Create administrative policies and controls by answering plain-english questions. These policy controls are connected into Dash technical controls and monitoring.
Set security controls across all of your AWS cloud services. So you can easily manage HIPAA compliance across your entire cloud environment.
Dash continuously scans and monitors all services. Teams receive security alerts and remediation for all potential HIPAA compliance issues.
Dash alerts you when there are issues related to cloud security groups, available ports and other network concerns.
Dash notifies you when your team utilizes AWS services that are out of the realm of Amazon’s Business Associates Agreement (BAA).
Dash provides alerts and recommendations for resolving issues with unencrypted cloud services.
Dash gives your team recommendations for AWS audit log configuration, so you can track system integrity.
Dash provides recommendations for backup and disaster recovery settings that your team should implement in your cloud environment.
Dash notifies you whenever your organization must conduct risk assessments, reviews, or other tasks related to Dash Administrative Policies.
Dash configures, monitors, and remediates compliance issues within your organization’s cloud services. Below are some examples of HIPAA security controls that are enforced and monitored for AWS services:
Unencrypted EBS Volumes – 164.312(a)(2)(iv) Encryption and Decryption
Security Groups With All Ports Open To Public – 164.312(c)(1) Integrity + 164.312(e)(1) Transmission Security
Security Group Allows Unrestricted Network Traffic – 164.312(c)(1) Integrity + 164.312(e)(1) Transmission Security
Security Groups Opens DB Ports To Public – 164.312(c)(1) Integrity
Security Groups Opens SSH, FTP, SMTP Ports To Public – 164.312(c)(1) Integrity
Root Account In Use – 164.312(a)(2)(i) Unique User Identification
Password Reuse Is Allowed – 164.308(a)(5)(ii)(D) Password Management
Password Standards Are Insecure – 164.308(a)(5)(ii)(D) Password Management
User Access Keys Rotation Is Disabled – 164.312(a)(1) Access Control
IAM Inline Policies Are In Use – 164.312(c)(1) Integrity + 164.312(e)(2)(i) Integrity Controls
IAM NotActions Are In Use – 164.312(c)(1) Integrity
IAM AssumeRole Is Misconfigured – 164.312(c)(1) Integrity
S3 Bucket Does Not Have Encryption Enabled – 164.312(a)(2)(iv) Encryption and Decryption
S3 Bucket Does Not Have Versioning Enabled – 164.308(a)(7)(ii)(A) Data Backup Plan
S3 Bucket Does Not Have Logging Enabled – 164.312(b) Audit Controls
S3 Bucket Is Readable By All (Public) – 164.312(d) Person or Entity Authentication
S3 Bucket Is Writable By All (Public) – 164.312(d) Person or Entity Authentication
Build HIPAA compliant services on all 100+ AWS services. Dash provides the monitoring and security controls required to maintain HIPAA compliance in the public cloud. Administrative policies created by your organization are connected into monitoring and allow your team to set a well defined security plan for HIPAA compliance management.
Dash works alongside Amazon Web Service agreements and protections so your team can maintain high security and compliance standards.
Utilizing Dash and AWS allows your organization to pay for only the services you need and scale up services at anytime.