Skip to content
HIPAA · 45 CFR Part 164

Your HIPAA controls,
continuously mapped.

Blackfyre maps multi-cloud and on-prem findings to the HIPAA Security Rule controls — administrative, physical, and technical safeguards — with weighted scoring and a tamper-evident evidence vault. It scans configuration posture, never the ePHI itself.

Coverage · illustrative

113

HIPAA controls

9

Frameworks

3 + on-prem

Clouds

Free

Apache-2.0

The standard

What the HIPAA Security Rule covers.

US healthcare rule protecting electronic PHI via administrative, physical, and technical safeguards.

§164.308

Administrative safeguards

Security management, workforce security, access management, training, contingency planning, and evaluation.

§164.310

Physical safeguards

Facility access, workstation use and security, and device / media controls.

§164.312

Technical safeguards

Access control, audit controls, integrity, authentication, and transmission security.

§164.314

Organizational requirements

Business-associate contracts and requirements for group health plans.

§164.316

Policies & documentation

Written policies and procedures, plus the required retention of documentation.

Blackfyre maps findings to the 113 HIPAA controls it tracks · one of 9 frameworks in the platform.

How it works

From scan to audit-ready evidence.

The same pipeline that scores your HIPAA posture also produces the artifacts an auditor asks for — no spreadsheet reconciliation. Blackfyre assesses and evidences posture; it never claims a certification on your behalf.

  1. 01 · Scan

    55 auditors enumerate real resources across AWS, Azure, GCP and on-prem — plus Prowler and Checkov / Semgrep / Bandit as containerised scanners.

  2. 02 · Map

    Every finding maps to the 113 HIPAA controls it affects. A single misconfiguration can touch several controls at once — the mapping records each one.

  3. 03 · Score

    Weighted per-framework scoring rolls findings into a posture score you track as your team ships fixes — no spreadsheet reconciliation.

  4. 04 · Evidence

    Each result is written to a tamper-evident vault — SHA-256 integrity hash, S3 Object Lock, versioning — ready to hand to an auditor.

Illustrative vault record · shows the shape, not real data

Evidence vaultillustrative
integrity
sha256:d4a1…9c02
control
§164.308
storage
S3 Object Lock · versioned
pii
AES-256-GCM · field-encrypted
verify
auditor recomputes the hash

55

Auditors

113

HIPAA controls

3 + on-prem

Clouds

SHA-256

Tamper-evident

Scope & honesty

Blackfyre's scanners collect the minimum posture data needed to assess a control — configuration and metadata. They never read ePHI, customer records, or business content. That data-collection boundary is documented, not just asserted.

Open source · Apache-2.0

HIPAA, mapped and evidenced.

Blackfyre is Apache-2.0 — self-host it free forever, or try the hosted option (early access). First findings and mapped HIPAA evidence in about fifteen minutes locally. It assesses and evidences your posture; it does not certify compliance.

113

HIPAA controls

9

Frameworks

55

Auditors

Free

Apache-2.0