Catalog of representative security and compliance controls mapped across HIPAA, SOC 2, and HITRUST frameworks. Evidence is linked where available through the Trust Automation pipeline.
CUBE OneCare maintains active compliance programs across three industry-recognized healthcare and security frameworks. Controls are cross-mapped to eliminate duplicate evidence collection.
Administrative, physical, and technical safeguards required under the Health Insurance Portability and Accountability Act. Covers Privacy Rule, Security Rule, and Breach Notification Rule requirements.
54 controls mapped
Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy. Readiness evidence is organized for independent CPA review.
87 controls mapped
Common Security Framework harmonizing ISO 27001, NIST 800-53, HIPAA, and PCI DSS requirements. CUBE OneCare tracks HITRUST readiness evidence before any validated assessment claim.
156 controls mapped
Controls are organized into functional categories aligned with healthcare-specific threat models and regulatory requirements. Each category has a designated control owner and quarterly review cadence.
Role-based access control (RBAC), multi-factor authentication, session management, and least-privilege enforcement. Includes patient-consent-gated data access, break-glass audit trails, and SCIM-provisioned identity lifecycle management.
38 controls in category
AES-256-GCM at rest and TLS 1.3 in transit, provided by the hosting platform. PHI fields use field-level encryption at the application layer. Keys are held in the platform's secret store; there is no customer-managed KMS rotation schedule today.
24 controls in category
Insert-only audit logs for data access and mutation events, recording actor identity, timestamp, resource ID, action type, and originating IP. Retention: 7-year policy. Hash chaining is implemented in the enterprise audit-log module, which is not enabled in the running product; there is no WORM storage.
19 controls in category
Documented incident response plan with defined severity classifications (P0–P3), automated paging, war-room protocols, and post-incident review (PIR) process. Regulatory notification within 60 minutes for confirmed breaches.
16 controls in category
Current readiness results across representative mapped controls. Status is refreshed as evidence is collected, with high-risk controls reviewed on an accelerated cadence.
Control evidence is current for internal readiness review. External auditor validation remains the source of formal assurance.
Last evaluated: 2026-02-26 04:00 UTC
Control evidence is approaching staleness threshold or minor configuration drift detected. Remediation ticket auto-generated.
Last evaluated: 2026-02-26 04:00 UTC
Control evidence did not meet the internal readiness threshold in the latest evaluation cycle. A remediation plan is tracked with an SLA.
Last evaluated: 2026-02-26 04:00 UTC
Controls are evaluated at different frequencies based on risk classification and regulatory requirements. Evidence is automatically collected and linked to the corresponding control in the evidence vault.
| Frequency | Controls | Examples |
|---|---|---|
Continuous | 147 | Encryption in transit, MFA enforcement, firewall rules, WAF signatures |
Daily | 112 | IAM policy reviews, key rotation status, backup verification, certificate expiry |
Quarterly | 38 | Vendor risk reassessment, access recertification, DR tabletop exercises, policy updates |
Evaluation results are retained according to the applicable evidence-retention schedule. Evidence packages are compiled for external auditor access through the Trust Automation platform.