Healthcare

OCR asks who looked, not just who broke in.

Schedule a meeting

Hospitals and health plans under HIPAA, GDPR and NIS2

Security built for patient care

Turn the patient record access reviews HIPAA requires into signed records.

Clauses

HIPAARequirementARRTECHStays with you
164.308(a)(1)(ii)(D)Regular activity review.Scheduled HIPAA report and case records. →Clinical app logs need a parser.
164.312(b)Record and examine activity.Signed, chained storage and a silent-source alert. →A system that does not log.
164.308(a)(5)(ii)(C)Monitor log-in attempts.AD, VPN and Microsoft 365 collection. →Training.
164.312(e)(1)Guard ePHI in transit.DLP inspection before Send and on upload. →Encryption in transit.
164.402(iii)Was PHI acquired or viewed?Signed logs and DLP events. →The legal determination.

HIPAA 164.308

Run the access reviews HIPAA requires

HIPAA 164.308(a)(1)(ii)(D) requires regular review of records of system activity, such as audit logs and access reports. ARRTECH runs a scheduled HIPAA report and records who reviewed each case.

Insider access

Catch staff snooping in patient records

Looking at a patient record without a work reason is an impermissible use under HIPAA. ARRTECH SIEM collects access logs, and an ARRTECH DLP screen watermark ties any photo of a record to a user, computer and time.

PHI protection

Stop patient data leaving by email or print

HIPAA 164.312(e)(1) asks you to guard patient data sent over a network. ARRTECH DLP checks email before it is sent and controls printing, USB drives and prompts to AI tools.

Medical devices

Protect medical devices that cannot run an agent

Many medical devices cannot run security software. Cyberdroid AI Detection learns each device’s normal network behavior from your SIEM data and flags changes. It only reads data and never changes a device.

By rule

164.312(b)

Record and examine activity. ARRTECH: Signed, chained storage and a silent-source alert.

164.312(e)(1)

Guard ePHI in transit. ARRTECH: DLP inspection before Send and on upload.

164.402(iii)

Was PHI acquired or viewed? ARRTECH: Signed logs and DLP events.

Questions

Can patient data leave by email or print?

ARRTECH DLP checks email before it is sent, controls printing, USB drives and screenshots, reads text inside images, and checks prompts to AI tools.

What about staff who look at records without a reason?

A watermark shows the user, computer and time on screen, so a photo of a record traces back to a person. Print rules keep a record of what was printed.

What about medical devices that cannot run an agent?

Cyberdroid AI Detection learns each device’s normal network behavior from your SIEM and flags changes. It only reads data and never changes a device.

Who isolates a system?

A person, because isolating the wrong system can interrupt patient care. ARRTECH SOAR emails the approver up to five options and waits.

What stays with you?

Encrypting patient data, segmenting networks, restoring systems and your risk analysis. The DLP agent runs on Windows and macOS.

Sources

Guide

What does HIPAA require for audit logs?

HIPAA 164.312(b) requires mechanisms that record and examine activity, and 164.308 requires regular review of that activity.

How do hospitals detect snooping in patient records?

Collect EHR access logs, review them regularly, and tie on-screen activity to a person with watermarks and user risk scores.

What is the HIPAA breach notification deadline?

Notify affected individuals within 60 days of discovery. Report breaches of 500 or more people to HHS in the same window, and smaller ones to HHS each year.

Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Available now

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Early access

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.

See every system. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.