Healthcare
US
Atlas Health Partners
Regional integrated delivery network with 14 clinics and a shared EHR, recently completed a merger with a smaller group.
Systems
- Epic EHR
- On-prem AD
- Patient portal
- HL7 feeds to a clearinghouse
Regulatory exposure
- HIPAA
- State medical record laws
- Joint Commission accreditation
Relevant frameworks
- HIPAA Security Rule
- NIST CSF
- HITRUST (in progress)
Top risks
- Post-merger AD trust bloat
- Untrained staff on phishing
- Vendor (clearinghouse) breach exposure
- Unencrypted laptop theft
Control priorities
- Risk analysis (45 CFR 164.308)
- Workforce training
- Encryption at rest for endpoints
- Vendor BAAs
Audit concerns
- Risk analysis currency post-merger
- Workforce training evidence
- BAA completeness
Your task
You inherited a half-finished HITRUST journey and a recent OCR inquiry letter. Sequence the next 60 days: which HITRUST controls do you close first, what do you send the OCR, and how do you get the post-merger combined entity onto one risk register?
Vendor risk
Clearinghouse and third-party billing vendors both hold ePHI; BAA review overdue.
BCP/DR
EHR hot-site exists; failover has not been exercised in 18 months.