essay · hipaa-active-defense
Threxen resources

HIPAA active defense

A cornerstone for covered entities: how Threxen’s HIPAA-aligned tenants run risk analysis as a workload, lock ePHI behind per-tenant key envelopes, and turn the agent loop into an artifact an HHS / OCR reviewer can sign off on.

HIPAA does not enumerate active defense; it enumerates safeguards. Administrative safeguards under §164.308 demand risk analysis, risk management, sanction policy, information-system activity review, and incident procedures; physical safeguards under §164.310 cover facility access, workstation use, and device controls; technical safeguards under §164.312 govern access control, audit controls, integrity, person-or-entity authentication, and transmission security. A covered-entity tenant that toggles the HIPAA pack under /app/settings/policy has each of those controls running as a workload inside the boundary — the Watchdog detectors fire on the §164.308(a)(1)(ii)(A) risk-analysis signal, Containment acts on §164.308(a)(6)(i) incident response, and Playbook produces the audit-log artifact the documentation rule §164.316(b)(1) requires to be retained for six years.

A Business Associate Agreement is the perimeter a HIPAA tenant writes at onboarding, and the key envelope is what makes the perimeter enforceable. PHI lives in a HIPAA-only data plane that no other tenant can read — there is no parallel ops database, no partnership back door, no override flag operators can flip at 02:00 — and the audit log is hash-chained end-to-end so a breach-review request landed months later can be answered from the same source of truth the agent saw when the verdict was issued. Reversal of a containment event goes through §164.308(a)(6)(ii) response and reporting; reversal is a first-class action so an analyst who disagrees can rewind the boundary and document the disagreement against §164.316(b)(2) updates.

Active-defense containment under HIPAA looks like this: a third-party SaaS provider’s compromised credential is fingerprinted on a §164.312(e)(1) transmission-security signal, isolation revokes the session under §164.312(a)(2)(iii) automatic-logoff and poisons the captured credential at the IdP rather than at the PHI store, and the resulting packet seals under §164.312(c)(1) integrity and §164.308(a)(6)(ii) reporting. The full mapping lives at /resources/sector-coverage — six rows by four columns — and the analyst can pivot the same packet back through §164.308(a)(1)(ii)(B) risk management without rewriting the incident.

All resourcessecurity & compliance posture →Threxen · static essay · drift-free by construction
compare across all five frameworks

Read this regulator alongside its four peers.

The same four capabilities — host isolation, live credential poisoning, decoy surface, and the hash-chained evidence packet — are mapped onto each named article, requirement, or control of every regulated framework Threxen ships a policy pack for. The comparison matrix is the single page that lays them side by side.

▸ four sibling pillars · one matrix page · biometric-style read-across without re-reading five essays · security & compliance posture on the trust center