Déjà
  • 164.308(a)(6)Security incident proceduresEvidenced by R1R1-L
  • 164.308(a)(8) (evidenced only by an R2)EvaluationEvidenced by R2

† 164.308(a)(8) gets evidence from a resolution receipt (R2) only. Most organisations get no resolution receipt (R2) yet: Déjà issues one only for an incident with an attribution receipt (R1), once 48 hours have passed since a user marked it resolved, and only if every gate then has a reading, which takes connected source control, Sentry, and Datadog (with a metrics read key) or New Relic. Until one is issued, it gets no evidence from Déjà.

03 · The receipt types

The evidence, and what each one is.

The receipt types that map evidence to at least one HIPAA control. The fields each one carries in its signed or hashed bytes are listed under receipt types.

  • R1Signed

    Attribution Receipt

    Incident attributed to a causal PR with CCS above threshold.

    Maps evidence to 164.308(a)(1) and 164.308(a)(6) · what R1 records

  • R1-LSigned

    Low-Confidence Attribution

    Candidate PRs identified but CCS in the low-confidence range (0.60–0.79).

    Maps evidence to 164.308(a)(1) and 164.308(a)(6) · what R1-L records

  • R2Signed

    Resolution Receipt

    An incident marked resolved, with its five gate scores and whether they passed. References its R1.

    Maps evidence to 164.308(a)(8) · what R2 records

04 · How an auditor checks it

Checked on the auditor's own machine.

An audit engagement opened for HIPAA covers the receipt types that map evidence to its controls: R1, R1-L and R2. The auditor gets a token link, sees the receipts in scope, downloads a signed period report and checks it on their own machine with dsr-verifier-cli, against Déjà's published keys.

The period report packs R1 and R1-L. R2 is listed in the auditor's portal and not packed.

Déjà's integrity monitor, every 15 minutes, checks R1 and R2; it does not check R1-L.

05 · Limits

What Déjà does not do for you.

Determine root cause
An attribution receipt (R1) records the change Déjà's scoring tied a failure to, and the score it reached. That is evidence for an investigation, not its finding.
Certify a control
A receipt maps evidence to a control. Whether the control is designed and operating effectively is the auditor's opinion, and the rest of each control is tested outside Déjà.
Attest
Déjà issues no attestation report or audit opinion about your firm. Déjà's own attestation status is on Security & trust.

Déjà supplies a record of what connected systems reported and what changed. It does not determine root cause, file regulatory reports, or discharge any obligation under any regime: those remain with your named accountable individuals.

Walk the list with us, control by control.

Bring your control matrix. We will say which rows a receipt maps evidence to, and which ones it does not.