Skip to main content
New: Vulkro Cloud for Salesforce, a hosted workspace for your team. Available by invitation: register your interestView docs

HIPAA

Profile name: hipaa

Vulkro covers the technical safeguards of the HIPAA Security Rule, Sec.164.312. Administrative and physical safeguards (Sec.164.308, Sec.164.310) are out of scope.

Run it​

vulkro compliance . --profile hipaa

High-traffic mappings​

Vulkro findingHIPAA Security Rule
BrokenAuthenticationSec.164.312(d) Person or Entity Authentication
BrokenObjectLevelAuthSec.164.312(a)(1) Access Control
Hardcoded secretSec.164.312(a)(2)(i) Unique User ID
Weak cryptoSec.164.312(a)(2)(iv) Encryption and Decryption
Insecure transmissionSec.164.312(e)(1) Transmission Security
Insecure loggingSec.164.312(b) Audit Controls
PHI exposureSec.164.312(c)(1) Integrity

PHI detection​

The privacy engine detects PHI-shaped fields in request and response shapes:

  • medical_record_number, mrn, patient_id
  • diagnosis, icd10, icd_code
  • prescription, rx
  • dob + name co-occurrence
  • Biometric IDs (fingerprint_hash, face_id)

Findings on these fields get HIPAA control citations, even when the underlying issue is generic (for example, "PII passed to logger"). The desktop console's Privacy tab shows these as a HIPAA-specific view.

Audit packaging​

vulkro report . --profile hipaa -o hipaa-report.html

This produces a single-page HTML report, ready for a covered entity's risk-analysis file.

Vulkro is a product of Reveriext.

reveriext.com

Visit Reveriext