Back to category

Week 1

Conduct a Security Policy Review for a Healthcare Client

Beginner
GRC Analyst
ISO 27001
NIST CSF 2.0
NIST SP 800-66r2 (HIPAA)
HHS 405(d) HICP
Policy Review
HIPAA Compliance
Risk Assessment
Access Control Review
NIST CSF 2.0
Cloud/SaaS Governance

Client Background

You are a GRC Analyst contracted by Meridian Family Health, a 3-clinic outpatient healthcare provider with roughly 180 staff serving 40,000+ patients annually. Meridian recently failed a routine vendor security questionnaire ahead of renewing its cyber liability insurance, and leadership has asked your consulting team to independently review their information security policies against HIPAA Security Rule requirements before the policy is resubmitted.

Business Environment

Meridian Family Health runs a cloud-hosted Electronic Health Records (EHR) system accessed by clinical staff at all three locations, plus a small on-site file server used by billing for scanned insurance documents. IT is managed by a 2-person internal team supported by an external MSP for infrastructure. Front-desk staff, nurses, physicians, and billing staff all have different levels of access to Protected Health Information (PHI), and several long-tenured employees have accumulated access beyond their current role over the years.

Security Incident

No breach; the engagement is a proactive commissioned policy review. The driver is Meridian failing a routine vendor security questionnaire ahead of renewing its cyber liability insurance, with leadership requiring an independent HIPAA Security Rule benchmark before the policy is resubmitted.

Scope

This engagement covers a documentation and process review only — no technical scanning or penetration testing is in scope. Review the provided security policy document, PHI system inventory, access control list, and audit log excerpt. Assess them against HIPAA Security Rule administrative, physical, and technical safeguard requirements and the client's own stated policies. Client-side environments outside the provided materials (e.g. physical clinic walkthroughs) are out of scope for this engagement.

Objectives

  • Evaluate the client's written security policy against HIPAA Security Rule requirements
  • Verify that PHI systems are properly inventoried and classified
  • Identify access control violations of the principle of least privilege
  • Detect gaps between documented policy and actual operational practice
  • Prioritize identified gaps by compliance risk and business impact
  • Benchmark the policy against recognized 2026 frameworks (NIST CSF 2.0, NIST SP 800-66r2, HHS 405(d)) and assess cloud/SaaS EHR governance and third-party supply-chain risk alongside HIPAA citations.

Required Deliverables

HIPAA Policy Gap Findings Summary
Prioritized Remediation Recommendations
3 hrs estimated