HIPAA Risk Visibility
In Minutes, Not Months.
Scan externally observable HIPAA control signals. Get a deterministic score with evidence-backed findings. Runtime and administrative controls clearly marked when they require internal assessment.
No credit card required. Results in under 5 minutes.
The HIPAA Problem
OCR fines hit $2.7B in 2025. Most hospitals don't know they're exposed until the audit letter arrives. By then it's too late.
Consultants Are Slow
6-month assessments. $200K+ engagements. By the time you get the report, your environment has changed.
Checklists Miss Reality
Spreadsheet audits don't scan your actual systems. They check policies, not implementations.
Evidence Beats Claims
When OCR asks for proof, you need documented evidence with clear methodology โ not just opinions.
How Archangel Works
Enter Domain
Point us at your patient portal, EHR login, or any web-facing healthcare system.
External Scan
25+ checks on externally observable controls. Technical safeguards verified from public signals.
Get Your Score
Deterministic scoring with findings mapped to HIPAA sections (ยง164.308, ยง164.310, ยง164.312).
Receipt Record
Every scan produces a chain-linked receipt with payload hash and integrity token.
What We Check
Real HIPAA sections. Observable controls verified externally. Runtime/admin controls marked UNKNOWN when internal assessment is required.
Technical Safeguards
ยง164.312- โTransmission Security (HSTS)
- โAccess Controls & Authentication
- โAudit Controls & Logging
- โIntegrity Controls (CSP, X-Frame)
- โMFA Indicators
- โTLS Configuration
Administrative Safeguards
ยง164.308- โNotice of Privacy Practices
- โBusiness Associate Agreements
- โSecurity Awareness Training
- โHIPAA Documentation
- ?Risk Analysis(runtime)
- ?Incident Response(runtime)
Physical Safeguards
ยง164.310- โFacility Access Controls
- โWorkstation Security
- โDevice & Media Controls
- ?Contingency Planning(runtime)
- โAsset Accountability
- โData Backup Procedures
\u26A0\uFE0F Runtime controls cannot be verified from external scan. These require internal assessment and are marked UNKNOWN with violation_count: 0.
Transparent Scoring
No black boxes. The algorithm is documented. You know exactly how your score is calculated. Only externally observed findings affect the score.
Severity Weights
Base score: 100. Observed findings subtract based on severity.
Grade Thresholds
Simple Pricing
Start free. See results. Then decide.
Scan
One-time external scan
- โExternal control scan
- โObservable control score (A-F)
- โFinding breakdown
- โExposure estimate
- โChain-linked receipt
Professional
For hospitals
- โDaily automated scans
- โUp to 200 assets
- โFull report suite
- โPriority support
- โAPI access
- โCustom checks
Enterprise
For health systems
- โUnlimited assets
- โContinuous scanning
- โCustom integrations
- โDedicated CSM
- โSLA guarantee
- โOn-prem option
Evidence-Backed Findings.
Every finding includes the evidence that triggered it. Scan results are chain-linked with integrity tokens for audit continuity.
Get Your Free External ScanNote: This scanner evaluates externally observable technical controls only. It does not constitute a full HIPAA compliance certification. Administrative, physical, and organizational controls that require internal access are marked as "UNKNOWN" and should be assessed separately. Consult qualified compliance professionals for comprehensive HIPAA audits.
Powered by FinalBoss Technology
Patent Pending โ FinalBoss Technology Inc.