All solutionsIndustry For healthcare and health tech

A breach of 500 records is published with your name on it.

HIPAA gives you 60 days to report a breach affecting 500 or more people, and the list is public. DeDups finds the open bucket, the unencrypted snapshot and the forgotten test database before someone else does, then fixes it once a person approves.

15 minutes to connect. No credit card. No sales call.
60 daysto report a breach of 500+ records

And it goes on a public list. Reputation is part of the penalty, not a side effect of it.

The problem

Patient data rarely leaks from the main system.

It leaks from the copy. A snapshot restored into staging to chase one bug. A bucket opened up so a partner could pull a single file. An old backup nobody has looked at since the migration. The main system is protected and audited. The copy is the one that ends up in the news.

  • A staging environment holds real patient records nobody remembers loading.
  • A storage bucket is public because it was the quick way that week.
  • Backups are encrypted and the snapshots of them are not.
How DeDups solves it

Find the copy. Close it. Prove it was closed.

Every store in every connected account is checked continuously - not just the ones on the architecture diagram. Exposure is flagged the same hour it appears, and the fix is recorded as evidence.

  1. 01Find every store

    Every bucket, database, volume, snapshot and backup across your cloud accounts - including the ones that are not on anyone’s list.

  2. 02Check exposure and encryption

    Public access, missing encryption, weak keys and over-broad roles are raised the same hour they appear.

  3. 03Fix with a dry run and an approval

    The change is shown before it happens, approved by a person, applied, then verified. A failed verification rolls back on its own.

  4. 04Keep the HIPAA evidence

    Every passing check becomes dated evidence tagged to HIPAA, SOC 2 and ISO 27001 controls, ready to export.

What you get

The numbers, and what sits behind them.

Every hourstorage is re-checked
1,000+checks per account
Rollbackon failed verification

Public-access, encryption and key checks on every store, snapshot and backup

Findings routed to the named owner on Slack, Jira or email

Dry run, human approval, verification and automatic rollback

HIPAA, SOC 2 and ISO 27001 evidence collected while you work

Laptop and server inventory through the Inspector agent, cloud or not

Full audit trail of every finding, message, approval and fix

Machine speed, human judgement

It reads settings, not records.

DeDups can tell you a bucket holding patient data is open to the internet. It does not open the bucket. Every check runs against configuration through your cloud provider’s own API, and every change waits for a person to approve it.

HIPAASOC 2ISO 27001GDPRDPDP Act
Before you commit

The questions we get asked most.

No. It reads configuration, not records. It can tell you a store is public, unencrypted or reachable by too many roles. It does not read what is inside it.

Ask on the demo call and we will answer plainly before you commit to anything. We would rather say no early than surprise you after a signature.

The Inspector agent covers Windows, macOS and Linux hosts wherever they run and reports installed software and known vulnerabilities. It needs no cloud account.

Get started

Start with your own numbers.

Connect one account. The first scan finishes in about 15 minutes and the report is yours either way - free, no credit card, no sales call. Read it, then decide.

sales@dedups.ai - we reply within 2 hours