Healthcare security, supported by evidence.
Mirava Evidence Lab performs authorized, evidence-bound security assessments of healthcare applications. We test the stated application and environment, document what we find, and do not claim more than the evidence supports.
Evidence Lab
Security work that leaves a useful record.
A scoped assessment produces findings, control mappings, remediation guidance, and retest evidence.
Assessment record
Useful evidence is specific enough to act on.
Assessment Areas
What an assessment covers.
Assessment
Authorization and scope
Application preservation
Static analysis
Runtime analysis
Network and third-party analysis
Backend and API testing
Healthcare control evaluation
Reporting and retesting
Standards
OWASP MASVS
OWASP MASTG
HIPAA Security Rule
HIPAA Privacy and Breach Rules
42 CFR Part 2 where applicable
FTC Health Breach Notification Rule where applicable
NIST SP 800-66
NIST SP 800-53
OWASP API Security
What You Receive
Evidence you can rely on.
Deliverables
Evidence ledger
Software dependency inventory
Documented findings
Control mappings
Remediation guidance
Retest results
What we do not claim
HHS does not recognize private “HIPAA certification.” An application security assessment is not a substitute for a regulated organization's required risk analysis.
Build something better for healthcare.
Have a program, workflow, or healthcare product that needs a better system?