Case Study

Regional Healthcare Provider: A HIPAA Risk Assessment That Found Shadow IT

A regional healthcare provider engaged Derivee for an annual HIPAA Security Risk Assessment ahead of a payer compliance review.

Technical testing of systems handling ePHI surfaced a department using a consumer file-sharing tool to move patient records between clinics — entirely outside the organization’s sanctioned systems and audit logging.

The finding was reported alongside a remediation path and staff training recommendation, and became a key input into the organization’s updated risk analysis documentation ahead of their compliance review.

← all case studies