| Framework | HIPAA Security Rule |
|---|---|
| Control ID | §164.312(d) |
| Control Family | Technical Safeguards > Authentication |
| Control Name | Person or Entity Authentication |
| Status | PARTIALLY IMPLEMENTED |
| Assessment Date | 2026-04-19T02:25:35.202960+00:00 |
| Assessor | TITAN AI Scanner v2.0 (CONDUCTOR + BASTION + SCOUT + COMPLY + SAGE) |
| Environment Scope | Azure: Pay-As-You-Go (prod) (4f29d094-1079-44c9-acb0-4d73a7a2dd34) |
| Report ID | 5cd4bc8a3b8d2b6daf66c5668c5ccfcd2530acda645f48d6902d3d7f1ac5a328 |
Standard: Person or entity authentication. Implement procedures to verify that a person or entity seeking access to electronic protected health information is the one claimed.
Source: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
Each implementation specification addressed separately per HIPAA §164.306(d) / NIST 800-53A assessment methodology.
Summarized with counts + exceptions + drill-down. Raw data available on request per retention policy.
Test of Design (does the control exist?) + Test of Operating Effectiveness (does it work consistently?). Sampling per AICPA AU-C 530.
n/a
Conditional access requires MFA for all ePHI-touching apps.
42 users
All 42 users enrolled.
18 SPs
15 of 18 SPs still password-based. Finding #1.
Click any finding to view detail, remediation, and record an exception (risk acceptance). Exceptions are retained in the report as part of the audit trail.
azure-ad-service-principals
15 of 18 service principals use password auth instead of certificate/managed identity.
▾
SOC 2 Type 2 and HITRUST assessors require management's written response to findings.
| Scanner | TITAN AI Scanner v2.0 (CONDUCTOR + BASTION + SCOUT + COMPLY + SAGE) |
|---|---|
| Scanner version | v2.0.1 |
| Collection timestamp | 2026-04-19T02:25:35.202960+00:00 |
| Retention | 2555 days (HIPAA 164.316(b)(2)) |
| Report hash (SHA-256) | 5cd4bc8a3b8d2b6daf66c5668c5ccfcd2530acda645f48d6902d3d7f1ac5a328 |
This same evidence is admissible for the following related controls. Scan once, satisfy multiple frameworks.
IA-2, IA-2(1), IA-2(2), IA-5 — same evidence satisfiesCC6.1, CC6.6 — same evidence satisfies8.2, 8.3, 8.4 — same evidence satisfiesA.9.2.4, A.9.4.2 — same evidence satisfies01.b, 01.d, 01.q — same evidence satisfiesIA-2, IA-2(1), IA-2(2) — same evidence satisfies