Compliance Engineering Platform

HIPAA Gap Remediation Engine

Live
Healthcare security
HIPAA Macie AWS

A single unresolved HIPAA gap can trigger fines ranging from $100 to $50,000 per violation category. Most organizations discover these gaps during audits, after the exposure has already occurred. This engine finds and closes them before they become findings.

Built on a deliberately non-compliant patient intake API. Every gap identified here maps to a real HIPAA Security Rule safeguard. Every remediation action fires automatically, logs to the evidence vault, and notifies the resource owner.

Built by a clinician
Over a decade in radiology, MRI, CT, and emergency departments. PHI is not an abstract compliance concept. It is a patient's cancer diagnosis, a psychiatric history, an HIV status. The controls on this page exist to protect that.
14
HIPAA control gaps identified and closed
$0
Audit findings. Gaps closed before review.
100%
PHI exposure attempts blocked automatically

Select a misconfigured scenario and watch the engine detect the HIPAA gap, map it to a Security Rule safeguard, and fire the remediation action.

Scanning with Amazon Macie...


  • 01
    Macie scans continuously for PHI
    Amazon Macie runs automated scans across all S3 resources, detecting PHI patterns including SSNs, MRNs, dates of birth, and clinical notes. Findings are written to Security Hub within minutes of detection.
  • 02
    SCPs block exposure before it happens
    Service Control Policies prevent any S3 bucket containing PHI from being made public, regardless of who requests it. The block fires at the AWS API level, before any object is exposed.
  • 03
    Lambda fires remediation automatically
    Every Macie finding triggers a Lambda function. High-severity findings get immediate automated remediation: public ACLs removed, encryption enforced, resource owner notified via SES. No human triage required.
  • 04
    Every action logged to the evidence vault
    CloudTrail captures every access event. Every remediation action writes a signed, timestamped record to the S3 Object Lock vault. Auditors get a complete chain of custody for every finding and its resolution.

Amazon Macie Service Control Policies Lambda Security Hub CloudTrail S3 Object Lock EventBridge SES
Part of the Compliance Engineering Platform, extended from the HIPAA gap remediation capstone built on the CGE-P patient intake API. Source in healthcare-compliance-as-code.

Jul 6, 2026 Interactive demo launched. Three HIPAA gap scenarios live with automated remediation flow.
Jul 6, 2026 SES notification wired to remediation Lambda. Resource owners now alerted within 60 seconds of a finding.
Jul 5, 2026 CloudTrail evidence export added. Every remediation action now writes a signed record to the Object Lock vault.
Jul 3, 2026 All 14 HIPAA Security Rule gaps mapped and closed. Gap analysis document added to repo.