{
    "$schema": "https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json",
    "serviceIdentification": {
      "fedRampPackageId": "86Borders-ConnectAllCare",
      "ueiNumber": "",
      "providerName": "86Borders LLC",
      "serviceName": "86Borders ConnectAllCare",
      "serviceAcronym": "86B-CAC",
      "serviceDescription": "86Borders is the trusted partner for health plans seeking measurable outcomes and quality improvement through human-first member engagement. By pairing local Care Coordinators with our ConnectAllCare (CAC) platform, we help payers and other risk-bearing entities reach hard-to-engage members, overcome social and behavioral barriers, and translate genuine connection into improved outcomes, higher quality scores, and healthier communities. 86Borders ConnectAllCare is a cloud-based healthcare coordination platform managing patient engagement and social care, deployed on AWS Commercial infrastructure.\n\n### Certification Package Metadata [CPO-CSO-MTD]\n- **Accountable Official:** Dan McDonald, Chief Executive Officer (CEO) (dmcdonald@86borders.com)\n- **Version:** 1.0.0\n- **Date and Time of Last Update:** 2026-08-28T15:08:00Z\n- **Source of Update:** Manual",
      "certificationType": "20x",
      "website": "https://www.86borders.com",
      "logo": "https://www.86borders.com/wp-content/uploads/2026/07/86Borders-Logo-scaled-2.png"
    },
    "serviceProperties": {
      "serviceType": [
        "SaaS"
      ],
      "deploymentModel": "Public Cloud",
      "businessCategory": [
        "Health & Wellness"
      ],
      "trustCenter": {
        "repositoryType": [
          "Trust Center"
        ],
        "url": "https://trust.paramify.com/86borders",
        "repositoryDescription": "Central Trust Center containing security posture data, continuous monitoring artifacts, and system architecture/information flow diagrams per [MAS-CSO-FLO] (Dataflow Diagram: https://86borders.atlassian.net/wiki/spaces/HC/pages/4979327048; Network Diagram: https://86borders.atlassian.net/wiki/x/V4HKKAE).",
        "authenticationRequired": true,
        "accessRequestInstructions": "Select the 'Request Access' button on desired document to request access to a specific document. To gain access to all trust center documents, select the blue 'Request Access' button."
      },
      "secureConfigurationGuidance": {
        "repositoryType": [
          "Trust Center / Secure Configuration Guide"
        ],
        "url": "https://trust.paramify.com/86borders/connectallcare/deliverables",
        "repositoryDescription": "86Borders Secure Configuration & Governance Guide. Select Download to view.",
        "authenticationRequired": false
      },
      "additionalRepositories": [
        {
          "repositoryType": [
            "System Security Plan (SSP)",
            "86Borders Policies & Procedure Index"
          ],
          "url": "https://trust.paramify.com/86borders/connectallcare/deliverables",
          "repositoryDescription": "Machine-readable and human-readable Policy and Procedure Index per [CDS-CSO-IRP], detailing all system policies, document IDs, versioning, word counts, and mapped FedRAMP practices.",
          "authenticationRequired": false,
          "accessRequestInstructions": "Access to the policy and procedure index is unrestricted, click on the 'Download' button to view."
        },
        {
          "repositoryType": [
            "Assessment Reports"
          ],
          "url": "https://trust.paramify.com/86borders/connectallcare",
          "repositoryDescription": "FedRAMP Independent Assessment Results per [IVV-CSO-ICP] and [CPO-CSO-OSA]. Status: FedRAMP 20x Class C Assessment currently in progress. Results will be uploaded immediately upon completion per [CPO-CSX-CPM] (bi-weekly maintenance rule).",
          "authenticationRequired": true,
          "accessRequestInstructions": "Access restricted to Authorizing Officials (AOs) and FedRAMP PMO reviewers."
        }
      ],
      "nextOngoingCertificationReportDate": "2027-01-15"
    },
    "contactInformation": [
      {
        "contactType": "Security",
        "contactName": "86Borders Security Team",
        "contactEmail": "fedramp-infosec@86borders.com"
      },
      {
        "contactType": "Sales",
        "contactName": "86Borders Sales Operations",
        "contactEmail": "sales@86borders.com"
      }
    ],
    "assessor": {
      "name": "A-LIGN Compliance and Security, Inc.",
      "assessorID": "100123"
    },
    "certifiedServices": [
      {
        "serviceName": "3rd Degree",
        "serviceDescription": "Pre-employment background screening and credential verification platform. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "86Borders/ConnectAllCare",
        "serviceDescription": "Healthcare coordination platform managing patient engagement and social care. (FIPS 199 Category: High [PHI/PII])",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "A-LIGN A-SCEND",
        "serviceDescription": "Cybersecurity compliance automation and audit portal; configured for evidence collection and continuous monitoring. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon CloudFront",
        "serviceDescription": "Global Content Delivery Network (CDN) service for fast web asset delivery. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon EC2 Container Registry (ECR)",
        "serviceDescription": "Managed Docker container image registry service. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon Elastic Compute Cloud (EC2)",
        "serviceDescription": "Scalable virtual server infrastructure providing compute capacity. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon Elastic Container Service (ECS)",
        "serviceDescription": "Highly scalable container orchestration service for running Docker containers. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon Elastic File System (EFS)",
        "serviceDescription": "Network File System (NFS) storage service for scalable file-sharing. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon GuardDuty",
        "serviceDescription": "Intelligent threat detection and continuous security monitoring service. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon Inspector",
        "serviceDescription": "Automated vulnerability management and security assessment service. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon Key Management Service (KMS)",
        "serviceDescription": "Managed encryption key lifecycle and cryptographic operations service. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon Keyspaces",
        "serviceDescription": "Managed Apache Cassandra-compatible database service. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon Lightsail",
        "serviceDescription": "Simplified, pre-configured cloud virtual private server (VPS) hosting service. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon RDS (MySQL)",
        "serviceDescription": "Managed relational database service configured with MySQL engine, automated backups, and encryption. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon Route 53",
        "serviceDescription": "Highly available and scalable Cloud Domain Name System (DNS) web service. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon Secrets Manager",
        "serviceDescription": "Key and credential management service for rotating and retrieving database/API secrets. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon Simple Storage Service (S3)",
        "serviceDescription": "Scalable cloud object storage for data archiving, backup, and application data. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Amazon Web Services (AWS)",
        "serviceDescription": "Cloud Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) provider. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "AWS Backup",
        "serviceDescription": "Centralized, policy-driven backup service for AWS cloud resources. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "AWS Certificate Manager",
        "serviceDescription": "Managed provisioning and renewal of SSL/TLS certificates for AWS resources. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "AWS CloudTrail",
        "serviceDescription": "Governance and API audit trail logging service across AWS accounts. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "AWS CloudWatch",
        "serviceDescription": "Monitoring and observability service for AWS cloud resources and applications. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "AWS Config",
        "serviceDescription": "Resource inventory tracking, compliance monitoring, and audit history engine. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "AWS Fargate",
        "serviceDescription": "Serverless compute engine for running containers without managing servers. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "AWS Linux",
        "serviceDescription": "Linux operating system distribution optimized for AWS cloud instances (AL2023). (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "AWS Security Hub",
        "serviceDescription": "Security posture management and aggregated security alerts platform. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "AWS Transfer Family",
        "serviceDescription": "Fully managed SFTP, FTPS, and FTP transfer service into AWS storage. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "AWS Virtual Private Cloud (VPC)",
        "serviceDescription": "Isolated cloud network framework for deploying secure AWS resources. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "AWS Web Application Firewall (WAF) & Shield",
        "serviceDescription": "Web application protection and DDoS defense security services. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Atlassian (Jira/Confluence)",
        "serviceDescription": "Enterprise documentation knowledge base (Confluence) and issue/task tracking platform (Jira); hosts compliance policies, system architecture, and incident tracking. (FIPS 199 Category: High [CUI/Internal])",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Google Workspace (Mail & Drive)",
        "serviceDescription": "Enterprise cloud productivity, corporate email (Gmail), and cloud file storage (Drive) platform. (FIPS 199 Category: High [CUI/PII])",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Kafka",
        "serviceDescription": "Distributed event streaming platform used for high-performance data pipelines. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Ninjio",
        "serviceDescription": "Security awareness training and simulated phishing platform. (FIPS 199 Category: Low)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "OneLogin",
        "serviceDescription": "Identity and Access Management (IAM) and Single Sign-On (SSO) solution. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "OpenVPN Server",
        "serviceDescription": "Centralized Virtual Private Network host application managing encrypted network tunnels. (FIPS 199 Category: High)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Paramify",
        "serviceDescription": "Automated cybersecurity compliance and documentation platform (FedRAMP/NIST). (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Terraform",
        "serviceDescription": "Infrastructure-as-Code (IaC) provisioning software for managing cloud infrastructure state. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Twilio",
        "serviceDescription": "Cloud communications platform for SMS, voice, and messaging APIs. (FIPS 199 Category: Moderate)",
        "dateAvailable": "2026-08-26"
      },
      {
        "serviceName": "Udemy Business",
        "serviceDescription": "Enterprise online learning and workforce up-skilling platform. (FIPS 199 Category: Low)",
        "dateAvailable": "2026-08-26"
      }
    ],
    "thirdPartyInformationResources": {
      "certified": [
        {
          "fedRampCertifiedThirdPartyInformationResource": "F1603087812",
          "useCase": "Resource Name: Amazon Web Services (AWS Commercial)\nGeneral Usage & Configuration: Cloud Infrastructure as a Service (IaaS) and Platform as a Service (PaaS) configured using AWS Organizations, IAM Identity Center, isolated VPCs, and centralized encryption.\nJustification for Use: Delivers scalable, highly available compute, storage, networking, and managed database services to host critical workloads.\nMitigation Measures: Implement AWS KMS encryption at rest and in transit, GuardDuty threat monitoring, CloudTrail audit logging, AWS WAF, and multi-factor authentication for all IAM identities.\nCompensating Controls: AWS Control Tower posture guardrails, automated compliance drift evaluation via AWS Config, and mandatory egress filtering through centralized firewalls."
        },
        {
          "fedRampCertifiedThirdPartyInformationResource": "FR2428769635XL",
          "useCase": "Resource Name: Paramify Cloud\nGeneral Usage & Configuration: Automated cybersecurity documentation and GRC platform configured to auto-generate and maintain OSCAL-based System Security Plans (SSPs) and compliance artifacts.\nJustification for Use: Automates compliance documentation drafting for NIST SP 800-53 and FedRAMP baselines, reducing manual oversight and documentation drift.\nMitigation Measures: Enforce RBAC for platform access, mandate SSO/MFA for all users, enforce AES-256 encryption at rest for generated compliance files, and sanitize operational details.\nCompensating Controls: Internal technical lead and CISO manual sign-off on all system boundaries, control implementations, and generated SSP artifacts before submission."
        }
      ],
      "nonCertified": [
        {
          "name": "1Password",
          "provider": "AgileBits Inc.",
          "website": "https://1password.com",
          "useCase": "General Usage & Configuration: Enterprise credential vault and secret management configured with zero-knowledge encryption, enforced Master Password + Secret Key policies, mandatory MFA, and role-based vault segregation.\nJustification for Use: Centralizes credential management, prevents plain-text secret storage, and eliminates risky password-reuse practices across administrative and operational teams.\nMitigation Measures: Enforce zero-knowledge architecture, continuous device trust validation, admin IP allowlisting, and automated secret rotation schedules.\nCompensating Controls: Mandatory integration with primary Identity Provider (SSO) for automated user provisioning/deprovisioning; secret access auditing via SIEM ingestion."
        },
        {
          "name": "3rd Degree",
          "provider": "3rd Degree Screening",
          "website": "https://www.3rddegreescreening.com",
          "useCase": "General Usage & Configuration: Pre-employment background verification and identity screening platform configured with encrypted candidate invite links and policy-driven adjudication workflows.\nJustification for Use: Verifies candidate background, credentials, and legal eligibility to mitigate insider threat risks before granting access to corporate infrastructure.\nMitigation Measures: Limit PII exposure via strict Role-Based Access Control (RBAC), enforce TLS 1.3 in transit and AES-256 at rest, enforce strict data retention schedules, and execute DPAs/BAAs.\nCompensating Controls: HR and Legal double-check and sign off on screening results before access is granted; zero system access or account creation prior to background clearance."
        },
        {
          "name": "A-LIGN",
          "provider": "A-LIGN Compliance and Security, Inc.",
          "website": "https://www.a-lign.com",
          "useCase": "General Usage & Configuration: Automated compliance management and audit portal (A-SCEND) configured for automated evidence collection, continuous control monitoring, and audit submission.\nJustification for Use: Streamlines SOC 2, ISO 27001, and FedRAMP assessment workflows, centralizing audit artifacts and continuous posture evaluation.\nMitigation Measures: Restrict portal access to compliance staff via SSO/MFA, apply least-privilege read-only permissions to audit integrations, and scrub sensitive PII/PHI from uploaded artifacts.\nCompensating Controls: Continuous manual review of all compliance evidence prior to auditor release; annual review of A-LIGN’s SOC 2 Type II assessment reports."
        },
        {
          "name": "Atlassian (Confluence & Jira)",
          "provider": "Atlassian Corporation",
          "website": "https://www.atlassian.com",
          "useCase": "General Usage & Configuration: Enterprise cloud documentation knowledge base and issue tracking configured with SAML 2.0 SSO, strict space/project permissions, and encrypted storage.\nJustification for Use: Centralizes compliance policy management, technical documentation, and security ticket tracking across operational teams.\nMitigation Measures: Enforce OneLogin SSO with hardware-token MFA, restrict public space/project sharing, enforce IP allowlisting, and sanitize sensitive PII/PHI from wiki pages.\nCompensating Controls: Mandatory SIEM log ingestion for admin activity; annual SOC 2 Type II review of Atlassian Cloud controls."
        },
        {
          "name": "Google Workspace",
          "provider": "Google LLC",
          "website": "https://workspace.google.com",
          "useCase": "General Usage & Configuration: Cloud productivity, corporate email (Gmail), and document collaboration (Drive) configured with Client-Side Encryption (CSE), context-aware access controls, and strict DLP rules.\nJustification for Use: Provides enterprise email, communication, and document sharing required for business operations.\nMitigation Measures: Enforce SSO with hardware-token MFA, implement strict Data Loss Prevention (DLP) rules blocking external sharing of sensitive data, and restrict OAuth app authorizations.\nCompensating Controls: Endpoint detection and response (EDR) software on all enterprise devices; continuous automated email security gateway scanning to filter phishing attempts."
        },
        {
          "name": "Ninjio",
          "provider": "Ninjio LLC",
          "website": "https://ninjio.com",
          "useCase": "General Usage & Configuration: Security awareness micro-learning and phishing simulation platform configured with automated monthly training modules and simulated phishing campaigns.\nJustification for Use: Strengthens staff defense mechanisms against social engineering, phishing, and malware threats, ensuring compliance with federal awareness standards.\nMitigation Measures: Anonymize user profiles using minimal PII (email/pseudonym only) during account provisioning; enforce strict administrative SSO access.\nCompensating Controls: Automated email security gateways (e.g., Defender for Office 365 / Proofpoint) that analyze, neutralize, and quarantine real-world threats independently of user action."
        },
        {
          "name": "OneLogin",
          "provider": "OneLogin, Inc.",
          "website": "https://www.onelogin.com",
          "useCase": "General Usage & Configuration: Enterprise Identity and Access Management (IAM) and Single Sign-On (SSO) solution configured with Adaptive MFA, SAML 2.0/OIDC integrations, and automated SCIM provisioning.\nJustification for Use: Centralizes user identity authentication, access enforcement, and automated user lifecycle management across all corporate SaaS and cloud systems.\nMitigation Measures: Require step-up Adaptive MFA based on risk scoring, enforce robust password complexity guidelines, limit session durations, and forward auth logs to a SIEM.\nCompensating Controls: Secured break-glass administrative credentials maintained in offline physical vaults; baseline access policies for critical infrastructure when SSO is unreachable."
        },
        {
          "name": "OpenVPN Server",
          "provider": "OpenVPN Inc.",
          "website": "https://openvpn.net",
          "useCase": "General Usage & Configuration: Centralized Virtual Private Network host application managing encrypted tunnel connections configured with TLS 1.3, AES-256-GCM, and client certificate authentication.\nJustification for Use: Grants encrypted, authenticated remote access to private corporate networks and non-public cloud infrastructure for remote staff.\nMitigation Measures: Enforce multi-factor authentication alongside key-based client certificates, restrict split tunneling, enforce tight firewall rules on VPN gateways, and log session data.\nCompensating Controls: Network-level micro-segmentation limiting VPN client routing exclusively to authorized IP ranges and application ports based on user role."
        },
        {
          "name": "Terraform",
          "provider": "HashiCorp, Inc.",
          "website": "https://www.terraform.io",
          "useCase": "General Usage & Configuration: Infrastructure-as-Code (IaC) tool (CLI/Cloud) configured to manage cloud resource provisioning, utilizing remote state locking and encrypted backend storage.\nJustification for Use: Enables repeatable, version-controlled, and audited infrastructure deployments, reducing human configuration error.\nMitigation Measures: Encrypt state files at rest using KMS AES-256, restrict state file access strictly to CI/CD service accounts, scan code for secrets/misconfigurations prior to commit, and require peer code reviews.\nCompensating Controls: Separation of duties preventing developers from directly applying infrastructure changes; all executions must run through isolated, audited CI/CD pipelines."
        },
        {
          "name": "Twilio",
          "provider": "Twilio Inc.",
          "website": "https://www.twilio.com",
          "useCase": "General Usage & Configuration: Cloud communications platform configured for programmatic SMS messaging, system status alerts, and multi-factor authentication token delivery via REST APIs.\nJustification for Use: Enables automated application-to-person notifications, out-of-band verification codes, and real-time operational status alerts.\nMitigation Measures: Enforce strict TLS API communication, scope API tokens to minimum required capabilities, implement strict rate-limiting, and validate incoming webhooks via digital signatures.\nCompensating Controls: Offer secondary/fallback out-of-band authentication methods (e.g., TOTP authenticator apps, WebAuthn push notifications) to mitigate SIM-swapping risks inherent to SMS."
        },
        {
          "name": "Udemy Business",
          "provider": "Udemy, Inc.",
          "website": "https://business.udemy.com",
          "useCase": "General Usage & Configuration: Enterprise digital learning platform configured via SAML 2.0 SSO for user identity verification and automated LMS profile creation.\nJustification for Use: Provides ongoing technical skill development, cybersecurity training courses, and professional development for staff.\nMitigation Measures: Enforce SSO/MFA authentication, restrict public course publishing from enterprise accounts, and minimize shared account details to essential attributes (Name/Work Email).\nCompensating Controls: Corporate endpoint isolation and web filtering policies preventing personal web activity or file downloads from impacting enterprise networks."
        }
      ]
    }
  }