| Module | Status | What It Does |
|---|---|---|
| Regulatory Pulse | Live | 5-source federal feed, daily Claude scoring, 50 of 65 events |
| Attestation Vault | Live | RxDC + Gag Clause tracking for 8 client plans |
| Vendor Risk | Live | Real TLS/header scanning + Claude HIPAA risk assessment |
| Incident Response | Live | NIST 800-61 playbooks auto-generated on every incident |
| Attestation Reminders | Live | Daily email when any client attestation is Overdue |
| Incident Escalation | Live | Daily email for Open incidents 7+ days; HIPAA OCR countdown |
| GitHub PR Automation | Live | High-risk event (score โฅ 8) โ auto branch + compliance alert PR |
| Executive Hub | Live | Single dashboard at acis.rossonlineservices.com |
| Operations Tab | Live | Manual triggers, heartbeat view, AI Gateway log streaming |
| Heartbeat Agent | Live | Daily self-audit โ Green/Yellow/Red โ CCC Admin report |
| Agent Logs | Live | Full AI inference trace visible in Operations tab |
Upgraded from claude-sonnet-4-6 to claude-opus-4-7. CFR citation precision and phase-level specificity measurably improved. Every new incident receives an Opus-quality playbook.
Daily cron checks for rxdc_status = 'Overdue' or gag_clause_status = 'Overdue'. When found, sends an HTML summary table to the compliance administrator via Resend. No-op on clean days โ no spam.
Daily cron checks for incidents open longer than 7 days. Email includes days-open count and HIPAA OCR window countdown per incident. Subject line escalates to โ ๏ธ URGENT when any incident hits 45+ days. Cites 45 CFR ยง 164.404.
When the Regulatory Pulse ingests a High-risk event (score โฅ 8), ACIS opens a GitHub pull request automatically โ creating a compliance alert file with Claude's full risk assessment, required action, and source citation. The compliance administrator reviews and merges. Demo PR #1 is open: HHS Notice of Benefit and Payment Parameters for 2027 (Risk: 9/10).
ACIS was built as a general healthcare compliance platform. Adapting it for BRMS would require approximately two weeks of configuration:
Data layer:
Compliance layer:
baa_status, baa_expiry, baa_signed_by)Reporting layer:
The traditional compliance administrator model requires constant manual effort: reading bulletins, updating spreadsheets, chasing attestations, writing incident reports, reviewing vendor SOC 2 reports. The ceiling on what one person can manage is defined by hours in a day.
ACIS redefines that ceiling. With ACIS deployed:
One compliance administrator with ACIS operates at the throughput of a three-person compliance team โ with an audit trail, an AI reasoning log, and a self-monitoring system that reports its own health daily.
That is not a role description. It is a competitive advantage for the organization that deploys it.