Mirava Health

Healthcare security, supported by evidence.

Mirava Evidence Lab performs authorized, evidence-bound security assessments of healthcare applications. We test the stated application and environment, document what we find, and do not claim more than the evidence supports.

Evidence Lab

Security work that leaves a useful record.

A scoped assessment produces findings, control mappings, remediation guidance, and retest evidence.

Assessment record

01Scope confirmed
02Finding documented
03Control mapped
04Fix retested

Useful evidence is specific enough to act on.

Assessment Areas

What an assessment covers.

01

Assessment

  • Authorization and scope

  • Application preservation

  • Static analysis

  • Runtime analysis

  • Network and third-party analysis

  • Backend and API testing

  • Healthcare control evaluation

  • Reporting and retesting

02

Standards

  • OWASP MASVS

  • OWASP MASTG

  • HIPAA Security Rule

  • HIPAA Privacy and Breach Rules

  • 42 CFR Part 2 where applicable

  • FTC Health Breach Notification Rule where applicable

  • NIST SP 800-66

  • NIST SP 800-53

  • OWASP API Security

What You Receive

Evidence you can rely on.

01

Deliverables

  • Evidence ledger

  • Software dependency inventory

  • Documented findings

  • Control mappings

  • Remediation guidance

  • Retest results

02

What we do not claim

  • HHS does not recognize private “HIPAA certification.” An application security assessment is not a substitute for a regulated organization's required risk analysis.

Build something better for healthcare.

Have a program, workflow, or healthcare product that needs a better system?