HIPAA § 164.308(a)(8) - Evaluation

The HIPAA § 164.308(a)(8) requirement states, "A covered entity or business associate must, in accordance with § 164.306, perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under this rule and, subsequently, in response to environmental or operational changes affecting the security of electronic protected health information, that establishes the extent to which a covered entity's or business associate's security policies and procedures meet the requirements of this subpart."

This requirement mandates regularly reviewing systems containing health information to ensure compliance with security policies.

Wazuh helps meet this requirement by providing several modules. One of these modules is the Security Configuration Assessment (SCA) module, which is enabled by default on your Wazuh installation. The Wazuh Security Configuration Assessment (SCA) module performs scans to determine if monitored endpoints meet secure configuration and hardening policies. These scans assess the endpoint configuration using SCA policy files that contain rules tested against the endpoint's actual configuration.

Use case: Security Configuration Assessment scan

In this case, we use the SCA module to evaluate a monitored Ubuntu 26.04 endpoint against the CIS Benchmark for Ubuntu Linux 26.04. SCA scans provide a mechanism to regularly assess the endpoint's security controls and identify configurations that require remediation. You can track these events and actions on the Wazuh dashboard:

Wazuh dashboard

  1. Click Configuration Assessment from the Wazuh Overview dashboard:

    Wazuh Overview dashboard - Configuration Assessment
  2. The Dashboard tab shows an overview of the top 5 SCA agents, policies, checks, MITRE tactics, number of passed, failed, not applicable checks, and an overall score.

    Configuration Assessment Dashboard tab
  3. The Inventory tab shows the current SCA state for monitored endpoints. It displays the SCA policies evaluated on each endpoint and their individual checks, and the check result.

    Configuration Assessment Inventory tab
  4. The Findings tab displays the SCA findings generated when the result of a check changes between scans.

    Configuration Assessment Findings tab