Learning Note

Prove controls operate when the demo ends

Turn risk decisions into dated access reviews, incident drills, restore tests, retention work, and scoped evidence.

Published September 23, 2026Revised September 23, 2026Version 1.0.0Review by December 23, 2026

Question

The Architecture Explorer can show a denied cross-tenant read once. What evidence would show that authorization, human approval, recovery, and deletion keep working as staff, vendors, code, and data change?

This final note remains a learning exercise for the same fictional U.S. provider and EEA clinic. Its service, cases, and evidence are synthetic. It does not describe a real SOC 2 report, HIPAA compliance assessment, GDPR opinion, or certified system. Sources were reviewed on September 23, 2026.

Current understanding

HIPAA legal duty, U.S. lane. The Security Rule requires a risk analysis, risk management, assigned responsibility, workforce and information access management, incident procedures, contingency planning, periodic evaluation, and documentation for regulated ePHI. HHS says the rule currently in effect is distinct from its proposed modifications. NIST SP 800-66 Rev. 2 provides practical resources for implementing the rule; the NIST guide is guidance, not a replacement regulation. HHS Security Rule summary · NIST HIPAA Security Rule resource guide

GDPR legal duty, EEA lane. The controller must account for applicable processing, security, rights, retention, and breach obligations; a processor assists under its instructions and contract. The controller documents personal-data breaches and notifies the authority without undue delay and, where feasible, within 72 hours after awareness unless the breach is unlikely to result in risk to people. A processor notifies its controller without undue delay. Notification to affected people has a separate high-risk threshold. These are conditional duties, not a universal countdown triggered by every security alert. EDPB breach guide · EDPB rights guide

HIPAA breach duty, U.S. lane. HHS describes notification after a breach of unsecured PHI, with required individual and business-associate-to-covered-entity notices made without unreasonable delay and no later than 60 days after discovery. Notice to HHS varies with breach size. A suspected incident needs classification before anyone assumes that a given notice applies. HHS Breach Notification Rule

SOC 2 audit criterion, shared service. A Type II examination concerns a defined service-organization system and the design and operating effectiveness of controls against selected Trust Services Criteria over a period. Dated records of a control actually operating may support an examination, but possessing these records does not itself create a SOC 2 report or satisfy either lane's law. AICPA SOC 2 guide · AICPA Trust Services Criteria

My engineering interpretation is an evidence loop: define a control and owner; run it on a schedule or event; keep a dated, scoped, minimally sensitive record; inspect failures; and track the correction to closure. The exact cadence and evidence store belong to the actual risk and examination scope. NIST's Secure Software Development Framework recommends secure development practices, while OWASP describes safe event logging; neither sets a universal medical-app checklist. NIST SSDF · OWASP logging guidance

Evidence and sources

For the fictional service I would keep six connected trails:

  • Risk and scope: a current diagram, tenant and vendor inventory, ePHI and personal-data locations, risk decisions, control owner, and selected SOC 2 system boundary. Record why a new model, queue, region, or support tool is in or out of scope. HHS Security Rule summary · AICPA description criteria
  • Access and change: dated grants, revocations, privilege and tool-policy reviews, code review, deployment approval, and tests proving an agent cannot read another tenant or write a clinical record. HHS Security Rule summary · NIST SSDF
  • Incident and response: first observation, affected tenant and stores, containment, evidence preserved, vendor and client escalation, legal notification assessment, decision owner, and timestamps. Keep the U.S. and EEA analyses separate. EDPB breach guide · HHS Breach Notification Rule
  • Recovery: dated backup and restore tests that verify the clinical intake service can resume with correct tenant boundaries and records. A backup job's green status is not the same as a successful restore. HHS Security Rule summary
  • Lifecycle: retention and deletion decisions for uploaded files, job state, database, retrieval index, model-provider copies, traces, logs, backups, and support tools, with documented exceptions and confirmation from responsible parties. EDPB compliance guide · EDPB rights guide
  • Evidence hygiene: a sanitized audit trail of actor, action, policy decision, time, and correlation ID, with access to evidence itself controlled. Keep document text and PHI out of routine exports unless specifically required and protected. OWASP logging guidance

Worked example

At 09:10, synthetic job JOB-104 proposes reading EEA tenant record EU-P900 while operating under US-CLINIC / US-P100. The retrieval gate denies the call before loading the record. At 09:11, an event with retrieval_denied, tenant_mismatch, a job reference, and a correlation ID reaches a restricted audit stream. The event contains no document paragraph or patient name. At 09:20, an on-call reviewer checks whether there was any earlier successful read, model transmission, log leak, or clinical-record write. That investigation, not the denied event alone, determines whether an incident or legally reportable breach occurred. OWASP API object authorization · HHS Breach Notification Rule · EDPB breach guide

The next review checks a sampled access grant, the current tool allowlist, a restore result, and whether the index and model-provider copies follow the recorded retention decision. Failures receive an owner and retest date. A SOC 2 examiner, if one were engaged, would assess controls in an agreed system and period; the clinic and provider would still need their separate legal reviews. AICPA SOC 2 guide

Copy the Markdown security review worksheet to map your own actors, data copies, denials, owners, tests, and unanswered legal questions. For a broader engineering perspective on the U.S. lane, read my Portfolio Journal account of learning HIPAA as a software engineer.

Open questions

  • Which controls and Trust Services Criteria would actually be selected for a future examination, and who owns each one?
  • How will the service prove deletion or justified retention across files, index, prompts, traces, backups, and vendors?
  • Which incident facts trigger client escalation, formal legal assessment, or notification in each lane?
  • How will a reviewer discover and correct a tool-policy drift before the next clinical job?

Sources


Canonical page