HIPAA · Health information
For HIPAA-regulated entities and business associates: PHI/ePHI scoping, risk analysis, access and BAAs where applicable. Compliance spans people, processes and technology.
Security and compliance: HIPAA, SOC 2, PCI DSS and ISO 27001
We design controls and evidence for projects with HIPAA, SOC 2, PCI DSS and ISO/IEC 27001 requirements, scoped to each organization.
Tell us about your projectWe begin by identifying data, risks, providers and responsibilities. Applicable requirements inform architecture, development practices and verifiable operational processes.
For HIPAA-regulated entities and business associates: PHI/ePHI scoping, risk analysis, access and BAAs where applicable. Compliance spans people, processes and technology.
We support control and evidence preparation against applicable criteria. SOC 2 is an independent auditor’s examination and report; this page does not represent an issued Border Valley report.
We scope cardholder data and prioritize integrations that reduce exposure. Applicable validation is determined with the compliance program’s responsible parties and relevant assessors.
We align engineering with ISMS risk management, policies and continual improvement. Certification is an independent assessment with a defined scope; using a platform does not confer it.
Each stage is agreed with your team before moving forward.
Data, systems and owners
Access, changes and recovery
Testing and follow-up
We design for agreed requirements and deliver evidence of implementation. External audits, certifications and validations have their own scope and are explicitly arranged when required.
Read the frameworks at their official sources:
HIPAA · HHSSOC 2 · AICPAPCI DSS · PCI SSCISO/IEC 27001 · ISOBefore starting, we define scope, owners and deliverables.
This page describes our engineering approach and frameworks we can address. It does not claim a current Border Valley ISO certification, PCI DSS validation or SOC 2 report. Any credential must be verified against its document, scope and validity.
No. Configuration, contracts, suppliers, training and ongoing operations also matter. The project must define what we implement, what the client operates and what a third party assesses.