HIPAA Security & Privacy Rules
45 CFR Part 160, 164 (Subparts A, C, E). Signed Evidence Packs™ per record-access give HHS-OCR the contemporaneous trail the Audit Protocol requires. Minimum Necessary attestation + BAA-ready evidence pack shape.
When HHS-OCR audits a HIPAA Privacy or Security incident, when FDA wants the SaMD post-market evidence, when NYDFS Part 500 requires the cyber-controls trail, when OCC Heightened Standards demands model-risk-management proof — KYE Protocol™ answers from a record sealed at the moment of action. Replayable from the publishing tenant's JWKS alone. No vendor dependency in the audit path.
45 CFR Part 160, 164 (Subparts A, C, E). Signed Evidence Packs™ per record-access give HHS-OCR the contemporaneous trail the Audit Protocol requires. Minimum Necessary attestation + BAA-ready evidence pack shape.
HITECH Breach Notification Rule + HITRUST Common Security Framework. Audit-chain immutability + per-decision evidence ready for HITRUST controls 01.b, 09.aa, 10.ab and the HITECH 60-day breach window.
Software as a Medical Device + electronic-records integrity + Predetermined Change Control Plan (FDA-CDRH 2024). KYE™ binds the runtime decision to the PCCP declaration; signed Evidence Pack™ per inference is the post-market record FDA reviewers expect.
OCC Heightened Standards (model-risk-management) + NYDFS Part 500 (cyber + AI 2024 amendments) + SEC Regulation Systems Compliance & Integrity. Banking-grade audit chain maps directly; signed Replay Proofs™ verify offline from public keys alone.
NIST CSF map →Govern · Map · Measure · Manage + Zero-Trust Architecture. The Measure + Manage functions map directly to KYE™ runtime-evidence + revocation primitives.
Coverage detail →FedRAMP (federal-cloud authorisations) · CISA Secure-by-Design AI guidance · state AI laws (Colorado SB 205, Illinois Generative AI Act). KYE™ records keep the federal-and-state audit trail contemporaneous and replayable across jurisdictional boundaries.
US SaMD vendors and US healthcare providers procure differently. Two pilot SKUs reflect that.
Independent — no government affiliation. KYE Protocol™ is an independent protocol and is not affiliated with, endorsed by, or part of any government, regulator, or official “Sovereign AI” programme. References to regulators and frameworks describe the requirements KYE™ helps you evidence — not any official relationship.