A HIPAA Security Rule gap analysis run live against the governance graph: 199 nodes covering assets, lineage, controls, regulations, stewards, and reports. Synthetic environment; real method.
One query, no scoping assumptions: every PHI or PII asset with no control tracing to the HIPAA Security Rule. This is the honest number, and it is unusable on its own.
Every finding is scored on classification (PHI 3, PII 2), gap type (control absent 2, status unknown 1, unmapped 0), and regulatory exposure through lineage (regulatory report downstream 2, any report 1). Nothing is dropped; risk acceptances are tracked with expiry.
| Tier | Asset | Class | System | Gap type | Reports exposed | Status |
|---|
Active risk acceptances suppressed, findings grouped by tier and gap type. Three numbers, three owners, three different actions.
All 199 nodes and 440 relationships, force-directed. Hover to identify a node and light up its neighborhood; drag nodes to untangle. The dense cluster is the asset layer; the satellites around it are the governance overlay attached to it.
Plain-English questions answered by Claude over a retrieved subgraph: keyword match seeds the relevant nodes, a two-hop expansion pulls their neighborhood, and the model answers only from what was retrieved, plus the computed triage worksheets.
This file is running outside Claude.ai, so the built-in model access isn't available. Paste an Anthropic API key (console.anthropic.com) to enable local mode. The key is held in this page's memory only: it is never saved to the file, to storage, or sent anywhere except api.anthropic.com. Use your own key on your own machine only.