Skip to main content
ForensicShield(go to home page)

HIPAA Compliance Map

Every HIPAA requirement that applies to ForensicShield, what it means in plain language, and exactly how we meet it.

Zero-Exposure ArchitecturePHI never leaves AWS Bedrock
Encrypted at Every LayerAES-256-GCM with AWS KMS envelope keys
Tamper-Proof Audit TrailAppend-only logs, 7-year retention
BAA RequiredSigned before any PHI upload

What is HIPAA compliance?

HIPAA (Health Insurance Portability and Accountability Act) is a federal law that protects sensitive patient health information. When forensic professionals upload evaluation reports containing patient data — names, diagnoses, criminal histories, clinical findings — that data is Protected Health Information (PHI).

ForensicShield processes PHI, which means we must comply with the HIPAA Security Rule (how we protect the data technically), the HIPAA Privacy Rule (how we handle and limit use of the data), and the Breach Notification Rule (what happens if something goes wrong).

Each requirement below is either R Required — must implement — or A Addressable — must implement or document why an alternative is equivalent.

All 36 requirements, mapped.

Implemented
RRequired
AAddressable

ForensicShield is designed to meet the requirements of the HIPAA Security Rule (45 CFR Part 164, Subpart C), the HIPAA Privacy Rule (45 CFR Part 164, Subpart E), and the Breach Notification Rule (45 CFR Part 164, Subpart D). Architecture and compliance status as of March 2026.

Zero-Exposure ArchitecturePHI never leaves AWS Bedrock
Encrypted at Every LayerAES-256-GCM with AWS KMS envelope keys
Tamper-Proof Audit TrailAppend-only logs, 7-year retention
BAA RequiredSigned before any PHI upload
HIPAA Compliant
AES-256
TLS 1.2/1.3

Your data deserves this level of protection.

Try ForensicShield on a sample report — no upload required. Then run your own.

Run a Free Sample Analysis →

14-day free trial · 2 reports included (1 sample + 1 of your own) · A payment method is collected for identity verification — your card will not be automatically charged when the trial ends · HIPAA compliant