| Framework | HIPAA Security Rule |
|---|---|
| Control ID | §164.308(a)(5) |
| Control Family | Administrative Safeguards > Training |
| Control Name | Security Awareness and Training |
| Status | IMPLEMENTED |
| Assessment Date | 2026-04-19T02:25:35.202960+00:00 |
| Assessor | TITAN AI Scanner v2.0 (CONDUCTOR + BASTION + SCOUT + COMPLY + SAGE) |
| Environment Scope | Azure: Pay-As-You-Go (prod) (4f29d094-1079-44c9-acb0-4d73a7a2dd34) |
| Report ID | 1c18e1558f923686c206b80129aaa389a4fe405c39860d5db571aaa68dbdd5ec |
Standard: Security awareness and training. Implement a security awareness and training program for all members of its workforce (including management).
Source: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
Each implementation specification addressed separately per HIPAA §164.306(d) / NIST 800-53A assessment methodology.
Periodic security updates.
Procedures for guarding against, detecting, and reporting malicious software.
Procedures for monitoring log-in attempts and reporting discrepancies.
Summarized with counts + exceptions + drill-down. Raw data available on request per retention policy.
Test of Design (does the control exist?) + Test of Operating Effectiveness (does it work consistently?). Sampling per AICPA AU-C 530.
n/a
Security Awareness Program doc v3.0.
110 employees
96.4% completion over prior 12 months.
Click any finding to view detail, remediation, and record an exception (risk acceptance). Exceptions are retained in the report as part of the audit trail.
training-non-completers
4 of 110 workforce members have not completed annual training (overdue 30+ days).
▾
SOC 2 Type 2 and HITRUST assessors require management's written response to findings.
| Scanner | TITAN AI Scanner v2.0 (CONDUCTOR + BASTION + SCOUT + COMPLY + SAGE) |
|---|---|
| Scanner version | v2.0.1 |
| Collection timestamp | 2026-04-19T02:25:35.202960+00:00 |
| Retention | 2555 days (HIPAA 164.316(b)(2)) |
| Report hash (SHA-256) | 1c18e1558f923686c206b80129aaa389a4fe405c39860d5db571aaa68dbdd5ec |
This same evidence is admissible for the following related controls. Scan once, satisfy multiple frameworks.
AT-1, AT-2, AT-3, SI-3, AU-6 — same evidence satisfiesCC1.4, CC2.2 — same evidence satisfiesA.7.2.2, A.12.2.1 — same evidence satisfies12.6, 5.x — same evidence satisfies02.e, 09.j — same evidence satisfies