Interactive Demo · Healthcare Edition

Protect PHI.
Prove compliance.

Built for covered entities and business associates: score your controls against the HIPAA Security, Privacy and Breach Rules and the HITECH obligations layered on top of them, see your OCR and breach exposure in dollars, and leave with a remediation roadmap your board and your cyber insurer will both understand.

Access is by invitation — request it above and we'll send you credentials.
Built for healthcare HIPAAHITECHNIST CSF 2.0HHS 405(d) alignedPCI DSS SOC 2ISO 27001CIS v8GDPRISO 27701

One assessment. HIPAA, HITECH and everything your partners ask for.

CyberSights is the gap-assessment platform we use with our own healthcare clients — built for privacy and security officers who answer to a board and a compliance committee, not just an auditor.

HIPAA and HITECH, scored once

HITECH layers breach notification, business-associate liability and expanded patient rights on top of the HIPAA rules. Select both — overlapping controls are scored once and credited to each. No duplicate work.

Plain-language scoring

Fully Met, Partially Met, Not Met. Every control shows its complete requirement text, its 45 CFR citation and the determination statements an assessor works through.

Risk in dollars

Gaps become financial exposure using real penalty models — OCR civil money penalty tiers, HITECH breach-response cost priced per affected record, and PCI card-brand fines. The HITECH model even credits 12 months of Recognized Security Practices, the way HHS is required to.

What-If simulator

Model remediation before you fund it: flip controls to a target state and watch risk, compliance and penalty exposure move.

POA&M roadmap

Every gap flows into a quarterly Plan of Action & Milestones with owners, costs and projected residual risk — the risk management plan §164.308(a)(1)(ii)(B) actually asks for. Exports to CSV and PDF.

Board-ready reports

Five branded PDF report types — executive, technical, compliance, remediation, risk register — generated in one click, and ready for your six-year documentation file.

What's in the demo

A guided, hands-on version of the real product — preloaded with a realistic health-system assessment so every chart has numbers in it. No PHI involved, ever.

  • A 3-minute guided tour A spotlight walkthrough of the full workflow: frameworks → scoring → findings → dashboard → simulator → POA&M → reports.
  • Realistic sample data A pre-scored community health system assessment — documented findings, real evidence artifacts (risk analysis, BAA register, EHR access reviews) and remediation plans. Explore freely or reset any time.
  • 6 frameworks unlocked HIPAA, HITECH, NIST CSF 2.0, PCI DSS, SOC 2 and ISO 27001, each with a representative sample of its controls. The full catalog is visible so you can see the breadth.
  • Nothing leaves your browser The demo is fully client-side — no sign-up forms, no tracking, no data collected.

Getting in takes a minute

1
Request access Use the request form below — tell us who you are and whether you're a covered entity or a business associate.
2
Receive your credentials We'll reply with a login for the demo (and can schedule a live walkthrough if you'd like one).
3
Take the tour Hit "Open the demo", sign in, and the guided tour starts automatically.

Request demo access

Tell us a little about your organization and we'll send your demo credentials — usually within one business day.

We only use this to set up your demo access — no mailing lists, no sharing.