How the mapping works
Every safe check BreakMesh runs on a verified target is linked to the HIPAA Security Rule HIPAA Security Rule safeguards it produces evidence for. When a scan completes you get a report that groups findings and passed checks by HIPAA Security Rule safeguards, with severity, evidence, and remediation guidance you can hand straight to an assessor or auditor.
HIPAA Security Rule coverage
164.308(a)(1)
- Dependency CVE Matching (SBOM)
- Drive-by Download / Malicious Redirect Chain
- Mobile App Static Analysis (APK/IPA)
- Service/Version CVE Hints (Advisory)
164.308(a)(6)
- Mail Security SPF/DKIM/DMARC
- Blocklist and Reputation Checks
- Security Contact Evidence
164.308(a)(7)
- API Rate-Limit Readiness
- Availability Status Evidence
- Bot Protection Detection
- DDoS Readiness Evidence
- Rate-Limit Readiness
- WAF/CDN Detection
- WAF Harmless Canary Probe
164.312(a)(1)
- Account Enumeration Indicators
- Auth Bypass Probes
- AWS CloudTrail Logging Disabled
- AWS Default Encryption Gaps
- AWS IAM Stale Access Keys
- AWS Open Security Group Ingress
- AWS Overly-Permissive IAM Policies
- AWS Public S3 Storage Exposure
- Azure Open NSG Ingress Rules
- Azure Public Blob Storage Exposure
- Broken Function Auth (Active)
- BFLA Privilege Escalation Probe
- BOLA / IDOR Two-Account Comparison
- Credentialed Test-Account Checks
- CSRF Protection Enforcement
- DNS Basics
- DNSSEC Review
- WHOIS and Domain Expiry
- Endpoint Auth Indicators
- GCP Open VPC Firewall Ingress
- GCP Public Cloud Storage Exposure
- IDOR (Two-Account)
- Login Rate-Limit Simulation
- Login Surface Controls
- Mail/DNS Hardening (MTA-STS / TLS-RPT / CAA)
- API Mass Assignment
- MFA Configuration Indicators
- OAuth 2.0 / OIDC Security Checks
- Origin Exposure Check
- Password Reset Flow Checks
- Password Spray Indicator
- Open Risky Ports
- Session Fixation Check
- Subdomain Discovery (Certificate Transparency)
- Subdomain Takeover Risk
- Weak Password Policy Review
164.312(c)(1)
- Business Logic — Price Manipulation
- Web Cache Poisoning Readiness
- Command Injection (Timing)
- Cookie Security
- CSP Quality Review
- Deprecated Browser APIs
- Directory Listing
- Sitemap and Robots Exposure
- Error Disclosure
- Error Disclosure Expansion
- File Upload Bypass
- Header Injection
- Insecure Deserialization (Timing)
- Open Redirect
- Open Redirect (Active)
- HTTP Parameter Pollution (HPP)
- Path Traversal
- Harmless Reflected XSS Indicators
- HTTP Request Smuggling / Desync Readiness
- Secrets in JavaScript Bundles
- Security Headers
- Sensitive Files
- Sensitive Response Pattern Detection
- Server Header Disclosure
- Session Cookie Scope
- Source Map Exposure
- Safe SQL Injection Indicators
- SQL Injection (Boolean-Blind)
- SQL Injection (Error-Based)
- Subresource Integrity (SRI) Missing
- SSRF (Callback)
- SSTI Template Injection Indicator
- Trusted Types Signal
- XSS — Reflected
- XSS — Stored
- XXE Injection
164.312(d)
- Account Enumeration Indicators
- Auth Bypass Probes
- Broken Function Auth (Active)
- BFLA Privilege Escalation Probe
- BOLA / IDOR Two-Account Comparison
- Credentialed Test-Account Checks
- CSRF Protection Enforcement
- Endpoint Auth Indicators
- IDOR (Two-Account)
- Login Rate-Limit Simulation
- Login Surface Controls
- API Mass Assignment
- MFA Configuration Indicators
- OAuth 2.0 / OIDC Security Checks
- Password Reset Flow Checks
- Password Spray Indicator
- Session Fixation Check
- Weak Password Policy Review
164.312(e)(1)
- AI Response Data Leakage
- API Documentation Exposure
- API Third-Party Dependency Inventory
- CORS Edge Cases (null origin / preflight)
- CORS Policy
- Excessive API CORS Checks
- GraphQL DoS Readiness (Batching / Alias / Depth)
- GraphQL Introspection Exposure
- HSTS Strength
- HTTP Method Exposure
- HTTP/2 and HTTP/3 Support
- HTTPS Redirect
- JWT Weakness Detection
- Mixed Content Detection
- Shadow API Discovery
- AI System Prompt Exposure
- TLS Certificate
- TLS Chain and Expiry Depth
- TLS Protocol and Cipher Review
- Training Data Extraction Indicator
- Versioned Endpoint Discovery
- WebSocket Security Check
164.502
- Cookie Consent Mechanism
- GDPR/CCPA Data Subject Rights
- Privacy and Terms Evidence