External HIPAA Observable Control Scanner

HIPAA Risk Visibility
In Minutes, Not Months.

Scan externally observable HIPAA control signals. Get a deterministic score with evidence-backed findings. Runtime and administrative controls clearly marked when they require internal assessment.

No credit card required. Results in under 5 minutes.

25+
Observable Checks
3
Safeguard Categories
< 5min
Full Scan Time
$10K
Per Violation (Tier 3)

The HIPAA Problem

OCR fines hit $2.7B in 2025. Most hospitals don't know they're exposed until the audit letter arrives. By then it's too late.

โฑ๏ธ

Consultants Are Slow

6-month assessments. $200K+ engagements. By the time you get the report, your environment has changed.

๐Ÿ“‹

Checklists Miss Reality

Spreadsheet audits don't scan your actual systems. They check policies, not implementations.

โœ“

Evidence Beats Claims

When OCR asks for proof, you need documented evidence with clear methodology โ€” not just opinions.

How Archangel Works

01

Enter Domain

Point us at your patient portal, EHR login, or any web-facing healthcare system.

02

External Scan

25+ checks on externally observable controls. Technical safeguards verified from public signals.

03

Get Your Score

Deterministic scoring with findings mapped to HIPAA sections (ยง164.308, ยง164.310, ยง164.312).

04

Receipt Record

Every scan produces a chain-linked receipt with payload hash and integrity token.

What We Check

Real HIPAA sections. Observable controls verified externally. Runtime/admin controls marked UNKNOWN when internal assessment is required.

๐Ÿ”’

Technical Safeguards

ยง164.312
  • โœ“Transmission Security (HSTS)
  • โœ“Access Controls & Authentication
  • โœ“Audit Controls & Logging
  • โœ“Integrity Controls (CSP, X-Frame)
  • โœ“MFA Indicators
  • โœ“TLS Configuration
๐Ÿ“‹

Administrative Safeguards

ยง164.308
  • โœ“Notice of Privacy Practices
  • โœ“Business Associate Agreements
  • โœ“Security Awareness Training
  • โœ“HIPAA Documentation
  • ?Risk Analysis(runtime)
  • ?Incident Response(runtime)
๐Ÿฅ

Physical Safeguards

ยง164.310
  • โœ“Facility Access Controls
  • โœ“Workstation Security
  • โœ“Device & Media Controls
  • ?Contingency Planning(runtime)
  • โœ“Asset Accountability
  • โœ“Data Backup Procedures

\u26A0\uFE0F Runtime controls cannot be verified from external scan. These require internal assessment and are marked UNKNOWN with violation_count: 0.

Transparent Scoring

No black boxes. The algorithm is documented. You know exactly how your score is calculated. Only externally observed findings affect the score.

Severity Weights

CRITICAL-25 points
HIGH-15 points
MEDIUM-8 points
LOW-2 points

Base score: 100. Observed findings subtract based on severity.

Grade Thresholds

Aโ‰ฅ 90
Bโ‰ฅ 75
Cโ‰ฅ 60
Dโ‰ฅ 40
F< 40

Simple Pricing

Start free. See results. Then decide.

Scan

Free

One-time external scan

  • โœ“External control scan
  • โœ“Observable control score (A-F)
  • โœ“Finding breakdown
  • โœ“Exposure estimate
  • โœ“Chain-linked receipt
Run Free Scan
MOST POPULAR

Professional

$799/month

For hospitals

  • โœ“Daily automated scans
  • โœ“Up to 200 assets
  • โœ“Full report suite
  • โœ“Priority support
  • โœ“API access
  • โœ“Custom checks
Start Trial

Enterprise

Custom

For health systems

  • โœ“Unlimited assets
  • โœ“Continuous scanning
  • โœ“Custom integrations
  • โœ“Dedicated CSM
  • โœ“SLA guarantee
  • โœ“On-prem option
Contact Sales

Evidence-Backed Findings.

Every finding includes the evidence that triggered it. Scan results are chain-linked with integrity tokens for audit continuity.

Get Your Free External Scan

Note: This scanner evaluates externally observable technical controls only. It does not constitute a full HIPAA compliance certification. Administrative, physical, and organizational controls that require internal access are marked as "UNKNOWN" and should be assessed separately. Consult qualified compliance professionals for comprehensive HIPAA audits.

Powered by FinalBoss Technology

Patent Pending โ€” FinalBoss Technology Inc.