You are stepping in as GRC Director. The previous GRC function was audit-only and compliance-reactive. Your mandate: build a modern, integrated, risk-based GRC program from the ground up within 12 months.
You are the new GRC Director at MeridianHealth Cloud — a multi-cloud telehealth platform serving 4 million patients across 11 states with 34 third-party vendors. Every concept from Modules 1–28 converges here. Deliver a complete program. Defend it to the board. This is the job.
| Dimension | Detail |
|---|---|
| Business Model | Telehealth SaaS platform — video consultations, e-prescriptions, remote patient monitoring devices, AI-powered clinical documentation |
| Scale | 4 million patients, 11 states, 1,200 employees, $340M ARR |
| Data Handled | PHI (Protected Health Information), PII, payment card data (PCI scope), clinical imaging, continuous biometric device telemetry |
| Infrastructure | AWS (primary), Azure (DR/secondary), 12 SaaS applications, on-premises clinical device management |
| Third Parties | 34 vendors — EHR vendors (3), payment processors (2), SMS/notification (2), AI transcription (1), cloud hosting (2), clinical device manufacturers (8), revenue cycle management (2), other (14) |
| Compliance Obligations | HIPAA Security Rule, HIPAA Privacy Rule, HITECH, PCI-DSS v4.0, CCPA (California), state-level health privacy laws (11 states), SOC 2 Type II (customer commitments), contractual breach-notification SLAs (<48 hours) |
| Recent Incidents | Ransomware near-miss (6 months ago — contained, no patient data affected), vendor data exposure (12 months ago — EHR vendor misconfigured API exposing 8,200 records) |
| Board Mandate | "Modernize GRC. Justify every dollar. No compliance theater. Show us real risk management." |
A full GRC program is not a collection of independent functions — it is an ecosystem where every component feeds the others. Understanding the integration points is what separates a program director from a function manager:
The charter establishes authority and committee structure. The committees define risk appetite. Risk appetite drives policy requirements — if the appetite is "low risk on PHI exposure," the data classification policy must define Restricted handling for all PHI and mandate encryption and access controls. Policy requirements flow directly from governance decisions. Without governance, policies are arbitrary.
The risk register identifies top risks. The audit plan prioritizes testing of controls over those top risks. The compliance map shows which frameworks require those controls — enabling a single control to satisfy HIPAA, SOC 2, and PCI-DSS simultaneously. Risks drive audit focus; audit findings update the risk register; the loop is continuous.
Vendor risk assessments feed risk register entries (each Tier 1 vendor with gaps generates a risk item). Vendor contractual requirements reflect compliance framework obligations (HIPAA BAAs, PCI-DSS contractual clauses). The vendor framework is not separate from the compliance program — it IS a required control under every major framework.
The dashboard feeds governance committees with current risk posture. Governance decisions (accept, mitigate, escalate) generate actions that update the risk register and treatment plans. The dashboard does not just report — it is the input to governance decision-making. Without the loop, reporting is theater.
Must include: Program purpose and authority. Committee structure (Board Risk Committee, Executive Steering, Security Operations Review). Reporting lines (CISO → CEO → Board). Risk appetite statement. Decision authority matrix. Annual review requirement. Common mistake: Governance charters that describe what governance does but do not assign authority or decision rights are unenforceable.
Must include: Unique risk ID and risk statement. Category, likelihood, impact, inherent and residual scores. Risk owner (named individual). Current controls. Treatment decision with justification. Target completion date. Review date. Common mistake: Risk registers with no named owners or past-due treatment dates — the register becomes a graveyard of acknowledged-but-ignored risks.
Must include: Information Security Policy (high-level intent). Acceptable Use Policy. Data Classification Policy. Access Control Policy. Incident Response Policy. Vendor Risk Policy. Business Continuity Policy. Each with version, owner, approval, and review date. Common mistake: Policies written in abstract language that cannot be audited against.
Must include: 12-month schedule of internal audits based on risk register priority. External audit schedule (HIPAA, PCI-DSS, SOC 2). Scope definition for each audit. Evidence collection approach. Reporting format and governance distribution. Follow-up tracking process. Common mistake: Audit plans based on rotation rather than risk — high-risk areas audited every 3 years while low-risk areas get annual attention.
Must include: Vendor tiering criteria (1–4). Due diligence requirements per tier. Questionnaire templates. Onboarding approval gate. Ongoing monitoring approach. SOC report review schedule. Offboarding procedure. Contractual security clause requirements. Fourth-party (sub-processor) management approach. Common mistake: Frameworks that only cover onboarding and never revisit active vendors.
Must include: Control inventory with unique IDs. Mapping of each control to every applicable framework requirement (HIPAA, PCI-DSS, SOC 2, CCPA, ISO 27001). Implementation status per control. Evidence type for each control. Control owner. Test frequency. Common mistake: Separate compliance silos — separate HIPAA controls and separate PCI controls, despite significant overlap.
Must include (board tier): Top 3 risks with ALE and trend. Residual risk vs appetite ratio. Regulatory compliance status by framework. Incident trend (3-month rolling). Vendor risk concentration. Must include (operational tier): Open critical vulnerabilities by age. Access review completion rate. Patch SLA compliance. Open audit findings. Common mistake: Technical metrics at board level; strategic metrics buried in operational reports.
MeridianHealth operates under five overlapping regulatory regimes. A unified control crosswalk prevents duplicate effort:
| Control | HIPAA | PCI-DSS | SOC 2 | CCPA |
|---|---|---|---|---|
| Encryption at rest (AES-256) | §164.312(a)(2)(iv) | Req 3.5 | CC6.1 | Implicit |
| Multi-Factor Authentication | §164.312(d) | Req 8.4 | CC6.1, CC6.3 | — |
| Quarterly Access Reviews | §164.308(a)(4) | Req 7.2 | CC6.2, CC6.3 | — |
| Vendor BAA / Security Contract | §164.308(b) | Req 12.8 | CC9.2 | Data Processing Agreement |
| Incident Response Plan & Testing | §164.308(a)(6) | Req 12.10 | CC7.5 | Breach Notification |
| Annual Risk Assessment | §164.308(a)(1) | Req 12.3 | CC3.1, CC3.2 | Implicit |
| Security Awareness Training | §164.308(a)(5) | Req 12.6 | CC1.4 | — |
| Audit Logging / SIEM | §164.312(b) | Req 10 | CC7.2 | — |
Every cell in this table where a control satisfies multiple frameworks is a saved audit, saved evidence collection, and saved documentation effort. For MeridianHealth, a unified crosswalk covering 40 controls can satisfy approximately 200 individual framework requirements — without writing 200 separate controls.
Use these professionally structured risk entries as your model for the deliverable section:
| Risk | Inherent | Key Controls | Residual | Treatment | Owner |
|---|---|---|---|---|---|
| Ransomware encrypting PHI systems (given near-miss 6 months ago) | 5×5=25 | EDR, offline immutable backups, IR plan | 3×3=9 | Mitigate: deploy MFA on all remote access, test DR quarterly | CISO |
| Vendor API misconfiguration exposes PHI (given prior incident) | 4×5=20 | TPRM program, contractual controls, API security testing | 2×4=8 | Mitigate: Tier 1 vendor reassessment + penetration test of EHR API | VP Engineering |
| HIPAA breach notification failure (34 vendors, contractual 48h SLA) | 3×5=15 | IR plan, vendor notification clauses, legal retainer | 2×4=8 | Mitigate: Update all vendor contracts; test notification process quarterly | General Counsel |
| Insider PHI exfiltration by clinical staff | 3×4=12 | RBAC, DLP, access reviews, background checks | 2×3=6 | Mitigate: Deploy clinical DLP; implement behavior analytics | CISO |
| Cloud misconfiguration exposing patient records (multi-cloud) | 4×5=20 | CSPM, IaC scanning, SCPs | 2×4=8 | Mitigate: Deploy Wiz CSPM across AWS + Azure; implement guardrails | VP Cloud Ops |
A realistic build sequence for a program like MeridianHealth's — balancing quick wins with sustainable foundations:
Read all existing policies, audit reports, incident records, vendor contracts. Interview CISO, General Counsel, CFO, VP Engineering. Produce a current-state gap assessment. Draft and get approved: Governance Charter, Risk Appetite Statement, and GRC team structure. Quick win: present the gap assessment to the board — immediate visibility without requiring remediation.
Build the risk register with top 15 risks (starting with lessons from the two prior incidents). Draft the core policy pack (7 policies). Establish the Executive Security Steering Committee with monthly cadence. Begin the vendor inventory and tier classification for all 34 vendors.
Build the control crosswalk (HIPAA × PCI × SOC 2 × CCPA). Complete Tier 1 and Tier 2 vendor assessments (approximately 12 of 34 vendors). Launch SOC 2 readiness gap assessment — customer commitments are at risk. Deploy CSPM to address the cloud misconfiguration risk.
Launch the internal audit program with risk-based scheduling. Begin automated control testing (configuration checks, access review automation). Deploy the GRC platform with integrated risk register, compliance tracking, and vendor risk module. Start generating the board dashboard with real data.
Begin SOC 2 Type II audit period (minimum 6 months — started Month 7). Complete first-year board GRC report with maturity score, risk posture trend, and next-year investment request. Present program to customers as differentiator. Target: GRC Maturity Level 3 by Year 1 end, Level 4 by Year 2.
The board meeting is in 10 minutes. You have built the program. Now defend it.
This quiz tests your ability to integrate concepts across all 28 prior modules. Questions are at Director-level judgment — not just recall.