Built for covered entities and business associates: score your controls against the HIPAA Security, Privacy and Breach Rules and the HITECH obligations layered on top of them, see your OCR and breach exposure in dollars, and leave with a remediation roadmap your board and your cyber insurer will both understand.
CyberSights is the gap-assessment platform we use with our own healthcare clients — built for privacy and security officers who answer to a board and a compliance committee, not just an auditor.
HITECH layers breach notification, business-associate liability and expanded patient rights on top of the HIPAA rules. Select both — overlapping controls are scored once and credited to each. No duplicate work.
Fully Met, Partially Met, Not Met. Every control shows its complete requirement text, its 45 CFR citation and the determination statements an assessor works through.
Gaps become financial exposure using real penalty models — OCR civil money penalty tiers, HITECH breach-response cost priced per affected record, and PCI card-brand fines. The HITECH model even credits 12 months of Recognized Security Practices, the way HHS is required to.
Model remediation before you fund it: flip controls to a target state and watch risk, compliance and penalty exposure move.
Every gap flows into a quarterly Plan of Action & Milestones with owners, costs and projected residual risk — the risk management plan §164.308(a)(1)(ii)(B) actually asks for. Exports to CSV and PDF.
Five branded PDF report types — executive, technical, compliance, remediation, risk register — generated in one click, and ready for your six-year documentation file.
A guided, hands-on version of the real product — preloaded with a realistic health-system assessment so every chart has numbers in it. No PHI involved, ever.
Tell us a little about your organization and we'll send your demo credentials — usually within one business day.