Compliance Frameworks

Deep-dive guides for every major compliance framework. Understand requirements, spot common gaps, and learn how AI accelerates your path to compliance.

United States Active

Health Insurance Portability and Accountability Act (HIPAA)

US federal law protecting the privacy and security of patient health information (PHI).

Overview

HIPAA is a US federal law that required the creation of national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. The HIPAA Privacy Rule, Security Rule, and Breach Notification Rule set the standards for protecting PHI.

Who It Applies To

Covered entities (health plans, healthcare clearinghouses, healthcare providers) and business associates who handle PHI. Subcontractors of business associates also covered.

Business Size

All covered entities regardless of size. Business associates of any size who handle PHI. No small business exemption.

Industries

Healthcare providers, health plans, health insurance, healthcare clearinghouses, IT vendors handling PHI, cloud storage providers, medical device companies, telehealth platforms.

Key Requirements

  • Privacy Rule: Establishes standards for when and how PHI may be used and disclosed, including the minimum necessary standard.
  • Security Rule: Requires administrative, physical, and technical safeguards to protect electronic PHI (ePHI).
  • Breach Notification Rule: Requires covered entities to notify affected individuals, HHS, and in some cases the media following a breach of unsecured PHI.
  • Business Associate Agreements: Written contracts required between covered entities and business associates that handle PHI.
  • Risk Analysis: Comprehensive assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
  • Workforce Training: All workforce members must receive training on HIPAA policies and procedures and how to protect PHI.

Common Gaps

  • Missing BAAs with vendors handling PHI
  • No risk analysis conducted
  • Inadequate access controls
  • Missing encryption for ePHI at rest and in transit
  • No incident response plan
  • Workforce training gaps and incomplete documentation

How Alternivite Helps

  • Maps your policies to HIPAA Privacy and Security Rules
  • Generates Business Associate Agreement templates
  • Creates risk analysis documentation
  • Identifies access control gaps
  • Produces breach notification templates
  • Tracks workforce training completion

Timeline

Risk analysis 2–4 weeks
Policy development 4–8 weeks
Implementation 4–6 weeks
Ongoing compliance Continuous

Compliance Checklist

  • ✓ Conduct risk analysis
  • ✓ Implement access controls
  • ✓ Encrypt PHI at rest and in transit
  • ✓ Execute BAAs with all vendors
  • ✓ Create incident response plan
  • ✓ Develop privacy and security policies
  • ✓ Implement workforce training
  • ✓ Establish minimum necessary standard
  • ✓ Set up audit logging
  • ✓ Conduct annual risk review
California, USAActive

California Consumer Privacy Act (CCPA)

Empowering California residents with control over their personal information and imposing obligations on businesses that collect and process it.

Overview

CCPA gives California consumers more control over the personal information that businesses collect about them. It grants rights to know, delete, and opt-out of the sale of personal information. Applies to for-profit businesses doing business in California that meet revenue or data thresholds.

Who It Applies To

For-profit businesses collecting California consumer data that meet ANY of the following criteria:

  • Annual gross revenue exceeding $25 million
  • Buy, sell, or share personal information of 100,000 or more consumers or households
  • Derive 50% or more of annual revenue from selling personal information

Business Size

Applies to businesses meeting revenue or data volume thresholds. Small businesses under $25M revenue and not selling data may be exempt.

Industries

Retail, e-commerce, technology, advertising, data brokers, financial services, and any business with California customers.

Key Requirements

  • Notice at collection: Inform consumers of the categories of personal information collected and the purposes for which they are used.
  • Right to know: Consumers can request disclosure of the categories and specific pieces of personal information collected about them.
  • Right to delete: Consumers can request deletion of their personal information, subject to certain exceptions.
  • Right to opt-out of sale: Consumers can opt-out of the sale of their personal information to third parties.
  • Non-discrimination: Businesses cannot discriminate against consumers who exercise their CCPA rights.
  • Privacy policy: Maintain a clear and conspicuous privacy policy describing data practices and consumer rights.

Common Gaps

  • Missing "Do Not Sell My Personal Information" link on website
  • No established consumer request process or response workflow
  • Inadequate identity verification procedures for consumer requests
  • Missing or outdated privacy policy updates for CCPA compliance
  • No employee training on CCPA obligations and consumer rights
  • Absence of vendor and service provider agreements with required clauses

How Alternivite Helps

  • Maps data flows against CCPA requirements to identify compliance gaps
  • Generates automated consumer request workflows with verification steps
  • Creates "Do Not Sell My Personal Information" implementation guide
  • Produces CCPA-compliant privacy policy templates
  • Tracks opt-out preferences across all data processing activities
  • Monitors ongoing compliance status with real-time alerts and reporting

Timeline

  • Assessment: 1-2 weeks
  • Gap remediation: 3-6 weeks
  • Implementation: 2-3 weeks
  • Ongoing: Continuous

Compliance Checklist

  • ✓ Identify all personal information collected about California consumers
  • ✓ Add "Do Not Sell My Personal Information" link to website homepage
  • ✓ Create and document a consumer request process with response timelines
  • ✓ Update privacy policy to include all CCPA-required disclosures
  • ✓ Implement reasonable security measures for identity verification
  • ✓ Train employees on CCPA obligations and handling consumer rights requests
  • ✓ Establish service provider and vendor agreements with CCPA clauses
  • ✓ Set and document data retention and deletion periods for all data categories
  • ✓ Implement opt-out mechanisms for the sale of personal information
  • ✓ Conduct annual CCPA compliance review and update policies accordingly
EU / EEA Active

General Data Protection Regulation (GDPR)

The world's most comprehensive data privacy law, protecting the personal data of individuals in the European Union and European Economic Area.

Overview

GDPR is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area. It addresses the export of personal data outside the EU and EEA areas. The GDPR aims to give control to individuals over their personal data and to simplify the regulatory environment for international business by unifying regulation within the EU.

Who It Applies To

  • Any organization processing personal data of EU/EEA residents
  • Organizations based in the EU, regardless of where data is processed
  • Non-EU organizations offering goods or services to EU residents
  • Non-EU organizations monitoring behavior of EU residents

Business Size

All sizes. Applies to sole traders, SMEs, and enterprises alike. However, organizations with fewer than 250 employees have some exemptions for record-keeping and Data Protection Officer (DPO) appointment.

Industries

  • Technology and SaaS
  • E-commerce and retail
  • Financial services and fintech
  • Healthcare (with HIPAA overlap)
  • Marketing and advertising
  • Any business with EU customers

Key Requirements

Lawful basis for processing — Must have a valid legal basis (consent, contract, legitimate interest, etc.) for every data processing activity.
Data subject rights — Must enable access, rectification, erasure, portability, and objection rights within 30 days.
Privacy by design — Data protection must be built into systems from the start, not bolted on later.
Data breach notification — Report breaches to supervisory authority within 72 hours and to affected individuals without undue delay.
Data Protection Officer — Required for public authorities and organizations conducting large-scale systematic monitoring.
Records of processing — Must maintain detailed records of all personal data processing activities.

Common Gaps

  • Missing or incomplete Records of Processing Activities (ROPA)
  • Vague or missing lawful basis documentation
  • No data subject request process in place
  • Third-party processors without Data Processing Agreements (DPAs)
  • Inadequate breach notification procedures
  • No privacy impact assessments for high-risk processing

How Alternivite Helps

  • AI auto-maps your documents against GDPR Article requirements
  • Generates ROPA templates and populates from your uploads
  • Identifies missing DPAs with third-party processors
  • Creates data subject request workflows
  • Produces breach notification templates ready to send
  • Tracks compliance status across all GDPR articles in real time

Timeline

Assessment1-2 weeks
Gap remediation4-8 weeks
Policy implementation2-4 weeks
Ongoing complianceContinuous

Compliance Checklist

GlobalActive

Service Organization Control Type II (SOC 2)

Building trust through demonstrated security controls that verify your organization protects customer data over time.

Overview

SOC 2 is a voluntary compliance framework developed by the AICPA. It defines criteria for managing customer data based on five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. A SOC 2 Type II report demonstrates that controls are operating effectively over a period of time.

Who It Applies To

Any service organization that stores, processes, or transmits customer data. Primarily SaaS companies, cloud service providers, data centers, managed service providers, and IT outsourcing firms.

Business Size

Most common for mid-market and enterprise SaaS companies. Startups pursuing enterprise deals often need SOC 2 early. Required by many enterprise procurement processes.

Industries

SaaS, cloud computing, data centers, managed IT, fintech, healthtech, edtech, any B2B technology company.

Key Requirements

  • Security: Logical and physical access controls protect systems from unauthorized access and misuse.
  • Availability: Systems meet commitments regarding uptime, disaster recovery, and business continuity.
  • Processing Integrity: System processing is complete, accurate, timely, and authorized.
  • Confidentiality: Encryption and access restrictions protect information designated as confidential.
  • Privacy: Personal data is collected, used, retained, disclosed, and disposed of in conformity with commitments.

Common Gaps

  • No formal change management process
  • Missing access review procedures
  • Inadequate logging and monitoring
  • No disaster recovery testing
  • Missing data classification
  • Incomplete vendor management

How Alternivite Helps

  • Maps controls to all 5 Trust Services Criteria
  • Generates control descriptions and evidence checklists
  • Tracks evidence collection timeline
  • Identifies missing controls before audit
  • Provides audit-ready compliance dashboard
  • Produces management assertion templates

Timeline

  • Readiness assessment: 2-3 weeks
  • Control implementation: 4-8 weeks
  • Observation period: 6-12 months
  • Audit preparation: 2-4 weeks

Compliance Checklist

  • ✓ Define Trust Services Criteria scope
  • ✓ Document all controls
  • ✓ Implement access control policies
  • ✓ Set up logging and monitoring
  • ✓ Create change management process
  • ✓ Develop disaster recovery plan
  • ✓ Conduct access reviews
  • ✓ Establish vendor management program
  • ✓ Perform risk assessment
  • ✓ Engage audit firm
New York, USA Active

New York Department of Financial Services Cybersecurity Regulation (23 NYCRR 500)

Mandatory cybersecurity program and controls for financial services companies regulated by the New York DFS.

Overview

23 NYCRR Part 500 is a regulation from the New York Department of Financial Services establishing cybersecurity requirements for financial services companies. One of the first state-level cybersecurity regulations in the US. Requires a cybersecurity program, risk assessment, CISO appointment, and annual compliance certification.

Who It Applies To

Any person or entity operating under or required to operate under a DFS license, registration, or charter. Includes banks, insurance companies, virtual currency businesses, mortgage brokers, and other DFS-regulated financial services.

Business Size

All covered entities regardless of size. Small organizations may qualify for limited exemptions for certain requirements (like CISO appointment) but must still maintain a cybersecurity program.

Industries

Banking, insurance, virtual currency and fintech, mortgage lending, financial advisors, money transmitters, and other DFS-regulated financial services in New York.

Key Requirements

  • Establish cybersecurity program
  • Conduct risk assessment
  • Implement controls (access, encryption, monitoring)
  • Appoint CISO
  • Report cybersecurity events within 72 hours
  • Annual compliance certification

Common Gaps

  • No designated CISO
  • Missing cybersecurity program documentation
  • Inadequate risk assessment
  • Missing multi-factor authentication
  • No incident response plan
  • Incomplete access reviews
  • Missing annual certification
  • No third-party security management

How Alternivite Helps

  • Maps controls to all 23 NYCRR 500 requirements
  • Generates cybersecurity program documentation
  • Creates risk assessment templates
  • Identifies MFA and encryption gaps
  • Produces event reporting templates
  • Tracks annual certification deadlines

Timeline

Gap assessment 2–3 weeks
Program development 4–6 weeks
Control implementation 4–8 weeks
Certification 1–2 weeks

Compliance Checklist

  • ✓ Appoint a qualified CISO
  • ✓ Develop written cybersecurity policy
  • ✓ Conduct annual risk assessment
  • ✓ Implement multi-factor authentication
  • ✓ Encrypt non-public information
  • ✓ Establish access privileges and review
  • ✓ Create incident response plan
  • ✓ Report cybersecurity events to DFS
  • ✓ Conduct penetration testing and vulnerability scanning
  • ✓ Submit annual compliance certification
Global Active

Payment Card Industry Data Security Standard (PCI DSS)

Protecting cardholder data through comprehensive security standards for every entity in the payment chain.

Overview

PCI DSS is a set of security standards designed to ensure that ALL companies that accept, process, store, or transmit credit card information maintain a secure environment. Created by major card brands (Visa, Mastercard, Amex, Discover, JCB). Version 4.0 introduced in 2022 with stricter requirements.

Who It Applies To

Any entity that accepts, processes, stores, or transmits cardholder data. This includes merchants, payment processors, payment gateways, hosting providers, and any service provider in the payment chain.

Business Size

All merchants regardless of size. Compliance level (SAQ vs ROC) depends on transaction volume: Level 1 (>6M transactions), Level 2 (1–6M), Level 3 (20K–1M), Level 4 (<20K).

Industries

Retail, e-commerce, hospitality, healthcare (with HIPAA overlap), financial services, subscription businesses, any business accepting card payments.

Key Requirements

  • Install and maintain network security controls — Firewalls and routers must be configured to protect cardholder data.
  • Protect cardholder data with encryption — Encrypt transmission of cardholder data across open, public networks and protect stored data.
  • Maintain a vulnerability management program — Develop and maintain secure systems and applications, including anti-virus software.
  • Implement strong access control measures — Restrict access to cardholder data on a need-to-know basis.
  • Regularly monitor and test networks — Track and monitor all access to network resources and cardholder data.
  • Maintain an information security policy — Maintain a policy that addresses information security for all personnel.

Common Gaps

  • Storing card data unnecessarily
  • Weak encryption implementations
  • Missing network segmentation
  • Inadequate access controls
  • No regular vulnerability scanning
  • Missing security awareness training
  • Incomplete audit trails

How Alternivite Helps

  • Maps controls to all 12 PCI DSS requirements
  • Identifies card data storage risks
  • Generates encryption compliance documentation
  • Creates network segmentation guidelines
  • Produces SAQ completion guides
  • Tracks vulnerability scan results

Timeline

Scope definition 1–2 weeks
Gap assessment 2–3 weeks
Remediation 4–8 weeks
Validation 2–4 weeks

Compliance Checklist

  • ✓ Define cardholder data environment scope
  • ✓ Install and configure firewalls
  • ✓ Encrypt cardholder data in transit and at rest
  • ✓ Implement access control policies
  • ✓ Develop secure coding practices
  • ✓ Maintain anti-virus software
  • ✓ Regularly test security systems
  • ✓ Maintain information security policy
  • ✓ Restrict physical access to cardholder data
  • ✓ Monitor and audit all access

Not Sure Which Framework Applies to You?

Our AI analyzes your business and recommends the right compliance frameworks. Start free, upgrade when ready.