Metric BeforeAfter 90 Days
etcd encryption mode EBS volume only KMS application-layer + EBS
API server audit log retention 7 days 6 years (365 days queryable, full term archived)
MFA coverage on cluster admin paths ~30% 100%
NetworkPolicy coverage on PHI namespaces 0% (no policies) 100% (block-by-default)
Mean time to detect suspicious pod activity undefined ~4 minutes
PHI services with full audit-on-read coverage 8 of 11 11 of 11
Image scans before PHI deploys none every CI run
Vulnerability scan frequency ad-hoc biannual + on every build
Penetration test frequency None in prior 24 months annual, scheduled
Open HIPAA findings on the cluster 11 0