A regional healthcare provider engaged Derivee for an annual HIPAA Security Risk Assessment ahead of a payer compliance review.
Technical testing of systems handling ePHI surfaced a department using a consumer file-sharing tool to move patient records between clinics — entirely outside the organization’s sanctioned systems and audit logging.
The finding was reported alongside a remediation path and staff training recommendation, and became a key input into the organization’s updated risk analysis documentation ahead of their compliance review.