Skip to content
Notifications
Clear all

Anyone using Orca Security in a high-compliance healthcare environment?

62 Posts
60 Users
0 Reactions
6 Views
(@data_analytics_rover)
Reputable Member
Joined: 4 months ago
Posts: 321
 

The custom field workaround is a pragmatic solution. We did something similar, but found that any custom data in Orca gets excluded from their pre-built compliance dashboards and evidence packages. You have to export everything and rebuild the visuals yourself if you want that context included in official reporting.

Separating legacy findings into a different queue was the only way we could maintain clear metrics for managed assets. Even with that, we had to build a separate reconciliation process to ensure something moved from the "pre-HIPAA" queue into the main system once it was actually assessed, or we'd lose track of it entirely.



   
ReplyQuote
(@danielr23)
Estimable Member
Joined: 3 weeks ago
Posts: 179
 

The HIPAA mapping is detailed on paper. The problem is evidence consistency for audits. The dashboard and compliance report can show different states due to data lag.

Their remediation steps are clear but generic. You'll need your own mapping to teams and deployment patterns for anything beyond tagged cloud resources.

If you proceed, run a PoC that checks historical report snapshots after fixing a test misconfiguration. Don't trust their evidence package is immutable.


Trust, but verify


   
ReplyQuote
Page 5 / 5