โ† All documents

Roadmap & Vision: ACIS at BRMS


Current State (Live Now)

Module Status What It Does
Regulatory Pulse Live 5-source federal feed, daily Claude scoring, 50 of 65 events
Attestation Vault Live RxDC + Gag Clause tracking for 8 client plans
Vendor Risk Live Real TLS/header scanning + Claude HIPAA risk assessment
Incident Response Live NIST 800-61 playbooks auto-generated on every incident
Attestation Reminders Live Daily email when any client attestation is Overdue
Incident Escalation Live Daily email for Open incidents 7+ days; HIPAA OCR countdown
GitHub PR Automation Live High-risk event (score โ‰ฅ 8) โ†’ auto branch + compliance alert PR
Executive Hub Live Single dashboard at acis.rossonlineservices.com
Operations Tab Live Manual triggers, heartbeat view, AI Gateway log streaming
Heartbeat Agent Live Daily self-audit โ†’ Green/Yellow/Red โ†’ CCC Admin report
Agent Logs Live Full AI inference trace visible in Operations tab

Completed Features

โœ… Playbook Agent Upgrade โ€” Complete (2026-04-25)

Upgraded from claude-sonnet-4-6 to claude-opus-4-7. CFR citation precision and phase-level specificity measurably improved. Every new incident receives an Opus-quality playbook.

โœ… Attestation Email Reminders โ€” Complete (2026-04-26)

Daily cron checks for rxdc_status = 'Overdue' or gag_clause_status = 'Overdue'. When found, sends an HTML summary table to the compliance administrator via Resend. No-op on clean days โ€” no spam.

โœ… Incident Escalation Notifications โ€” Complete (2026-04-26)

Daily cron checks for incidents open longer than 7 days. Email includes days-open count and HIPAA OCR window countdown per incident. Subject line escalates to โš ๏ธ URGENT when any incident hits 45+ days. Cites 45 CFR ยง 164.404.

โœ… GitHub PR Automation โ€” Complete (2026-04-27)

When the Regulatory Pulse ingests a High-risk event (score โ‰ฅ 8), ACIS opens a GitHub pull request automatically โ€” creating a compliance alert file with Claude's full risk assessment, required action, and source citation. The compliance administrator reviews and merges. Demo PR #1 is open: HHS Notice of Benefit and Payment Parameters for 2027 (Risk: 9/10).


BRMS-Specific Adaptation (If Deployed)

ACIS was built as a general healthcare compliance platform. Adapting it for BRMS would require approximately two weeks of configuration:

Data layer:

Compliance layer:

Reporting layer:


The Vision: Compliance as Infrastructure

The traditional compliance administrator model requires constant manual effort: reading bulletins, updating spreadsheets, chasing attestations, writing incident reports, reviewing vendor SOC 2 reports. The ceiling on what one person can manage is defined by hours in a day.

ACIS redefines that ceiling. With ACIS deployed:

One compliance administrator with ACIS operates at the throughput of a three-person compliance team โ€” with an audit trail, an AI reasoning log, and a self-monitoring system that reports its own health daily.

That is not a role description. It is a competitive advantage for the organization that deploys it.

Requirement AlignmentThe Build Story