Pular para o conteúdo

Product

Four pillars, fifteen modules, one data model.

higeia covers the full governance cycle the sector was missing. Every module speaks to the others through the same data model. Nothing lives in a silo.

LGPD Compliance

The regulatory core of the governance operation.

Treatment Inventory

Treatments with purpose, legal basis under art. 11 of LGPD, data categories, data subjects, sharing, retention and attached evidence. Inheritance across units, full versioning, native links to controls and third parties.

  • Structured registration by purpose, legal basis and data category
  • Treatment inheritance across units (parent → branch)
  • Full versioning with diff between versions
  • Native links to controls, policies and third parties
  • Configurable fields by sector (hospital, clinic, laboratory)
  • Export to ANPD report in structured format

Assisted DPIA

Structured risk assessment from the source treatment, with probability, impact, vulnerability, threat and residual risk factors. AI produces narrative; DPO reviews and approves. Configurable review cycle.

  • DPIA generation from registered treatment
  • Risk matrix with 5 factors: probability, impact, vulnerability, threat, residual
  • First narrative generated by AI with versioned prompt
  • Review and approval workflow with named responsibility
  • Configurable review cycle (quarterly, biannual, annual)
  • Complete version history with diff between revisions

Policy Library

Documents with versioning, diff between versions, configurable approval workflow, review cadence and links to treatments, controls and third parties.

  • Structured editor with native versioning
  • Visual diff between versions for quick review
  • Configurable approval workflow by document type
  • Review cadence with automatic alerts
  • Links to affected treatments, controls and third parties
  • Pre-loaded templates for privacy, security and retention policies

Third-Party Due Diligence

Configurable questionnaires by third-party category, deterministic scoring, action plan, periodic review and links to treatments where each third party operates.

  • Configurable questionnaires by category (laboratory, IT, marketing)
  • Deterministic score calculated by auditable formula
  • Action plan with deadlines and owners
  • Periodic review with configurable cadence
  • Direct link to treatments where third party operates
  • Templates for the most common healthcare scenarios

Information Security

Technical and operational controls for data protection.

Controls Engine

Controls by domain (identity, data, AI, governance, incident response), with owner, required evidence and cadence. Pre-loaded minimum lists by scenario.

  • Controls organized by functional domain
  • Named owner, required evidence, verification cadence
  • Pre-loaded minimum lists by operational scenario
  • Real-time status: on track, pending, overdue, expired
  • Links to relevant treatments and policies
  • Verification history with attached evidence

Asset Inventory

Information asset catalog with criticality classification, owner, location and links to treatments and controls.

  • Registration of servers, IoMT devices, network and applications
  • Classification by criticality and sensitivity
  • Designated owner and technical officer
  • Links to treatments processing data in the asset
  • Documented lifecycle (acquisition, operation, disposal)
  • Basis for risk analysis and pentest planning

Pentests & Vulnerabilities

Recording and tracking of penetration tests, identified vulnerabilities and remediation plans with CVSS scoring.

  • Internal and external pentest records with scope and methodology
  • Finding catalog with CVSS scoring
  • Remediation plan with owner and deadline
  • Retest tracking and correction validation
  • Links to affected assets and controls
  • Consolidated history by asset and period

Risk Analysis

Risk matrix with probability, impact, inherent and residual risk. Visual heat map and treatment plan by risk.

  • Risk matrix with quantifiable factors
  • Visual heat map by domain and criticality
  • Inherent vs. residual risk after safeguards
  • Treatment plan with owner and cadence
  • Links to assets, controls and treatments
  • Temporal evolution of the organization's risk profile

Security Incidents

Recording, classification and tracking of security incidents with timeline, impact and lessons learned.

  • Structured record with severity classification
  • Incident timeline (detection, containment, eradication, recovery)
  • Impact assessment on affected data subjects and treatments
  • Communication to ANPD and data subjects when applicable
  • Lessons learned and preventive actions documented
  • Client notification deadline: 48 hours after confirmation

Governance

Maturity, interoperability and DPO channel.

Certifications & Frameworks

Tracking certifications and alignment to security and privacy frameworks with control mapping.

  • Control mapping against ISO 27001, ISO 27701, ISO 27799
  • Alignment to NIST CSF 2.0 and CIS Controls v8
  • Support for HIPAA and GDPR for international operations
  • Certification roadmap with milestones and owners
  • Automated gap analysis by framework
  • Exportable maturity report for audits

Healthcare Interoperability

Mapping and documentation of integrations with national and international health standards.

  • Integration with RNDS (National Health Data Network)
  • Support for FHIR (Fast Healthcare Interoperability Resources)
  • TISS/TUSS mapping for health insurers
  • HL7 and DICOM flow documentation
  • Inventory of active integrations by system
  • Compliance assessment by integration point

DPO Portal

Structured channel for data subject requests under LGPD, with service workflow and legal deadlines.

  • Receipt of data subject requests (access, correction, deletion)
  • Service workflow with configurable SLA (default: 5 days)
  • Status tracking and communication with data subject
  • Consent and revocation record
  • Request report by period and type
  • Integration with treatment inventory for data location

Operational

Visibility and traceability for the governance team.

Executive Dashboard

Residual risk by unit, overdue controls, maturity by domain and audit response time. Configurable by role: DPO, CIO, executive management.

  • Consolidated view of residual risk by unit
  • Overdue controls and expired items highlighted
  • Maturity by governance domain
  • Average response time for internal and external audits
  • Filters by role: DPO, CIO, executive, board
  • Executive report export in PDF

Audit Trail

Append-only log with chained hash. Every control, approval and review creates an immutable record.

  • Append-only with chained SHA-256 hash for tamper detection
  • Every action records user, IP, timestamp, previous and new state
  • Minimum retention of 5 years with automatic cold storage
  • AI-assisted summarization for pattern and anomaly detection
  • Audit report export in minutes
  • Chain integrity verification via dedicated endpoint

Configuration

Identity, access, units and integrations. SSO, RBAC, API keys and webhooks in a single panel.

  • SAML 2.0 / OIDC SSO configuration
  • Granular RBAC by unit and module
  • API keys for external integrations
  • Webhook for operational system notifications
  • Multi-unit management with centralized policies
  • Configurable session expiry and MFA

Ready to see higeia in action?

Write to higeia@saude.dev and we'll set up a demo tailored to your organization's context.