Compliance / US 45 CFR §164
HIPAA
Safeguards for protected health information. When agents touch PHI, §164.312(b) audit controls and §164.308(a)(1)(ii)(D) log review become regulator evidence.
Evidence Kaldros produces
Each item is generated from the chain for the selected window and included in the framework-specific evidence pack. Items below are illustrative — the full control map is in the documentation.
- ▸ Audit controls (§164.312(b))
- ▸ Information system activity review (§164.308(a)(1)(ii)(D))
- ▸ Breach notification timelines
- ▸ BAA coverage for sub-processors