Aegis / Clearwater Medical - Comply v2 Deployment Kickoff
44 turns · 9 min captured of 43 min stated?Only the captured portion exists in the database. The remaining 34 min of this call was never transcribed, so nothing said in it appears anywhere in this application.
Showing 44 of 44 turns · 30 turns were used as evidence for at least one fact.
- Aisha JohnsonAegisCloud0:04turn 0ASR 97%
Alright, I think we've got everyone on now — Natalie, Ajay, good to see you both, welcome to the Comply v2 kickoff!
- Natalie SimmonsCustomer0:13turn 1ASR 97%
Thanks Aisha, really excited to finally be here, it feels like we've been building up to this for a while.
+1Natalie says she is really excited to finally be here. · other
- Natalie SimmonsCustomer0:21turn 2ASR 94%
Yeah, same here, we've been looking forward to getting started — Ajay especially, he's been, uh, chomping at the bit on the compliance side.
- Ajay MehtaCustomer0:30turn 3ASR 92%
Ha, guilty as charged — our last audit cycle was, let's just say, not fun, so anything that makes that smoother is a win in my book.
- Aisha JohnsonAegisCloud0:41turn 4ASR 94%
We totally hear you on that, and honestly that's exactly what Comply v2 was built for, so I think you're going to be really happy — let me also just quickly introduce Kevin and Mike who are joining me today.
- Kevin O'BrienAegisCloud0:56turn 5ASR 92%
Hey everyone, Kevin O'Brien here, Solutions Architect — I'll be the one getting into the weeds with you on the technical deployment side, really glad to be on this call.
- Mike RomanoAegisCloud1:08turn 6ASR 93%
And I'm Mike Romano, Staff Engineer, so I'm sort of Kevin's partner in crime on the implementation — if anything breaks I'm the one you can blame.
- Ajay MehtaCustomer1:18turn 7ASR 94%
Ha, we'll hold you to that Mike.
- Aisha JohnsonAegisCloud1:22turn 8ASR 89%
So before we dive in, I just want to set the agenda real quick — we're going to walk through the Comply v2 feature set, talk about your specific compliance framework needs, get into the deployment plan, and then leave time at the end for questions and next steps, does that work for you both?
- Natalie SimmonsCustomer1:42turn 9ASR 89%
That sounds perfect, yeah.
- Aisha JohnsonAegisCloud1:45turn 10ASR 95%
Great — so, big news, and I mean this is actually really good timing for you guys, Comply v2 went GA literally today, April 7th, so you are among the very first customers to be onboarding onto the new version.
- Natalie SimmonsCustomer2:00turn 11ASR 93%
Oh wow, we didn't realize we were that early in the queue — that's kind of exciting actually.
+1Natalie says being early in the Comply v2 onboarding queue is kind of exciting. · onboarding and implementation
- Aisha JohnsonAegisCloud2:07turn 12ASR 89%
Yeah it's genuinely exciting, and the headline feature that I know is going to matter a lot for Clearwater specifically is the on-demand reporting — so rather than waiting for scheduled report runs, your compliance team can pull a SOC 2 or HIPAA report literally whenever they need it.
- Ajay MehtaCustomer2:26turn 13ASR 96%
Okay that — that right there is huge, because our last HIPAA audit we were scrambling to pull together evidence at like eleven at night, so on-demand is just... yeah, that's the thing.
+1Ajay calls on-demand reporting huge and contrasts it with a past late-night audit scramble. · compliance reporting
- Aisha JohnsonAegisCloud2:39turn 14ASR 97%
Yeah and the other thing I want to highlight is the multi-framework support, so Comply v2 covers SOC 2, PCI DSS, HIPAA, and ISO 27001 all in one place — Kevin, do you want to speak a bit to how that's structured under the hood?
- Kevin O'BrienAegisCloud2:55turn 15ASR 97%
Sure, yeah — so the way it works is that the platform uses a unified control mapping layer, which means a single data point or evidence artifact can satisfy requirements across multiple frameworks simultaneously, so if you're doing HIPAA and SOC 2, you're not duplicating work, the system handles the cross-mapping automatically.
- Ajay MehtaCustomer3:14turn 16ASR 97%
That is — okay that is actually really smart because that was one of my biggest pain points, I was maintaining like three separate spreadsheets for three different frameworks and it was just, ugh, it was a mess.
+1Ajay says the unified control mapping is really smart and removes a big pain point. · compliance reporting
- Kevin O'BrienAegisCloud3:28turn 17ASR 88%
Yeah the spreadsheet era is officially over for you, which is, I think, cause for celebration.
- Aisha JohnsonAegisCloud3:35turn 18ASR 94%
So Natalie, I know from our earlier conversations that HIPAA is obviously the primary framework given that you're in healthcare, but can you give us a sense of what else is on your radar — I believe PCI came up at some point?
- Natalie SimmonsCustomer3:50turn 19ASR 91%
Yeah, so HIPAA is definitely the big one, that's non-negotiable for us — but we also process some payment data through our patient portal so PCI DSS is relevant, and then our board has been nudging us toward ISO 27001 as more of a longer-term goal, maybe end of year.
- Kevin O'BrienAegisCloud4:10turn 20ASR 94%
That's actually a really common progression we see in healthcare organizations, and the good news is you can start with HIPAA and PCI in Comply v2 and then ISO 27001 just kind of layers on without a big lift — Mike, can you talk a little bit about the deployment sequence we'd recommend here?
- Mike RomanoAegisCloud4:30turn 21ASR 94%
Yeah absolutely — so for Clearwater, what I'd suggest is we start with the data connector setup first, getting your cloud environment piped into the platform, and then we layer in the HIPAA framework configuration, run a baseline report, and that gives you an immediate lay of the land before we touch anything else.
- Natalie SimmonsCustomer4:51turn 22ASR 91%
How long does that initial connector setup typically take, like are we talking hours or days?
- Mike RomanoAegisCloud4:57turn 23ASR 92%
For a cloud environment your size, honestly, the connector piece is usually a few hours if everything goes smoothly — I'd say plan for a full day just to give yourself buffer, and then the HIPAA baseline report can actually run that same day once data is flowing.
- Natalie SimmonsCustomer5:14turn 24ASR 88%
Oh that's faster than I expected, honestly I was bracing for like a week of setup.
+1Natalie says the setup time is faster than she expected. · onboarding and implementation
- Kevin O'BrienAegisCloud5:21turn 25ASR 90%
Yeah v2 specifically made a big push to reduce that time to first value — the old version had a lot more manual configuration steps and we heard that feedback pretty loudly from customers, so that was a big focus area.
- Aisha JohnsonAegisCloud5:36turn 26ASR 90%
Ajay, while we're on the topic, what does your typical audit cycle look like — like how far in advance do auditors usually come knocking?
- Ajay MehtaCustomer5:47turn 27ASR 92%
So for HIPAA we get maybe, um, thirty days notice if we're lucky, sometimes it's less, and then SOC 2 we're actually pursuing type two for the first time this year so that's more of an ongoing thing over like a six month observation period.
- Kevin O'BrienAegisCloud6:04turn 28ASR 89%
Okay so the SOC 2 type two use case is actually perfect for Comply v2 because the continuous monitoring integration means evidence is being collected automatically throughout that observation window, so you're not trying to reconstruct what happened six months ago.
- Ajay MehtaCustomer6:18turn 29ASR 90%
That alone might have saved me from that eleven PM scramble situation — like if I'd had this six months ago...
+1Ajay says continuous monitoring might have saved him from the late-night scramble. · product capability
- Aisha JohnsonAegisCloud6:28turn 30ASR 93%
Ha, well you have it now — and honestly given your SOC 2 timeline, the sooner we get you live the better, because that observation period clock is sort of always ticking.
- Ajay MehtaCustomer6:39turn 31ASR 92%
Yeah that's a really good point, I want to make sure we're not losing any time — Natalie, should we try to target getting the connectors up this week?
- Natalie SimmonsCustomer6:51turn 32ASR 94%
I think so, yeah — Mike, what do you need from us to get that started, like what does the prep checklist look like on our end?
- Mike RomanoAegisCloud7:02turn 33ASR 95%
So the main things are going to be CloudPrime or Azure — which cloud provider are you on?
- Natalie SimmonsCustomer7:09turn 34ASR 90%
We're primarily CloudPrime, we have a small Azure footprint but like eighty percent is CloudPrime.
- Mike RomanoAegisCloud7:16turn 35ASR 93%
Perfect, CloudPrime is very well-trodden ground for us — so you'll need to create an IAM role with read permissions that we can assume, I'll send you a CloudFormation template that does that in about five minutes, and then just make sure your CloudTrail logging is enabled across all regions.
- Natalie SimmonsCustomer7:34turn 36ASR 89%
CloudTrail should already be on, we turned that on a while back — I'll double check the multi-region piece but I'm pretty confident we're good there.
- Mike RomanoAegisCloud7:44turn 37ASR 93%
Great, that's going to make things really smooth — and once I send that template over, you or your team can run it in maybe ten minutes and then just send me the role ARN and we're off to the races.
- Natalie SimmonsCustomer7:58turn 38ASR 97%
This is, honestly, way more straightforward than I anticipated — I had kind of mentally prepared for this to be a whole thing.
+1Natalie says the deployment is way more straightforward than anticipated. · onboarding and implementation
- Kevin O'BrienAegisCloud8:07turn 39ASR 93%
We appreciate you saying that — a lot of work went into making this less painful and it's nice to hear it's landing that way.
- Aisha JohnsonAegisCloud8:17turn 40ASR 88%
So let's talk about next steps and timeline — what I'm thinking is Mike sends over that CloudFormation template today, we target connector setup early this week, baseline HIPAA report by maybe Wednesday or Thursday, and then we reconvene late this week to review the first report together — does that sound reasonable?
- Natalie SimmonsCustomer8:37turn 41ASR 93%
That sounds great to me — Ajay, does Thursday work for you for that review call?
- Ajay MehtaCustomer8:44turn 42ASR 92%
Thursday works, yeah — and honestly I'm just really glad we're moving this fast, this has been a long time coming for our compliance program and I feel really good about where this is headed.
+1Ajay says he is really glad they are moving fast and feels good about where this is headed. · onboarding and implementation
- Aisha JohnsonAegisCloud8:58turn 43ASR 93%
That's exactly what we want to hear — alright, I'll get a Thursday invite out to everyone, and in the meantime don't hesitate to reach out if anything comes up, we are very much in this together.