Compliance · Hub · 1440
Compliance & Governance
Operations · Compliance Hub · Aetna MA HMO + VA Region 8
Module 27 · Compliance & Governance · CGAE

Compliance & Governance

Unified compliance posture across HIPAA · FedRAMP High · FIPS 140-3 · OIG · CAIG AI Governance · ONCLAVE Zero Trust
Overall Compliance Posture
94%
SSP Coverage
418 / 444 controls implemented · +12 since Q1
Open P1 Findings
3
2 due in <14d
3PAO Days Out
42
Coalfire · Aug 2026
AAT Events · 24h
14.2K
100% chained
Bias Monitor
0.94
Within tolerance
HIPAA Security Rule
Pass
100%
45 CFR §164.312
Last review: Apr 14 · BAA active
FedRAMP High
In Prep
89%
395 / 444 controls
3PAO assessment: 42d
FIPS 140-3 Crypto
Validated
100%
CMVP modules · TLS 1.3
Azure Gov FIPS mode on
OIG Audit Defense
3 gaps
96%
RPM/CCM evidence
3 patients missing IC
CAIG AI Governance
Active
100%
DEE · AAT · BFM live
21 OQ items resolved
ONCLAVE Zero Trust
Phase 1
68%
SC-7/SC-8 microseg
DHA ATO reciprocity req
Control Family Coverage FedRAMP High · NIST 800-53 Rev 5 · 17 families
Full SSP →
AC
Access Control
ORAK RBAC · MFA · session mgmt · SSO
25/25
100%
AU
Audit & Accountability
CAIG AAT · immutable hash chain · Splunk forwarding
16/16
100%
SC
System & Comm Protection
SC-7/SC-8/SC-28 · ONCLAVE microseg · TLS 1.3 · FIPS
42/47
89%
SI
System & Information Integrity
SIEM · WAF · EDR · IDS/IPS · ConMon scanning
21/23
91%
CM
Configuration Management
Configurator · ORAK change control · CAIG attestation
15/16
94%
IR
Incident Response
PagerDuty · runbooks · ISSO escalation chain
10/12
83%
CP
Contingency Planning
DR runbooks · multi-region failover · BCP test
9/13
69%
AI
AI Governance (CAIG)
Custom: DEE · AAT · BFM · OQ review · model registry
21/21
100%
Open Findings — POA&M Plan of Action & Milestones · 8 active
Full POA&M →
P1
SC-8(1) — 2 home gateways awaiting Onclave certificate renewal
VIDA RPM rural patients · RUCA 9 · CAIG AAT: ONCLAVE_ZT/CERT_EXPIRING
Due 6d
P1
CP-9 — DR multi-region runbook not exercised in past 12 months
Last drill: Apr 2025 · BCP testing required for FedRAMP High
Due 13d
P1
OIG — 3 RPM patients missing interactive comm. evidence in 99457 BRR
Eleanor M · James C · Donald P · period close 23d
Due 23d
P2
IR-3 — Tabletop exercise overdue (Q1 cycle)
Quarterly cadence · last conducted Dec 2025 · ISSO + CIRT
Due 21d
P2
SI-2 — 12 medium-severity CVEs unpatched on CCPR cluster
ConMon scan May 06 · Tenable findings · 30-day SLA
Due 18d
P2
AC-2(3) — Stale account review · 8 inactive coordinator accounts >90d
ORAK auto-flag · disable required · attestation log
Due 30d
P3
PL-2 — System Security Plan v1.4 needs annual refresh
Last revision: May 2025 · 7 control statements changed
Due 60d
P3
SA-9 — Third-party SaaS dependency audit pending refresh
14 vendors in scope · CONUS data residency check
Due 45d
CAIG · AI Governance
DEE · AAT · BFM · 24h window
8.4K
DEE explanations
100%
AAT chained
0.94
BFM parity
Bias Monitor green ✓ — Channel-selection demographic parity at 0.94 (target ≥0.85). Zero alerts in past 30d. Doppler bucket distribution by race/ethnicity within 4pp of population baseline.
CAIG AAT · Live Audit Trail Immutable hash-chained · last 8 events
● Streaming
14:42:18 LAT.MOV
Lateral movement blocked — service ppaf-portal-7d8 → ccpr-write rejected by Onclave Orchestrator policy
…f4a2
14:38:02 AI.DEC
Doppler EMERGENT assignment for MRN 47281-A · DEE explanation: LACE+ ≥15 post-discharge
…b91e
14:30:55 CERT
Onclave certificate issued · device dexcom-G7-aetnaMR-014 · microsegment scope: mdrx-cgm
…2c7d
14:22:31 CFG
Configurator update · LACE+ trigger threshold 15 → 13 · user dburns@aetna.com · effective immediately
…9f01
14:18:14 AI.DEC
IRIS background task · auto-populate post-discharge plan · patient: Eleanor Markham · 3 meds + 1 fu
…0e84
14:09:45 ACCESS
State Health Authority RHTP read · View 9 export · 248K rows · scope: NM-rural-roster
…7b39
14:01:08 DATA
FHIR write-back · 32 Observation resources to Epic · CFW · BIM 99454 evidence
…4d62
13:58:22 CERT
Cert revoked · device a&d-bp-aetnaMR-082 · reason: device returned to inventory · auto-replacement queued
…e15a
Certifications & Accreditations Active · expiry-tracked
HITRUST CSF r2 i1
Issued Jul 2025 · Expires Jul 2027
Active
SOC
SOC 2 Type II
Period: Jan–Dec 2025 · Auditor: Schellman
Active
VA
VA ATO Ready
Sponsor: Valor Healthcare · IHT 2.0
Ready
FR
FedRAMP High ATO
3PAO: Coalfire · Assessment Aug 2026
In Prep
DHA
DHA Reciprocity (via ONCLAVE)
Onclave DHA ATO Jul 2024 · Reciprocity eval
Pending
FIPS
FIPS 140-3 Validation
CMVP modules · Azure Gov + AWS GovCloud
Validated