Skip to content
AskFlorence
Main Navigation ArchitectureFlorence AIAgentsMembersAgent PlatformValidationInfrastructure

Appearance

Sidebar Navigation

Overview

Home

Glossary

System Architecture

Consumer & Agent Flow

Florence AI

Overview

Principles

Runtime

Tool surface

Adding a tool

Tool registry

Knowledge: SBC scenarios & CSR

Voice

Evals & observability

Provider risk & portability

Outage playbook

Roadmap

Build plan

Agents

Overview

Workflows & pain points

Members

Overview

Medicaid coverage gap

Carriers

Overview

Marketplaces

Overview

Agency

Overview

Regulations

Overview

Agent Platform

Overview

Auth Architecture

MongoDB Permissioning

Compliance Model

Data Models

Data Sources

Overview

CMS Marketplace API

CMS dependency map

PUF Data

State Subsidies

SBE Ingestion Playbook

SBE State Watchouts + Decisions

CA Phase C/D Playbook

NY Phase C/D Playbook

Validation

Overview

Methodology

APTC Formula

California 2026

New York 2026

CAPS Formula

Scenario Results

Infrastructure

Account Inventory

AWS Setup Runbook

AWS Organizations

CloudTrail

GuardDuty

Security Hub

Config

CloudFront + WAFv2

Data sources & ingest

Phase 4 DNS

Change Log

Vulnerability Management

MongoDB Setup

Access Control

Data Classification

Documentation Hosting

Post-deploy Smoke

Development

Preflight (local CI mirror)

Testing strategy

Compliance

Overview (auditor entry point)

SOC 2 Control Mapping

HIPAA Control Mapping

CMS EDE Appendix A Mapping

Risk Assessment

Encryption Policy

Data Retention Policy

Privacy Impact Assessment

Consent Capture & Versioning

Incident Response Plan

Access Control Policy

Marketing vs. Portal Analytics

Vendor / Subprocessor Register

Dependency Vulnerability Policy

BAA / Compliance Evidence

Compliance-Automation Integration

Compliance-Automation Vendor Evaluation

Penetration Test Reports

Architecture

Portal entry handoff

Mobile app strategy

Deferred architecture decisions

Session cookie architecture

Share flows

Decisions (ADRs)

Index

0001 — Atlas project isolation

0002 — Append-only audit log

0003 — Narrow-scoped Mongo users

0004 — Cross-cluster Atlas PrivateLink

0005 — Delayed-job architecture

0006 — Mongo user simplification

0007 — Terraform owns ECS task def

0008 — E2E testing strategy

0009 — Self-hosted analytics + observability (superseded)

0010 — PostHog HIPAA Cloud (supersedes 0009)

Runbooks

Security Incident Response

Break-Glass Root Login

Onboard Team Member

Offboard Team Member

Atlas user provisioning

Deploy via Terraform (ENG-277)

Rollback via Terraform (ENG-277)

S3 data bucket migration (planned Phase 11)

Access Reviews

2026-Q2 Review

Session log

Index

2026-04-23 — Phase 10 DNS cutover

2026-04-22 — Phase 8 prod AWS mirror

2026-04-22 — Phase 7 Atlas VPC peering

2026-04-22 — Phase 6 CloudFront + WAF

2026-04-21 — Phase 5 staging go-live

2026-04-17 — Atlas staging

Briefs

Index

Member portal plan (ENG-187)

2026-04-16/17 handoff

2026-04-17 Atlas handoff

System briefing (2026-04-17)

Creative AdBundance proposal brief

Creative AdBundance analytics brief

ElevenLabs RN integration research

Policies

Overview

On this page

Security Hub — Org-wide compliance posture ​

Status: Active since 2026-04-18, delegated admin: log-archive. Purpose: SOC 2 CC7.1, HIPAA §164.308(a)(1)(ii)(A), CMS EDE Phase 3 evidence of continuous control monitoring.

Summary ​

Security Hub aggregates findings from GuardDuty, Config, IAM Access Analyzer, Inspector (future), and its own managed standards into a single compliance dashboard. It evaluates our resources against industry benchmarks and scores our security posture continuously.

Resources ​

ResourceValue
Delegated administrator754660694122 (log-archive)
Finding aggregator ARNarn:aws:securityhub:us-east-1:754660694122:finding-aggregator/06cecfad-472c-80ae-e30b-b0bd4eb40824
Finding aggregator regionus-east-1 (all regions → us-east-1)
Auto-enable new membersYes, with default standards
Member accounts enrolled778477254880 (mgmt), 039624954211 (prod), 549136075525 (staging) — all Enabled

Standards subscribed ​

Standardmgmtprodstaginglog-archive
AWS Foundational Security Best Practices v1.0.0✓✓✓✓
CIS AWS Foundations Benchmark v1.2.0 (legacy default, to be disabled)✓✓✓✓
CIS AWS Foundations Benchmark v3.0.0—✓✓—
NIST 800-53 Rev 5 (HIPAA-aligned technical control set)—✓——

Prod carries the most stringent set — NIST 800-53 Rev 5 maps to HIPAA technical safeguards at §164.312, which is what EDE Phase 3 auditors look for. Staging runs CIS to catch misconfiguration without the finding volume of NIST on a pre-prod environment.

No native "HIPAA" standard ​

Security Hub doesn't have a standalone HIPAA standard. HIPAA compliance in AWS is evidenced via NIST 800-53 (for controls) + the signed AWS BAA (for data handling). Audit teams accept this mapping.

Controls status ​

Controls are in PENDING state immediately after subscription and transition to PASSED / FAILED / NOT_AVAILABLE over ~30-60 minutes as Security Hub evaluates resources. Expect a baseline score within a few hours.

Expected failures at launch (to be triaged once stack is built):

  • Controls that require ALB / CloudFront / WAF / Config / GuardDuty will initially fail on accounts where those resources don't exist yet (staging/prod get them in Phases 4-8).
  • Mgmt account controls like "MFA on root" should pass since we just set up root MFA on all member accounts.

Where findings go ​

  • Security Hub console in log-archive = primary dashboard.
  • EventBridge (future, Phase 11): rule to ship critical findings to an alerting destination.
  • S3 (future, Phase 11): cross-account export of findings to log-archive S3 for long-term retention and Drata ingestion.

SCP protection ​

ScpBaseline denies:

  • securityhub:DisableSecurityHub
  • securityhub:DeleteMembers
  • securityhub:DisassociateFromMasterAccount
  • securityhub:DisassociateMembers

Costs ​

Security Hub charges per finding ingested + per standard check per month. Pre-launch estimate: $5–15/mo scaling with finding volume.

Runbook ​

  • aws securityhub get-findings --filters '{"WorkflowStatus":[{"Value":"NEW","Comparison":"EQUALS"}]}' --max-items 20 — see current open findings.
  • aws securityhub get-enabled-standards — confirm standards per account.
  • aws securityhub describe-organization-configuration — confirm auto-enroll is on.
  • Recommended weekly: Security Hub console → Summary page in log-archive; triage any CRITICAL or HIGH findings.
Pager
Previous pageGuardDuty
Next pageConfig

AskFlorence Internal Documentation. Not for public distribution.

AskFlorence

Internal Documentation

Access restricted. Not for public distribution.