← Back to the call brief
External21 Apr 2026· Blackridge Investments22% captured

Aegis / Blackridge Investments - HIPAA Compliance Review

46 turns · 12 min captured of 49 min stated?Only the captured portion exists in the database. The remaining 37 min of this call was never transcribed, so nothing said in it appears anywhere in this application.

Show facts?Markers in the left gutter show which facts the model built from each turn. Click a marker to open that fact's evidence — this is the citation trail running backwards.

Showing 46 of 46 turns · 29 turns were used as evidence for at least one fact.

  1. Warren BeckCustomer0:07turn 0ASR 90%

    Good morning everyone, thanks for jumping on — Lisa, Maria, can you hear us okay?

  2. Lisa ParkAegisCloud0:14turn 1ASR 89%

    Yeah, loud and clear Warren, good morning! Thanks for making time for this — I know your calendar's been pretty packed lately.

  3. Maria SantosAegisCloud0:23turn 2ASR 91%

    Morning! Really excited for this one, we have a lot of good stuff to walk through today.

  4. Julia TranCustomer0:31turn 3ASR 96%

    Morning everyone, Julia Tran here from the security team — looking forward to digging into the HIPAA piece specifically.

  5. Lisa ParkAegisCloud0:38turn 4ASR 92%

    Perfect, yeah, that's really the main focus for us today. Um, so just to set the stage a little — Warren, do you want to give everyone a quick overview of where Blackridge is at from a compliance standpoint before we jump in?

  6. Warren BeckCustomer0:55turn 5ASR 93%

    Sure, yeah, happy to. So, uh, as you know we're primarily a financial services firm, right, but we have a subsidiary — Blackridge Health Finance — that handles healthcare lending and some benefits administration, and that arm of the business has to be fully HIPAA compliant. We went through an internal audit last quarter and honestly, the reporting piece was just... it was painful. A lot of manual work, a lot of spreadsheets, and our auditors were not happy.

    -1Warren describes the internal audit's reporting as painful, with manual work and unhappy auditors. · compliance reporting

  7. Maria SantosAegisCloud1:24turn 6ASR 91%

    Yeah, that's such a common story and it's — honestly it's one of the exact things that the new Comply v2 release was built to address. Julia, I'm curious, from your perspective on the analyst side, where were the biggest friction points in that audit process?

  8. Julia TranCustomer1:41turn 7ASR 94%

    So, um, the biggest thing for me was just the evidence gathering. Like I was spending, I don't know, probably two full weeks before the audit just pulling logs from different systems, trying to reconcile timestamps, making sure our access control documentation was current. It was... yeah, it was a lot of manual effort that felt like it shouldn't have to be manual.

    -1Julia says she spent about two weeks pulling logs and reconciling timestamps for the audit. · compliance reporting

  9. Lisa ParkAegisCloud2:05turn 8ASR 88%

    Two weeks — yeah, that's significant. And that's two weeks of your time that's not going toward actual security work.

  10. Julia TranCustomer2:13turn 9ASR 96%

    Exactly, exactly. And we had a near-miss on a deadline last time because of it, so Warren kind of lit a fire under us to find a better solution.

    -1Julia mentions a near-miss on an audit deadline that prompted the search for a better solution. · compliance reporting

  11. Warren BeckCustomer2:25turn 10ASR 91%

    Right, and that's — that's kind of what led us back to this conversation with Aegis. We've been running Protect and Identity for about, what, eight months now? And those have been really solid. So when Lisa mentioned that the Comply module had a major update, it felt like the right time to take a closer look.

    +1Warren says Protect and Identity have been really solid over eight months. · service reliability

  12. Maria SantosAegisCloud2:46turn 11ASR 92%

    Yeah, exactly, and honestly Warren your timing could not be better. So Aegis Comply v2 went generally available on April 7th — just a couple weeks ago — and the headline feature for a customer in your situation is really the on-demand compliance reporting. So instead of that two-week evidence gathering scramble, you can generate a full HIPAA report... basically whenever you need it. On demand.

  13. Julia TranCustomer3:10turn 12ASR 94%

    When you say on-demand, are we talking like, I click a button and it's done in minutes, or is there still some configuration and setup time involved?

  14. Lisa ParkAegisCloud3:20turn 13ASR 96%

    Great question. So there's an initial configuration pass — you're mapping your environment, defining your scope, connecting your data sources — and that typically takes, uh, Maria correct me if I'm off, but somewhere in the range of a few days to maybe a week depending on environment complexity?

  15. Maria SantosAegisCloud3:38turn 14ASR 92%

    Yeah, that's right. For a environment like yours where you already have Aegis Identity and Protect running, honestly it could be even faster because we're already pulling a lot of the relevant signals. The IAM data, the access logs, the backup records — a lot of that is already flowing into the platform. So once Comply is scoped and configured, generating a HIPAA report is... yeah, it's essentially a few clicks.

  16. Julia TranCustomer4:04turn 15ASR 91%

    Okay, that's — that's actually really compelling. Because right now it's like, we have all this data in various places and it's just not... connected in any meaningful way for audit purposes.

    +1Julia calls on-demand reporting compelling because audit data is currently unconnected. · compliance reporting

  17. Maria SantosAegisCloud4:16turn 16ASR 94%

    That's exactly the problem Comply v2 was designed to solve. And you mentioned HIPAA but I do want to flag — the multi-framework support is a big part of this release too. So you get SOC 2, PCI DSS, ISO 27001 all in the same platform. Given that you're in financial services, I'd imagine PCI DSS is also on your radar.

  18. Julia TranCustomer4:38turn 17ASR 93%

    Oh yeah, absolutely. We have a separate compliance cycle for PCI and right now that's managed by a completely different team using completely different tools, so the idea of consolidating that is... yeah, Warren, that's something we've talked about.

  19. Warren BeckCustomer4:52turn 18ASR 96%

    We have, yeah. I mean, the consolidation story is attractive from a cost standpoint and also just from an operational standpoint. Having one pane of glass for compliance across frameworks — that's something our board has actually been asking about.

    +1Warren says consolidating compliance frameworks is attractive and the board has been asking about it. · compliance reporting

  20. Lisa ParkAegisCloud5:07turn 19ASR 91%

    That's great to hear, and I think that's a really strong use case we can build out for you. But let's stay focused on HIPAA for now since that's the urgent one — we can absolutely come back to the multi-framework story. Maria, do you want to walk through what a HIPAA report actually looks like in v2?

  21. Maria SantosAegisCloud5:28turn 20ASR 88%

    Yeah, definitely. So I'm going to pull up a sample report here — bear with me one second — okay, so what you're seeing is the executive summary view, which is what you'd typically hand to an auditor or your leadership team. It maps your controls directly to the HIPAA Security Rule safeguards — administrative, physical, technical. Each control has a status, an evidence log, and a timestamp. Auditors love the timestamp piece because it removes a lot of the back and forth.

  22. Julia TranCustomer5:57turn 21ASR 94%

    Oh, that's really clean actually. Can you click into — um, can you show the technical safeguards section? That's typically where we have the most scrutiny.

  23. Maria SantosAegisCloud6:07turn 22ASR 93%

    Of course, yeah. So here you can see access controls, audit controls, integrity controls, transmission security — each one has a detailed evidence panel. And if you have a gap, it'll flag it and give you a recommended remediation action. It's not just telling you that you have a problem, it's pointing you toward how to fix it.

  24. Julia TranCustomer6:29turn 23ASR 97%

    Okay I have to say, that remediation guidance piece is something we're missing completely right now. Like our current process is finding a gap and then going okay, now what? And it usually involves a lot of internal back and forth.

    +1Julia says remediation guidance is something they are missing completely right now. · product capability

  25. Lisa ParkAegisCloud6:44turn 24ASR 90%

    Yeah, and that back and forth is where time really bleeds out. And honestly, Warren, from a CISO perspective, that remediation guidance also gives you a cleaner audit trail to show that gaps were identified and actioned — which is exactly what regulators want to see.

  26. Warren BeckCustomer7:02turn 25ASR 90%

    That's a really good point. The ability to demonstrate that we have a process for finding and remediating issues is almost as important as the issues themselves in the eyes of HHS.

  27. Lisa ParkAegisCloud7:14turn 26ASR 95%

    Exactly, yeah. So, um, I do want to just mention one thing — and Maria, jump in here — but we did have a period of instability on the Detect side back in March, some of you may have been aware of that. We were very upfront about it. That was a six-hour window where event processing had an issue. That's been fully resolved with redundant nodes and a circuit breaker pattern, and I want to be transparent that we took that very seriously.

  28. Warren BeckCustomer7:45turn 27ASR 88%

    Yeah, we did see the incident notification. Appreciate that you were proactive about communicating it. Honestly, the transparency there actually... it increased my confidence in Aegis a little, weirdly enough. Like you didn't try to hide it.

    +2Warren says Aegis's transparency about the incident increased his confidence. · support experience

  29. Maria SantosAegisCloud7:58turn 28ASR 88%

    That means a lot to hear, Warren, really. And just to be clear, Comply v2 — the reporting infrastructure — runs on a completely separate pipeline from the Detect event processing, so that incident has no bearing on the compliance reporting capabilities.

  30. Warren BeckCustomer8:13turn 29ASR 89%

    Good to know, and yeah, I didn't think it was related but it's good to have that confirmed. Julia, any other questions on the technical side before we talk about next steps?

  31. Julia TranCustomer8:26turn 30ASR 89%

    Um, yeah, one thing — what does the scheduling look like? Can we set up automated recurring reports or is it purely on-demand?

  32. Maria SantosAegisCloud8:35turn 31ASR 89%

    Both, actually. You can do on-demand whenever you need a fresh snapshot, but you can also configure scheduled reports — monthly, quarterly, whatever cadence makes sense for your audit cycles. And they get delivered to whatever stakeholders you define, so Warren could get an executive summary automatically without Julia having to manually generate and send it.

  33. Julia TranCustomer8:55turn 32ASR 90%

    Oh that's a nice feature. Yeah, I currently send Warren a monthly compliance status email that takes me like an hour to put together. That's... I could see that going away.

    +1Julia says the scheduled report feature could eliminate her hour-long monthly compliance email. · compliance reporting

  34. Warren BeckCustomer9:08turn 33ASR 92%

    Ha, one less thing on your plate, Julia.

  35. Julia TranCustomer9:12turn 34ASR 90%

    I'll take it! Um, one more question — and this is maybe a bigger one — what does the integration look like with our existing SIEM? We're running LogVault.

  36. Maria SantosAegisCloud9:23turn 35ASR 94%

    LogVault is fully supported, yeah. We have a native connector — it's not a custom integration, it's out of the box. So Comply can pull relevant log data from LogVault as part of the evidence collection, which again reduces the manual work significantly.

  37. Julia TranCustomer9:40turn 36ASR 91%

    Okay, that's a big one for us. We were a little worried we'd have to do some heavy lifting on the integration side but that's — that's reassuring.

    +1Julia calls the native LogVault integration a big one and reassuring. · product capability

  38. Lisa ParkAegisCloud9:50turn 37ASR 94%

    So from a next steps standpoint — and I want to make sure we're leaving this call with something concrete — I'd love to propose that we put together a scoped proof of concept specifically for the HIPAA reporting against your Blackridge Health Finance environment. We can have our implementation team map out the configuration, give you a realistic timeline, and then do a demo with your actual data architecture. Does that sound like a reasonable path forward?

  39. Julia TranCustomer10:19turn 38ASR 91%

    Yeah, I think that makes a lot of sense. Warren, what do you think?

  40. Warren BeckCustomer10:24turn 39ASR 93%

    I think so, yeah. I'd want our legal and compliance team looped in before we go too far down the path, but a scoped POC sounds like the right way to validate the approach. Lisa, can you get us a proposed timeline for that?

  41. Lisa ParkAegisCloud10:41turn 40ASR 90%

    Absolutely, I'll have something over to you by end of week. And I'll include a contact from our implementation team so Julia can connect directly with them on the technical environment questions. Maria, anything else you want to cover before we close out?

  42. Maria SantosAegisCloud10:57turn 41ASR 93%

    Just one thing — I'll send over the v2 release notes and a sample HIPAA report PDF after this call so Julia and the team can review it offline. And Warren, I'll include some customer case studies from other regulated industries — not exactly financial services but close enough that they should resonate.

  43. Warren BeckCustomer11:16turn 42ASR 90%

    That's great, really appreciate it. This has been a really productive conversation — honestly more than I expected going in. I feel like we have a clear path forward here.

    +2Warren says the conversation was really productive and more than expected, with a clear path forward. · other

  44. Julia TranCustomer11:28turn 43ASR 88%

    Same, yeah. Thank you both, this was super helpful.

    +1Julia says the call was super helpful. · other

  45. Lisa ParkAegisCloud11:33turn 44ASR 94%

    Really appreciate your time Warren, Julia. We're excited about this one and I think Comply v2 is going to make a real difference for your team. We'll be in touch by Friday with the POC proposal. Have a great rest of your week everyone.

  46. Maria SantosAegisCloud11:48turn 45ASR 90%

    Thanks everyone, take care!