One engine.
One audit trail.

From HIPAA evidence to ambient OASIS extraction — same platform, same trail.

Healthcare-native + cloud-aware

Built for HIPAA, Home Health, and clinical workflows — not adapted from enterprise GRC. Continuous AWS / Azure / GCP posture monitoring feeds infrastructure evidence directly into your control mapping.

Compliance + clinical

One platform for audit readiness and ambient OASIS extraction.

AI that proposes

Six autonomous agents run on a schedule — human approval required for every action.

No SSO tax

SAML SSO included on every paid tier. Every SSO + SCIM event becomes auditor-facing evidence — not a $50k Enterprise upgrade.

Priced for healthcare

Built for small practices and growing agencies — not enterprise IT budgets. ROI in the first billing cycle.

Dynamic Risk Assessment

Shift from annual spreadsheets to live risk heatmaps. Run HIPAA Risk Assessments across your control families, track progress per assessor, and monitor your compliance trend over a rolling 30-day window — with one-click review actions.

Compliance Trend 30-Day Rolling Average
Frameworks HIPAA, NIST 800-66
HIPAA risk heatmap · Q1 2026 87 / 100
30-day rolling trend +4 pts
61 controls 0 unassessed 4 in review
Evidence repo · live mapping 3 just now
  • 14:32 Annual_Training_Q1.xlsx
    §164.308(a)(5) Training records auto
  • 14:27 Northwind_BAA_2026.pdf
    §164.314(a)(1) Vendor agreements auto
  • 14:24 S3_AccessLogs_Q1.json
    §164.312(b) Audit controls auto
89% auto-mapped 248 total 0 unmapped

Evidence Repository

Stop chasing screenshots. Upload documents, map them to HIPAA control families, and keep every piece of evidence — including your policy library, version-controlled and continuously diffed against the live infrastructure it governs — organised in a centralised repository ready for auditors on demand.

Control Mapping Automatic & Manual
Policy Workflows Create, Edit, Version, Diff

Agents propose. You decide.

Autonomous agents run continuously, surfacing remediation proposals to your review queue with a confidence score and a one-click decision.

Intelligence Engine Protexa AI
Insight Types Anomalies · Policy Gaps · Evidence Gaps · Drift · Vendor BAAs
Evidence Sentinel Nightly scan of your evidence repo for gaps, expiries, and drift.
Drift Detector Flags any framework domain that drops 5+ points from baseline.
Vendor Risk Agent Weekly BAA sweep — catches expiries before they become findings.
Policy Drift Agent Diffs documented policies against the live infrastructure.
SRA Prep Agent Pre-assessment baseline, scoping, and asset inventory per cycle.
Breach Responder §164.408 timeline draft + forensic evidence bundle assembly.
Human approval required for every agent action
Protexa AI · live queue 3 active
Anomaly 2h ago

Admin login from new IP — 73.x.x.x (Brisbane, AU)

confidence 0.91 Investigate →
BAA expiry just now

Northwind LLC — agreement lapses in 14 days

confidence 0.94 Renew draft →
Evidence gap just now

§164.308(a)(5) — Training 2024 has 0 mapped files

confidence 0.88 Auto-map →
Drift Detector · running
Audit pack assembly 0%
  • Executive summary 3.1s
  • Risk register snapshot 8.7s
  • Evidence inventory (248 items) 47.2s
  • Control attestations 22.3s
  • NIST 800-66 mapping 9.4s
  • Audit timeline 4.8s
  • Final attestation signature 3.2s
p95 SLO < 5 min this run 1m 47s ✓ on pace

Reports & Audit Packs

Generate executive summaries, audit reports, compliance status snapshots, and risk assessments — all from live data. Tasks land in your team's queue with priority and due date; status feeds straight into the report. Download your full audit pack in one click, or drill into your risk register and NIST 800-66 mapping for deeper analysis.

Report Types Executive · Audit · Risk · Compliance
Export Audit-Ready PDF / JSON
Tasks List + Calendar views, priority + due dates

HIPAA is the start. Not the limit.

Protexa supports HIPAA Security Rule, SOC 2 (Trust Services Criteria), HITRUST, Home Health (Medicare CoP, 42 CFR §484), and ISO 27001:2022 from a single dashboard — with the same evidence repository, the same assessment engine, and the same audit report format. NIST 800-66 Rev 2 mapping ships overlaid on HIPAA for organizations that need it. Switching frameworks is a dropdown, not a separate product.

HIPAASOC 2 TSCHITRUSTHome HealthISO 27001NIST 800-66 (mapping)
Ambient session · live 0:14:22
  • M1830 Bathing just now

    "able to bathe with assistance"

  • M1840 Toilet transferring just now

    "independent"

  • M2200 Therapy need just now

    "PT, 3x weekly"

Maps to §164.308(a)(7) · saved to evidence repo

Clinical documentation that captures OASIS items while your clinicians work.

Ambient recording listens during patient visits and extracts OASIS assessment items in real time — with clinician attestation, two-party consent management, and PDGM reimbursement estimation built in. Documentation that used to take 45 minutes now takes under 15, and every completed visit feeds directly into your compliance evidence repository.

Capabilities Recording · OASIS Extraction · PDGM Estimation
Consent Two-Party Consent (all applicable states)
Compliance Link Auto-maps to evidence repository
ROI $2,000+/clinician/month recovered