Skip to content

feat(compliance): fix dead trend chart, add remediation lifecycle + HIPAA seed - #42

Merged
xuyushun441-sys merged 1 commit into
mainfrom
optimize/compliance
Jun 14, 2026
Merged

xuyushun441-sys merged 1 commit into
mainfrom
optimize/compliance

Conversation

@xuyushun441-sys

Copy link
Copy Markdown
Contributor

Why

  • The charter's flagship "Assessments by Month" chart filtered on a status (complete) that doesn't exist — the real terminal results are passed/partial/failed — so it always rendered empty.
  • A failed/partial finding had a plan + due date but no way to track the fix to closure, and no overdue signal — the heart of post-assessment work was invisible.
  • The charter targets health-tech (SOC2/ISO27001/HIPAA/GDPR) but the seed shipped no HIPAA.

What changed (within the 4-object cap)

  • Dead chart fixed: filter on status ∈ {passed, partial, failed}.
  • Remediation lifecycle: remediation_status (open / in_progress / resolved / risk_accepted) + is_remediation_overdue formula + an "Open Remediations" assessment tab; seeded so the tab has data.
  • HIPAA seed: HIPAA Security Rule framework + two controls (164.308(a)(1), 164.312(a)(1)).
  • Removed stale failing_table / expiring_evidence_table dashboard translation keys (retired to object-bound tabs).

en + zh-CN updated.

Verification

typecheck + objectstack build + repo format:check clean. Build: 4 Objects / 44 Fields.

🤖 Generated with Claude Code

…IPAA seed

- The flagship "Assessments by Month" chart filtered on status 'complete', a
  value that doesn't exist (the real terminal results are passed/partial/
  failed), so the chart always rendered empty. Filter on the real statuses.

- Remediation lifecycle: a failed/partial finding had a plan + due date but no
  way to track it to closure. Add `remediation_status` (open / in_progress /
  resolved / risk_accepted) and an `is_remediation_overdue` formula (past due
  and not resolved/accepted), plus an "Open Remediations" assessment tab. Seed
  the failed/partial assessments with a remediation status so the tab has data.

- HIPAA: the charter targets health-tech (SOC2/ISO27001/HIPAA/GDPR) but the
  seed shipped no HIPAA. Add a HIPAA Security Rule framework + two controls
  (164.308(a)(1) Security Management, 164.312(a)(1) Access Control).

- Remove stale dashboard widget translation keys (failing_table /
  expiring_evidence_table) that were retired to object-bound tabs (ADR-0017).

en + zh-CN updated. typecheck + objectstack build + format:check clean
(4 Objects).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@xuyushun441-sys
xuyushun441-sys merged commit 9625c8b into main Jun 14, 2026
3 checks passed
@xuyushun441-sys
xuyushun441-sys deleted the optimize/compliance branch June 14, 2026 23:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants