FeaturesCompliance Reports

HIPAA Evidence Report

HIPAA Security Rule Technical Safeguards evidence under 45 CFR § 164.312 — audit controls, access authorization, integrity controls, and transmission security.

Overview

The HIPAA Security Rule (45 CFR Part 164) requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect electronic Protected Health Information (ePHI). The Technical Safeguards (§ 164.312) govern access controls, audit controls, integrity, and transmission security for systems that create, receive, maintain, or transmit ePHI.

Koalr's HIPAA report generates evidence for four Technical Safeguard requirements addressable by engineering change management data. The report is designed for delivery to your HIPAA Security Officer or for OCR audit response.

Controls covered

§164.312(b) — Audit Controls

Standard: Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.

Koalr evidence: Koalr maintains a complete, tamper-evident audit log of every code change, reviewer, approver, risk score, and signal breakdown for the audit period. The export provides a machine-readable record suitable for OCR review.

§164.312(a)(2) — Access Authorization

Implementation specification: Implement policies and procedures for granting access to ePHI, for example through access to a workstation, transaction, program, process, or other mechanism.

Koalr evidence: CODEOWNERS rules define which individuals are authorized to approve changes to protected system paths. Every merge is verified; unauthorized merges to ePHI-adjacent code paths are detected and logged.

§164.312(c)(1) — Integrity Controls

Standard: Implement policies and procedures to protect ePHI from improper alteration or destruction.

Koalr evidence: Mandatory peer review ensures every change to production systems handling ePHI is verified by a second authorized party before deployment. Changes merged without review are tracked and surfaced as integrity control exceptions.

§164.312(e)(2) — Transmission Security

Implementation specification: Implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic communications network.

Koalr evidence: Automated deploy risk scoring flags high-risk changes — including DDL migrations, blast-radius changes, and changes to ePHI-adjacent services — before they are deployed to systems handling ePHI. Risk-assessed changes are documented in the evidence log.

Report output

  • Dark navy cover page prepared for "HIPAA Security Officer / OCR Compliance Audit"
  • Executive summary with six KPI tiles
  • Per-control detail blocks with EVIDENCED / PARTIAL / NOT_COVERED status badges and evidence counts
  • Change log table with approval, CODEOWNERS, and risk columns
  • Page number footer with CONFIDENTIAL marking
  • Machine-readable CSV export

Generating a report

  1. Navigate to ComplianceHIPAA
  2. Select your reporting period (typically the 12 months preceding your audit or risk assessment)
  3. Click Download evidence package (PDF) or Export CSV

Scope considerations

HIPAA Technical Safeguards apply to systems that create, receive, maintain, or transmit ePHI. When generating reports:

  • Connect only the GitHub repositories for systems in your HIPAA boundary
  • If your production and non-production repositories are separate Koalr organizations, generate the report from your production organization
  • Koalr's repository filter (available in the report UI) lets you scope the evidence to specific repositories if your organization spans both in-scope and out-of-scope systems

HIPAA Security Officer review notes

  • The PDF cover page names "HIPAA Security Officer / OCR Compliance Audit" in the Prepared For field
  • Koalr's evidence addresses the Technical Safeguards category only — pair with your Administrative Safeguard policies and Physical Safeguard documentation for a complete HIPAA Security Rule package
  • For Business Associate Agreements (BAAs): Koalr processes GitHub webhook data (PR metadata, reviewer names, repository names). Review whether Koalr qualifies as a Business Associate under your organization's data flow analysis

Integration requirements

  • GitHub (required) — provides all change management and access control data

Disclaimer

This report is designed to support HIPAA Technical Safeguard evidence collection for the covered implementation specifications. It does not constitute a formal HIPAA compliance assessment. Engage a qualified HIPAA consultant or legal counsel for your organization's HIPAA compliance program.