G8KEPR implements the technical and administrative safeguards required by the HIPAA Security Rule. We will sign a Business Associate Agreement before your deployment processes any ePHI.
What "HIPAA-ready" means here. G8KEPR implements the technical controls required by the HIPAA Security Rule and will sign a BAA before your deployment processes ePHI. We are not formally audited by a third-party HIPAA compliance assessor. Physical safeguards (device tracking, visitor logs) are partially implemented. Our 75% readiness score reflects the current state of our safeguard tracking — not a certification claim.
The Security Rule organizes safeguards into three categories. Here is where G8KEPR stands in each.
§164.312(a)(1)RBAC with least-privilege; TOTP MFA is available per user, not enforced org-wide
§164.312(b)Append-only audit log; authentication and domain events HMAC-SHA256 hash-chained per tenant and verified daily (since 2026-09-13); 7-year audit retention by default
§164.312(d)Password plus optional per-user TOTP MFA; SSO and hardware tokens are not yet available
§164.312(e)(1)TLS 1.3 at the origin; the public edge also accepts TLS 1.2
§164.312(c)(1)Checksums in place; real-time tamper detection in progress
§164.308(a)(1)Annual risk assessment completed Q1 2026; documented in security policy
§164.308(a)(3)Role-based security training; annual completion tracking in progress
§164.310(a)(1)Badge access active; visitor log digitization in progress
§164.310(d)(1)Policy drafted; automated device inventory tooling not yet deployed
These are the specific technical measures in place — not marketing copy. Each maps to a Security Rule requirement.
AES-256 for all ePHI stored in PostgreSQL. Field-level encryption for the most sensitive identifiers (SSN, diagnosis codes).
TLS 1.3 enforced end-to-end. All API endpoints reject plaintext connections. Certificate pinning on internal service-to-service calls.
Tenant-scoped queries are filtered to the caller’s organization in the application layer. PostgreSQL Row-Level Security (RLS) policies add defence-in-depth, enforced when the app connects as the NOBYPASSRLS g8kepr_service role (the self-hosted Helm default).
Every authenticated API request is recorded with user and timestamp in an append-only table. Authentication and domain events are also HMAC-SHA256 hash-chained per tenant and verified daily (since 2026-09-13); per-request rows carry their own in-row HMAC chain.
HIPAA requires 6 years. G8KEPR keeps audit logs for 7 years by default (84 monthly partitions). The S3 Object Lock archival period is configurable.
Authenticated API requests are scored per organization against a learned baseline that includes time of day and request volume. MCP sessions are checked for multi-turn attacks, but MCP tool calls have no learned baseline of their own. There is no ePHI-specific access model.
A Business Associate Agreement is required before G8KEPR processes any ePHI on your behalf. The process is straightforward — typical turnaround is 1–2 business days.
Contact us via the form below. Tell us which PHI types your deployment will process and your organization name.
We confirm the covered services, PHI types, and your obligations as a covered entity. Typically a 1–2 day turnaround.
Sign electronically via DocuSign. Executed BAA stored in the compliance dashboard under Business Associate Agreements.
§164.312(b) requirement: 6 years
Logs are append-only. Authentication and domain events are hash-chained per tenant and verified daily (since 2026-09-13). Exportable in standard formats for auditors.
§164.400–414 Breach Notification Rule
G8KEPR can run entirely on your own servers. No data ever transits a third-party cloud — your BAA obligations are significantly simpler.
Deploy on-premises or in your own cloud account. ePHI stays within your security boundary — you are the only covered entity in the picture.
Helm chart for production deployments. Runs in existing hospital or health system Kubernetes clusters with RBAC and namespace isolation.
When self-hosted, G8KEPR is not a business associate — it is your software. BAA still covers any support or monitoring access we have to your environment.
We will walk through the technical controls, sign the BAA, and help you map your compliance requirements to the G8KEPR configuration.