Compliance OS

Vendor Workspace

Demo ModeSample Data Only

This is a Demo Compliance Environment

No real customer data is stored here. All organizations, evidence, assessments, and control updates are seeded sample/demo data for product demonstrations.

Active demo organization: King's Healthcare, Inc. (Demo Organization)

Vendor self-assessment workspace

King's Compliance Advisory (Demo)

King's Compliance Advisory (Demo) HIPAA Audit 2026-07-30

Status: IN PROGRESSCustomer: Ball State UniversityEngagement: Ball State University - King's Compliance Advisory (Demo) Compliance ProgramDue: Aug 29, 20261 framework
Total Controls
6

1 framework scope

Applied Controls
0

0 fully implemented

Tasks (Open)
6

0 overdue POA&M items

Evidence Linked
0

0 awaiting customer review

High-Risk Gaps
0

0 needs info/rejected

Control Completion
Answered controls vs total in scope
0 / 6
0% complete
Submission Readiness
Combines completion, evidence, and open high-risk gaps
0%
0% complete
Risk Assessment Score
Higher is better (lower open-risk exposure)
75
75% complete
Control Status Breakdown
Implementation state distribution across this audit scope.
Controls
6
Open
6
100%
Request Queue Breakdown
What is blocking submission or requires follow-up.
No chart data available yet.
Domain Completion
Answered controls by domain (top incomplete domains surface first).
No chart data available yet.
Framework Scope
Frameworks currently included in this vendor assessment.

HIPAA Security Rule

HIPAA · 45 CFR 164

6 controls
0%
Domain Progress
Accordion view for control domains, completion, evidence, and top gaps.

Administrative Safeguards

0 / 2 controls answered

0%
0 implemented2 open

Implementation Coverage

0%

Includes fully implemented controls only

Evidence Coverage

0%

Controls with at least one linked evidence item

High Risk Gaps

0

Open controls marked High/Critical

Top Gaps

164.308(a)(1)(ii)(A) Risk Analysis

NOT IMPLEMENTED

164.308(a)(5)(ii)(C) Log-in Monitoring

NOT IMPLEMENTED

Physical Safeguards

0 / 1 controls answered

0%
0 implemented1 open

Implementation Coverage

0%

Includes fully implemented controls only

Evidence Coverage

0%

Controls with at least one linked evidence item

High Risk Gaps

0

Open controls marked High/Critical

Top Gaps

164.310(d)(1) Device and Media Controls

NOT IMPLEMENTED

Policies & Procedures

0 / 1 controls answered

0%
0 implemented1 open

Implementation Coverage

0%

Includes fully implemented controls only

Evidence Coverage

0%

Controls with at least one linked evidence item

High Risk Gaps

0

Open controls marked High/Critical

Top Gaps

164.316(b)(1) Documentation Retention

NOT IMPLEMENTED

Technical Safeguards

0 / 2 controls answered

0%
0 implemented2 open

Implementation Coverage

0%

Includes fully implemented controls only

Evidence Coverage

0%

Controls with at least one linked evidence item

High Risk Gaps

0

Open controls marked High/Critical

Top Gaps

164.312(a)(1) Access Control

NOT IMPLEMENTED

164.312(b) Audit Controls

NOT IMPLEMENTED
Customer Requests / POA&M
Controls needing remediation action, evidence, or reviewer follow-up.

164.308(a)(1)(ii)(A) Risk Analysis

NOT IMPLEMENTEDDRAFTevidence neededowner unassignedDue in 1d

164.308(a)(5)(ii)(C) Log-in Monitoring

NOT IMPLEMENTEDDRAFTevidence neededowner unassignedDue in 1d

164.310(d)(1) Device and Media Controls

NOT IMPLEMENTEDDRAFTevidence neededowner unassignedDue in 1d

164.316(b)(1) Documentation Retention

NOT IMPLEMENTEDDRAFTevidence neededowner unassignedDue in 1d

164.312(a)(1) Access Control

NOT IMPLEMENTEDDRAFTevidence neededowner unassignedDue in 1d

164.312(b) Audit Controls

NOT IMPLEMENTEDDRAFTevidence neededowner unassignedDue in 1d
Control Workbench
Vendor-ready questionnaire table for implementation status, risk, owners, and evidence.
ControlDomainFrameworkStatusCustomer ReviewEvidence ReviewRiskEvidencePOA&MOwnerDue

164.308(a)(1)(ii)(A) Risk Analysis

Administrative SafeguardsHIPAANOT IMPLEMENTEDDRAFT
Missing
Aug 29, 2026
Due in 1d

164.308(a)(5)(ii)(C) Log-in Monitoring

Administrative SafeguardsHIPAANOT IMPLEMENTEDDRAFT
Missing
Aug 29, 2026
Due in 1d

164.310(d)(1) Device and Media Controls

Physical SafeguardsHIPAANOT IMPLEMENTEDDRAFT
Missing
Aug 29, 2026
Due in 1d

164.316(b)(1) Documentation Retention

Policies & ProceduresHIPAANOT IMPLEMENTEDDRAFT
Missing
Aug 29, 2026
Due in 1d

164.312(a)(1) Access Control

Technical SafeguardsHIPAANOT IMPLEMENTEDDRAFT
Missing
Aug 29, 2026
Due in 1d

164.312(b) Audit Controls

Technical SafeguardsHIPAANOT IMPLEMENTEDDRAFT
Missing
Aug 29, 2026
Due in 1d
This vendor workspace is designed for customer-facing audits and self-assessments. It supports framework-scoped progress tracking, evidence collection, and POA&M-style remediation queues for HIPAA, NIST CSF, SOC 2, ISO 27001, CIS Controls, and the added NIST 800-171 / 800-172 / 800-53 frameworks.