SurePassID Compliance Manager Datasheet:
HIPAA and CMMC 2.0
SurePassID Authentication Server
SurePassID
Compliance Monitoring and Reporting Library
Overview
The SurePassID Compliance Monitoring and Reporting
Library is a comprehensive .NET solution designed to help
organizations achieve and maintain CMMC 2.0 and
HIPAA Security Rule compliance for privileged user
authentication. It provides automated collection, correlation, analysis,
and reporting of authentication events to demonstrate MFA enforcement
for privileged accounts.
Key Benefits
Benefit
Description
Automated Compliance
Scheduled compliance checks with cron-based scheduling
Audit-Ready Evidence
Generate evidence packs with SHA-256 hashes for assessments
Real-Time Monitoring
Streaming alerts for immediate response to security events
Multi-Format Reports
Professional PDF, HTML, JSON, and CSV report generation
Flexible Integration
Multiple event sources and identity providers
Multi-Framework Support
Supports CMMC 2.0 and HIPAA Security Rule requirements
Event Aggregation
Aggregate authentication events from multiple sources
simultaneously
MFA Coverage Analysis
Cross-source correlation proves every privileged Windows logon has a
corresponding SurePassID MFA event
Cloud & On-Prem
Support for both cloud (Entra ID, SurePassID) and on-premises (AD,
Syslog) systems
Interactive Setup
Configuration wizard for easy setup without editing JSON
CMMC 2.0 Controls Addressed
Control ID
Control Name
How We Address It
IA.L2-3.5.3
Multifactor Authentication
Track and report MFA vs SFA usage for privileged users
AC.L2-3.1.1
Authorized Access Control
Correlate events with AD privileged group membership
AC.L2-3.1.5
Least Privilege
Identify users in multiple privileged groups
AU.L2-3.3.1
System Auditing
Collect and store authentication audit trails
AU.L2-3.3.2
Audit Content
Capture user, timestamp, result, method, IP address
SI.L2-3.14.6
Security Alerts
Real-time alerting on security events
HIPAA Security Rule
Controls Addressed
This solution also supports HIPAA Security Rule
technical safeguard requirements for healthcare organizations:
Access Controls (§164.312(a)(1))
HIPAA Requirement
Standard
How We Address It
Unique User Identification
§164.312(a)(2)(i)
Correlates events with AD identities via UPN, SAMAccountName,
canonical user ID
Automatic Logoff
§164.312(a)(2)(iii)
Monitors session events and tracks authentication timestamps
Audit Controls (§164.312(b))
HIPAA Requirement
Standard
How We Address It
Audit Controls
§164.312(b)
Comprehensive authentication event logging from multiple
sources
Audit Trail
§164.312(b)
Captures user, timestamp, result, method, IP address, source
system
Evidence Packs
§164.312(b)
Generates SHA-256 hashed evidence bundles for audits and
assessments
Person or Entity
Authentication (§164.312(d))
HIPAA Requirement
Standard
How We Address It
Authentication Verification
§164.312(d)
Tracks MFA vs SFA authentication classification
MFA Enforcement
§164.312(d)
Reports MFA adoption rates, alerts on SFA usage by privileged
users
MFA Coverage Analysis
§164.312(d)
Cross-source correlation matches Windows SFA logons to SurePassID
MFA events; identifies machines without MFA enforcement
Transmission Security
(§164.312(e)(1))
HIPAA Requirement
Standard
How We Address It
Encryption
§164.312(e)(2)(ii)
TLS 1.2/1.3 for AD (LDAPS) and API communications
Security Incident
Procedures (§164.308(a)(6))
Alert Type
HIPAA Relevance
Severity
Brute Force Detection
Detect credential attacks against ePHI systems
Critical
Suspicious IP Authentication
Detect unauthorized access attempts
High/Critical
Authentication Failures
Track failed access attempts to systems with ePHI
Warning/High
After-Hours Access
Detect unusual access patterns
Warning
MFA Bypass Detected
Identify weakened authentication controls
Critical
Workforce Security
(§164.308(a)(3))
Feature
HIPAA Control
Description
Privileged User Tracking
Authorization/Supervision
Monitors users with elevated access to ePHI systems
Group Membership Correlation
Access Management
Links authentication events to AD group membership
Drift Detection
Termination Procedures
Identifies users with MFA coverage gaps
Information Access
Management (§164.308(a)(4))
Feature
HIPAA Control
Description
Privileged Auth Report
Access Authorization
Documents who accessed systems with elevated privileges
SFA/MFA Summary
Access Establishment
Reports on authentication strength enforcement
Evidence Pack Generation
Documentation
Audit-ready evidence for HIPAA compliance assessments
Note: While this solution provides significant
support for HIPAA technical safeguards, full HIPAA compliance requires
additional administrative and physical safeguards, policies, and
procedures.
Use the built-in wizard to configure the service without editing JSON
manually:
compliance-cli configurecompliance-cli configure --quick# Only required settingscompliance-cli configure --test# Test configuration after saving
Option 2: Console Application
Run on-demand compliance checks from command line or scripts.
Option 3: Windows Service
Scheduled compliance checks using cron expressions with automatic
evidence pack generation.
Option 4: Docker Container
Containerized deployment for cloud or Kubernetes environments.
Option 5: MCP Server
(AI Agent Integration)
Pre-built MCP server for GitHub Copilot, Claude Desktop, and Cursor.
Build and register -- all nine compliance tools are available in your AI
assistant immediately.
Option 6: Library Integration
Embed compliance checking into existing applications via NuGet
packages.
Configuration Example
The configuration wizard generates a JSON configuration file
automatically. You can also configure manually:
Interactive HTML reports (Chart.js, sortable tables, responsive
layout), expanded SFA IP gap analysis (total events, MFA gaps, sources,
first/last seen timestamps), PDF report parity with HTML
1.2.0
2025-06
MFA Coverage Analysis (cross-source Windows SFA ? SurePassID MFA
correlation), Windows Event Log multi-source support in MCP server,
FindUser REST API enrichment, username normalization (DOMAIN\user, UPN),
UTC timestamp normalization across sources
1.1.0
2025-01
Multi-source event aggregation, SurePassID REST API source, Entra ID
integration (Graph API & JSON import), SurePassID identity provider,
Interactive configuration wizard
1.0.0
2024-01
Initial release
The software and information contained herein are proprietary to, and
comprise valuable trade secrets of, SurePassID Authentication, Inc.,
which intends to preserve as confidential trade secrets such software
and information. Such software and information shall not be reproduced,
published, or disclosed to others, or used for any purpose other than
that for which it is expressly provided, without the prior written
consent of SurePassID Authentication,
Inc.