New: Active Pentest Package — Try it free
BreakMesh shield BreakMesh – Vulnerability Simulator & Cyber Range

Compliance evidence mapping

HIPAA Security Rule evidence mapping

BreakMesh maps each safe scan finding to the HIPAA Security Rule safeguard it provides evidence for, helping healthcare teams demonstrate technical safeguards for electronic protected health information (ePHI).

111 checks mapped 8 HIPAA Security Rule safeguards Non-destructive scans

BreakMesh helps you gather audit evidence and reduce risk. It maps findings to control evidence to support your assessment — it does not by itself make your organization compliant or certified.

How the mapping works

Every safe check BreakMesh runs on a verified target is linked to the HIPAA Security Rule HIPAA Security Rule safeguards it produces evidence for. When a scan completes you get a report that groups findings and passed checks by HIPAA Security Rule safeguards, with severity, evidence, and remediation guidance you can hand straight to an assessor or auditor.

HIPAA Security Rule coverage

164.308(a)(1)

  • Dependency CVE Matching (SBOM)
  • Drive-by Download / Malicious Redirect Chain
  • Mobile App Static Analysis (APK/IPA)
  • Service/Version CVE Hints (Advisory)

164.308(a)(6)

  • Mail Security SPF/DKIM/DMARC
  • Blocklist and Reputation Checks
  • Security Contact Evidence

164.308(a)(7)

  • API Rate-Limit Readiness
  • Availability Status Evidence
  • Bot Protection Detection
  • DDoS Readiness Evidence
  • Rate-Limit Readiness
  • WAF/CDN Detection
  • WAF Harmless Canary Probe

164.312(a)(1)

  • Account Enumeration Indicators
  • Auth Bypass Probes
  • AWS CloudTrail Logging Disabled
  • AWS Default Encryption Gaps
  • AWS IAM Stale Access Keys
  • AWS Open Security Group Ingress
  • AWS Overly-Permissive IAM Policies
  • AWS Public S3 Storage Exposure
  • Azure Open NSG Ingress Rules
  • Azure Public Blob Storage Exposure
  • Broken Function Auth (Active)
  • BFLA Privilege Escalation Probe
  • BOLA / IDOR Two-Account Comparison
  • Credentialed Test-Account Checks
  • CSRF Protection Enforcement
  • DNS Basics
  • DNSSEC Review
  • WHOIS and Domain Expiry
  • Endpoint Auth Indicators
  • GCP Open VPC Firewall Ingress
  • GCP Public Cloud Storage Exposure
  • IDOR (Two-Account)
  • Login Rate-Limit Simulation
  • Login Surface Controls
  • Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
  • API Mass Assignment
  • MFA Configuration Indicators
  • OAuth 2.0 / OIDC Security Checks
  • Origin Exposure Check
  • Password Reset Flow Checks
  • Password Spray Indicator
  • Open Risky Ports
  • Session Fixation Check
  • Subdomain Discovery (Certificate Transparency)
  • Subdomain Takeover Risk
  • Weak Password Policy Review

164.312(c)(1)

  • Business Logic — Price Manipulation
  • Web Cache Poisoning Readiness
  • Command Injection (Timing)
  • Cookie Security
  • CSP Quality Review
  • Deprecated Browser APIs
  • Directory Listing
  • Sitemap and Robots Exposure
  • Error Disclosure
  • Error Disclosure Expansion
  • File Upload Bypass
  • Header Injection
  • Insecure Deserialization (Timing)
  • Open Redirect
  • Open Redirect (Active)
  • HTTP Parameter Pollution (HPP)
  • Path Traversal
  • Harmless Reflected XSS Indicators
  • HTTP Request Smuggling / Desync Readiness
  • Secrets in JavaScript Bundles
  • Security Headers
  • Sensitive Files
  • Sensitive Response Pattern Detection
  • Server Header Disclosure
  • Session Cookie Scope
  • Source Map Exposure
  • Safe SQL Injection Indicators
  • SQL Injection (Boolean-Blind)
  • SQL Injection (Error-Based)
  • Subresource Integrity (SRI) Missing
  • SSRF (Callback)
  • SSTI Template Injection Indicator
  • Trusted Types Signal
  • XSS — Reflected
  • XSS — Stored
  • XXE Injection

164.312(d)

  • Account Enumeration Indicators
  • Auth Bypass Probes
  • Broken Function Auth (Active)
  • BFLA Privilege Escalation Probe
  • BOLA / IDOR Two-Account Comparison
  • Credentialed Test-Account Checks
  • CSRF Protection Enforcement
  • Endpoint Auth Indicators
  • IDOR (Two-Account)
  • Login Rate-Limit Simulation
  • Login Surface Controls
  • API Mass Assignment
  • MFA Configuration Indicators
  • OAuth 2.0 / OIDC Security Checks
  • Password Reset Flow Checks
  • Password Spray Indicator
  • Session Fixation Check
  • Weak Password Policy Review

164.312(e)(1)

  • AI Response Data Leakage
  • API Documentation Exposure
  • API Third-Party Dependency Inventory
  • CORS Edge Cases (null origin / preflight)
  • CORS Policy
  • Excessive API CORS Checks
  • GraphQL DoS Readiness (Batching / Alias / Depth)
  • GraphQL Introspection Exposure
  • HSTS Strength
  • HTTP Method Exposure
  • HTTP/2 and HTTP/3 Support
  • HTTPS Redirect
  • JWT Weakness Detection
  • Mixed Content Detection
  • Shadow API Discovery
  • AI System Prompt Exposure
  • TLS Certificate
  • TLS Chain and Expiry Depth
  • TLS Protocol and Cipher Review
  • Training Data Extraction Indicator
  • Versioned Endpoint Discovery
  • WebSocket Security Check

164.502

  • Cookie Consent Mechanism
  • GDPR/CCPA Data Subject Rights
  • Privacy and Terms Evidence