Skip to content

Compliance

Different rules. The same five controls underneath.

HIPAA, SOX, FERPA and your state's records law use different words, but they ask your documents the same things: who could see them, what happened to them, and how long you kept them. Content Central gives you those controls and the records that show they ran.

  • HIPAA

    Permissions and MFAAudit trailVersion historyRetention and legal holds

  • SOX

    Version historyAudit trailRetention and legal holds

  • GLBA Safeguards Rule

    Permissions and MFAAudit trailRetention and legal holds

  • FERPA

    Permissions and MFAAudit trail

  • State public records laws

    SearchRetention and legal holds

  • Privacy laws (GDPR, state laws)

    Permissions and MFARetention and legal holdsSearch

Which controls each set of rules leans on most.

Your rules, in plain words, and the controls that help.

Short summaries to orient you, not legal advice. Your counsel and auditors decide what your organization must do.

GLBA Safeguards Rule

Financial institutions under the FTC rule, including many lenders, brokers and tax preparers.

A written security program with access controls, multi-factor authentication for anyone accessing customer information, logging of user activity, and disposal of customer information on a set schedule.

FERPA

Schools, colleges and universities that receive federal education funds.

Education records are disclosed only as the law allows, and the school keeps a record of each request for and disclosure of a student’s records.

State public records laws

Cities, counties, school districts and state agencies.

Answer records requests within the time your state sets, and keep and destroy records on the schedule your state archives approves.

Privacy laws (GDPR, state laws)

Organizations holding personal data about EU residents or residents of states with privacy laws.

Keep personal data secure and no longer than needed, and be able to find what you hold about a person when they ask.

Healthcare customers: Ademero signs Business Associate Agreements. About our BAA

Audit week

What you open when the auditor sits down.

Each item is a screen or a report in Content Central. The Event Viewer is read on screen; reports and search results save as files.

  • Who has accessThe Document Type Permissions screen for each type in scope.
  • Activity in the audit periodThe Event Viewer filtered by date range, user and action.
  • The life of one recordIts version history: created, changed, approved, signed, with names and times.
  • What is due to be destroyedThe Retention Policies page, with anything pending removal shown in red.
  • Approvals in the periodA Documents by Approval Process report, saved as CSV.
  • Everything matching a requestA saved search, with the results exported to CSV or Excel.

Why you will not read "compliant" on this page

Software cannot make an organization compliant. Your policies, your people and your auditors do that. What Content Central does is enforce the access, retention and review rules you set on every document, in the cloud or on your own servers, and keep the record that shows it. Fortune 500 companies and government agencies review Ademero's security every year.