Healthcare
US

Atlas Health Partners

Regional integrated delivery network with 14 clinics and a shared EHR, recently completed a merger with a smaller group.

Systems
  • Epic EHR
  • On-prem AD
  • Patient portal
  • HL7 feeds to a clearinghouse
Regulatory exposure
  • HIPAA
  • State medical record laws
  • Joint Commission accreditation
Relevant frameworks
  • HIPAA Security Rule
  • NIST CSF
  • HITRUST (in progress)
Top risks
  • Post-merger AD trust bloat
  • Untrained staff on phishing
  • Vendor (clearinghouse) breach exposure
  • Unencrypted laptop theft
Control priorities
  • Risk analysis (45 CFR 164.308)
  • Workforce training
  • Encryption at rest for endpoints
  • Vendor BAAs
Audit concerns
  • Risk analysis currency post-merger
  • Workforce training evidence
  • BAA completeness
Your task
You inherited a half-finished HITRUST journey and a recent OCR inquiry letter. Sequence the next 60 days: which HITRUST controls do you close first, what do you send the OCR, and how do you get the post-merger combined entity onto one risk register?
Vendor risk
Clearinghouse and third-party billing vendors both hold ePHI; BAA review overdue.
BCP/DR
EHR hot-site exists; failover has not been exercised in 18 months.