Final Risk Management Plan
Final Risk Management Plan
1. Introduction
In addition to the systems it operates, Health Network Inc. serves hospitals, physician
groups, insurance companies, and individual patients across multiple states. The
organization employs approximately 1,200 - 1,500 employees and generates an
estimated $450 - $600 million annually through subscription-based service contracts,
transaction-based payment processing fees, enterprise licensing agreements, and data
integration services. Moreover, The company’s business model centers on providing
secure, compliant, and interoperable digital infrastructure to streamline healthcare
delivery and financial operations. Revenue is generated primarily through subscription
contracts for HNetExchange and HNetConnect, fees from HNetPay claims and payment
processing, and Long-term managed service agreements.
This plan directly impacts the following individual stakeholders, each of whom holds a
specific accountability in ensuring the success of the Risk Management Framework at
Health Network Inc.:
Chief Executive Officer (CEO): The CEO is the ultimate decision-maker and risk
owner at Health Network Inc. This plan ensures the CEO has visibility into enterprise-
wide risk exposure so that residual risk decisions align with business strategy, corporate
governance obligations, and long-term organizational viability. Without CEO buy-in, risk
mitigation investments cannot be approved or sustained.
Chief Information Officer (CIO): The CIO is responsible for the technical integrity of all
three core platforms—HNetExchange, HNetPay, and HNetConnect. This plan provides
the CIO with a structured framework to ensure security architectures, system
configurations, and technology investments meet risk management requirements and
comply with applicable standards.
Chief Financial Officer (CFO): The CFO evaluates the financial impact of identified
risks and approves budgets for mitigation controls. This plan enables the CFO to
understand the cost-benefit analysis behind control investments and the potential
financial exposure associated with data breaches, regulatory fines, and system
downtime, particularly as they relate to HNetPay operations.
Chief Compliance Officer (CCO): The CCO ensures that all risk management
activities align with HIPAA, HITECH, PCI DSS, and applicable state regulations. This
plan provides the CCO with documented compliance controls and breach notification
procedures, reducing the organization’s legal and regulatory exposure.
Risk Management Project Manager (Risk PM): The Risk PM coordinates the day-to-
day risk assessment activities, manages the risk register, and ensures that milestones
are met. This plan gives the Risk PM the structured scope, schedule, and methodology
needed to drive the RMF process to completion without scope creep.
Authorized End Users (Employees, Patients, and Vendors): End users interact with
HNetExchange, HNetPay, and HNetConnect daily. Their adherence to security policies,
proper credential management, and timely reporting of suspicious activity are essential
to the plan’s effectiveness. Authorized vendors who have integration access to Health
Network Inc.’s systems also represent a risk vector that must be governed through this
plan.
A qualitative risk assessment evaluates risks using descriptive categories such as Low,
Medium, High, or Very High rather than numerical probability values. It relies on expert
judgment and contextual business impact analysis to prioritize risks and guide mitigation
strategies. This approach will be leveraged in subsequent project phases to assess
likelihood and impact.
The scope of this Risk Management Plan defines the organizational boundaries of the
assessment and identifies the systems, infrastructure, processes, and personnel
included. Clearly defining scope prevents uncontrolled expansion of the project and
ensures alignment with organizational objectives
This assessment applies to all systems and environments owned and operated by
Health Network Inc.
HNetExchange
Included components:
Web servers
Application servers
API integrations
Key asset categories and processes evaluated (per NIST SP 800-30 and Gibson &
Igonor risk assessment framework):
HNetPay
Included components:
Data and Information Assets: HNetPay stores and processes cardholder data,
insurance claim records, and financial transaction histories, all of which are
classified as private and proprietary data. Exposure of this data could result in
PCI DSS violations, state-mandated breach notifications, and significant financial
and reputational harm. The assessment will evaluate data classification controls,
encryption practices, and access restrictions on all stored financial data.
HNetConnect
Included components:
Data and Information Assets: HNetConnect stores patient profile data, medical
records, and appointment histories, all of which constitute PHI under HIPAA.
Patient data is classified as private and proprietary; unauthorized access or
disclosure could result in identity theft, regulatory penalties, and patient harm.
The assessment will evaluate data encryption at rest and in transit, access
logging, and identity management controls.
The scope includes the supporting infrastructure for the above systems:
IDS/IPS systems
The following individual roles are included in the risk management effort. Each role is
described in terms of how it interacts with Health Network Inc.’s systems and influences
the Risk Management Framework (RMF):
Chief Executive Officer (CEO): The CEO holds ultimate organizational authority over
risk tolerance and strategy. In the RMF context, the CEO formally accepts residual risk
and approves the overall risk management strategy. Without executive sponsorship at
this level, the RMF cannot be fully resourced or enforced across Health Network Inc.’s
business units.
Chief Information Officer (CIO): The CIO owns the technical infrastructure underlying
HNetExchange, HNetPay, and HNetConnect. In the RMF, the CIO is responsible for
ensuring security architecture decisions—such as firewall configurations, IDS/IPS
deployment, and system segmentation—align with identified risks and established
controls. The CIO also reviews and approves major security technology investments.
Chief Financial Officer (CFO): The CFO controls budget allocation and financial risk
exposure. In the RMF, the CFO reviews cost-benefit analyses for proposed controls,
approves mitigation investment decisions, and evaluates the financial risk associated
with HNetPay operations, including potential losses from payment processing outages
or cardholder data breaches.
Chief Compliance Officer (CCO): The CCO is responsible for ensuring that all RMF
activities satisfy HIPAA, HITECH, PCI DSS, and applicable state regulatory
requirements. The CCO reviews breach notification procedures, conducts compliance
audits, and advises executive leadership on regulatory risk, particularly as it applies to
the PHI handled by HNetExchange and HNetConnect.
Risk Management Project Manager (Risk PM): The Risk PM is the primary
coordinator of the RMF lifecycle at Health Network Inc. This individual defines and
protects the assessment scope, manages the risk register, facilitates risk identification
workshops, tracks Plan of Action and Milestones (POA&M) items, and reports progress
to executive stakeholders. The Risk PM is the single point of accountability for keeping
the project on schedule and within scope.
While Section 2.1 identifies the specific systems, hardware, software, and infrastructure
included in this assessment, the Scope Boundary defines the logical and organizational
perimeter that separates what is inside the risk assessment from what is outside it. This
distinction is critical: scope creep occurs when assets outside the defined boundary are
inadvertently evaluated, consuming time and resources without producing relevant
results (Gibson & Igonor, 2020).
All three production data centers (Minneapolis MN, Portland OR, Arlington VA)
and the geographically separated disaster recovery site.
Integration points and connection risks between Health Network Inc.’s systems
and external partner systems (e.g., hospital EHR connections, insurance
clearinghouse APIs).
Personal devices used by patients to access HNetConnect that are not managed
or owned by Health Network Inc. (i.e., BYOD endpoints).
Any modification to this scope boundary requires formal written approval from the Risk
Management Project Manager and key stakeholders prior to implementation, in order to
prevent scope creep and ensure assessment resources remain focused on the agreed
assessment target.
[Link] Diagram
The diagram illustrates the enterprise network architecture for Health Network, Inc.,
depicting seven distinct security zones separated by trust boundaries. The architecture
follows a defense-in-depth model with an untrusted Internet/External Zone at the
perimeter, a DMZ containing the perimeter firewall, WAF, load balancer, IDS/IPS, VPN
gateway, and email gateway, followed by an internal firewall enforcing least-privilege
routing into the production network. Three co-location data centers — Minneapolis, MN
(primary), Portland, OR (secondary), and Arlington, VA (east coast) — host the three in-
scope systems: HNetExchange (EHR exchange, VLAN 11–13), HNetPay (payment
processing, VLAN 14–16), and HNetConnect (patient portal, VLAN 21–23), each
implemented in a three-tier Web/App/Database architecture. Supporting infrastructure
includes an out-of-band Security Management zone (VLAN 40) housing the SIEM,
vulnerability scanner, patch server, PKI, and jump server, a geographically separated
Disaster Recovery site (VLAN 50–55), and a Corporate Endpoint Network (VLAN 60–
62) spanning all three office locations. All internal systems use RFC 1918 private
address space (Class A [Link]/8) with the DMZ on Class B [Link]/12.
Figure 1: Health Network, Inc. Enterprise Network Architecture
4. Compliance and Regulatory Requirements
HIPAA establishes national standards for protecting Protected Health Information (PHI).
Because HNetExchange and HNetConnect transmit, store, and provide access to
electronic health records, Health Network Inc. qualifies as a covered entity or business
associate under HIPAA.
4.2 Health Information Technology for Economic and Clinical Health (HITECH) Act
The HITECH Act strengthens HIPAA by requiring mandatory breach notification when
unsecured PHI is compromised. Because Health Network Inc. stores and transmits PHI
electronically, any breach affecting HNetExchange or HNetConnect systems must be
reported to affected individuals and regulatory authorities.
HITECH also increases civil and criminal penalties for noncompliance and extends
liability to third-party vendors. This makes vendor risk management a critical component
of this plan.
HNetPay processes credit and debit card transactions. As a result, Health Network Inc.
must comply with PCI DSS requirements for secure handling of cardholder data.
Vulnerability management
Failure to comply may result in fines, loss of payment processing privileges, and legal
liability. Therefore, HNetPay infrastructure and processes are prioritized within the
scope of this risk management plan.
Although not a regulatory requirement, Health Network Inc. aligns its risk management
process with the National Institute of Standards and Technology (NIST) Risk
Management Framework (SP 800-37 Rev. 2)
The RMF provides a structured seven-step lifecycle for integrating risk management
into system operations:
1. Prepare
2. Categorize
3. Select
4. Implement
5. Assess
6. Authorize
7. Monitor
Ensures compliance with HIPAA, HITECH, PCI DSS, and state regulations.
The following Gantt chart presents the proposed schedule for the Risk Management
Framework planning and implementation process. The timeline spans from February
23, 2026 through May 10, 2026 and illustrates the structured progression of project
activities from initial planning through final consolidation. Major tasks are organized
chronologically and aligned with academic project deliverables. Key milestones—
including Project Parts 1 through 5—are clearly identified to support tracking and
accountability.
The schedule reflects the lifecycle approach of risk management, beginning with plan
development and scope definition, followed by risk assessment, mitigation strategy
development, business impact analysis, and final integration. Overlapping tasks
demonstrate realistic project dependencies and coordination among governance,
technical, and compliance functions. This Gantt chart serves as a planning placeholder
and will be updated and refined in Project Part 4 as implementation details are finalized.
Figure 2 Risk Management Planning and Implementation Schedule
1. Introduction
Health Network, Inc. is a U.S.-based healthcare technology company headquartered in
Minneapolis, MN, with additional offices in Portland, OR, and Arlington, VA. The
(PHI), payment card data, and personally identifiable information (PII) for hospitals,
who is responsible for each component of the assessment. It builds directly on the
scope, roles, and network architecture established in Project Part 1 (Risk Management
Plan). In accordance with course guidance, this plan does not address remediation or
mitigation—those activities are reserved for Project Part 3. This document is a scenario-
based assessment plan tied to the required table and control-selection process.
Network, Inc.’s information systems, data center assets, and supporting infrastructure.
As a healthcare organization handling PHI and payment card data, Health Network, Inc.
faces regulatory obligations under HIPAA, HITECH, and PCI DSS. A risk assessment is
not optional—it is a foundational requirement under the HIPAA Security Rule and a
prerequisite for selecting and justifying the security controls that protect patient and
financial data. Per NIST SP 800-30 Rev. 1, a risk assessment supports organizational
risks (NIST, 2012). This assessment provides the analytical foundation for the mitigation
than precise numerical probability values (Gibson & Igonor, 2020). This approach is
appropriate for Health Network, Inc. because many potential losses (reputational harm,
regulatory penalties, patient trust) are difficult to quantify precisely, and the assessment
team can leverage operational knowledge of the three production systems to assign
consistent ratings.
Assessment procedures follow the Examine, Interview, and Test methods defined in
how likelihood and impact ratings are assigned and how the overall risk rating is
derived.
Likelihood Criteria:
Rating Criteria
High Threat source is highly motivated and capable; vulnerability is easy to exploit; exploit
observed in similar environments within 12 months.
Moderate Threat source is motivated but requires moderate skill; vulnerability exists but is
partially mitigated; exploit plausible but not recently observed.
Low Threat source has limited motivation or capability; vulnerability exists only under
specific conditions; exploit theoretically possible but unlikely.
Impact Criteria:
Rating Criteria
Critical Complete loss of C/I/A for a mission-critical system; regulatory penalties, large
financial loss, significant reputational harm.
High Significant degradation affecting multiple departments; moderate financial or
compliance consequences; recovery requires days.
Moderate Localized disruption to a single department; limited financial impact; recovery within
hours.
Low Minor inconvenience with negligible effect on operations, finances, or reputation;
immediate recovery.
Risk Derivation:
Overall Risk = Likelihood × Impact. High Likelihood + Critical Impact = Critical Risk.
Moderate Likelihood + High Impact = High Risk. The matrix ensures systematic,
personnel owned and directly managed by Health Network, Inc. Only assets within the
Systems in Scope:
650 corporate endpoints. The scope boundary excludes external hospital systems,
and valuing organizational assets across six categories: (1) system access and
availability, (2) system functions, (3) hardware assets, (4) software assets, (5) personnel
assets, and (6) data and information assets. The table below inventories Health
HNetExchange PHI (EHR) Critical Web/app System access & Health data
servers, EHR availability (24/7); transmission &
database, API automated EHR storage; access
integrations, routing; data & info control; audit
auth & assets (PHI); logging;
encryption hardware/software encryption
services validation
HNetConnect PII / PHI High Public web System access & User auth;
portal, identity availability (24/7 telehealth; secure
mgmt, patient patient-facing); messaging;
profile DB, automated patient patient record
session mgmt auth; data assets retrieval
(PHI/PII); personnel
pairs in the required seven-column format. Each row tells a complete “risk story”:
identifying the threat source, the specific vulnerability it exploits, the concrete exploit
path an attacker would follow, what protection is currently in place and its status
(Missing, Partial, or Weak), the possible impact with CVSS base score, the selected
NIST SP 800-53 Rev. 5 controls, and a detailed justification explaining exactly how
each control reduces the identified weakness, blocks the exploit path, improves
All controls cited in this table are drawn exclusively from the 25-control inventory in
Section 5, ensuring full alignment between the analytical section and the control-
selection section. There are no mismatched controls between the two sections.
Health Network, Inc. — Final Risk Management Plan
27
Health Network, Inc. — Final Risk Management Plan
compromises authentication only; credentials from a place with minimal PHI access IA-2(2) (MFA directly neutralizing credential
HNetConnect no MFA for patients third-party data complexity rules (8 violates — Non- stuffing because stolen
patient portal or providers; dump and uses chars, no special HIPAA, Privileged), passwords alone become
accounts session timeouts automated character enables AC-12 insufficient for login. This
set inconsistently credential-stuffing requirement). medical (Session blocks the exploit at the
across portal tools against Session timeout identity theft, Termination) authentication boundary. AC-12
modules (30 min to HNetConnect. configured and enforces consistent 15-minute
4 hours). Compromised inconsistently. No degrades idle timeouts across all portal
accounts are used MFA deployed. patient trust modules, eliminating the
to access PHI, Status: Weak. in the portal. session replay vector from
modify records, or CVSS: 8.1. abandoned sessions. The
impersonate vulnerability is single-factor
patients for auth and inconsistent sessions;
fraudulent MFA blocks the credential
prescriptions. attack, session termination
closes the replay window.
Physical theft Physical access An unauthorized Badge-controlled Critical. Loss PE-3 (Physical PE-3 strengthens entry controls
of controls at co- individual tailgates entry at all three of Access by requiring multi-factor
unencrypted location facilities not through a badge- data centers. CCTV unencrypted Control), PE-6 physical authentication (badge
storage media consistently controlled door at installed but footage production (Monitoring + PIN), eliminating the
from co- verified; no the Minneapolis retained only 7 days media Physical tailgating vector that enables
location data quarterly hardware data center, and not actively containing Access), PE- unauthorized entry. PE-6
center audit performed; removes an monitored. Visitor PHI and PCI 16 (Delivery mandates regular review of
removable storage unencrypted logs maintained data triggers and Removal) physical access logs and
media is storage drive from a inconsistently. No dual HIPAA extends CCTV retention to 90
unencrypted. production server, hardware audit and PCI DSS days, directly addressing the
and exfiltrates data schedule. breach detection gap that allowed the
offsite. The theft Removable media notification, theft to go unnoticed. PE-16
goes undetected unencrypted. Status: regulatory establishes formal authorization
because physical Partial. penalties, and logging procedures for all
access logs are not and business hardware and media removals,
reviewed regularly. continuity blocking the unauthorized drive
disruption. removal exploit path. The
CVSS: 8.4. combination ensures
prevention (PE-3), detection
(PE-6), and procedural control
(PE-16).
Production Change A software update Change High. SC-7 SC-7 enforces network
outage from management is deployed to management policy Extended (Boundary segmentation between the
failed software process lacks HNetExchange exists but does not multi-system Protection), three production systems,
change mandatory rollback production without a require rollback outage SI-7 (Software directly preventing the
causes plans and pre- rollback plan. The plans or pre- causes SLA Integrity), SC- cascading failure by isolating
cascading deployment test update causes a deployment testing. breaches, 28 (Protection the impact of a failed update to
28
Health Network, Inc. — Final Risk Management Plan
system failure gates; no tested cascading failure BCP exists but client of Info at Rest) the originating system. SI-7
and SLA contingency plan across HNetPay untested for 18 financial implements integrity verification
breach covers all three and HNetConnect months and does claims, that detects unauthorized or
systems due to shared not cover delayed corrupted software changes
simultaneously. infrastructure simultaneous three- claims before propagation to
dependencies. All system outage. processing, production, addressing the root
three systems go Backup jobs run and cause. SC-28 ensures
offline for 72 hours, nightly but reputational encrypted, verified backup
breaching client restoration has not damage. copies exist, enabling rapid
SLAs. been tested. Status: Potential restoration and limiting outage
Weak. regulatory duration. Together: blast radius
scrutiny if isolation (SC-7), deployment
PHI integrity (SI-7), recovery
availability is assurance (SC-28).
affected.
CVSS: 7.5.
Ransomware ~650 corporate An employee Basic spam filtering Critical. SI-3 (Malicious SI-3 requires EDR on 100% of
propagates endpoints lack receives a spear- without attachment Ransomware Code endpoints (closing the 40%
via phishing uniform EDR phishing email with sandboxing or URL encryption of Protection), coverage gap) with behavior-
email and deployment (~60% a weaponized PDF scanning. Anti-virus EHR SC-7 based detection that identifies
encrypts EHR coverage); email attachment. The deployed on databases (Boundary ransomware execution patterns
data across gateway does not attachment approximately 60% causes Protection), before encryption completes,
the network sandbox executes of corporate complete SC-8 blocking the exploit at the
attachments; ransomware that endpoints. loss of PHI (Transmission endpoint. SC-7 enforces
security awareness encrypts local files Awareness training availability, Confidentiality) segmentation between
training is informal and propagates conducted once at triggers corporate and production
and non-recurring. laterally across the onboarding but not HIPAA environments, preventing
corporate network repeated. No breach lateral propagation from a
to HNetExchange network notification, compromised laptop to
EHR databases, segmentation halts clinical HNetExchange databases—
rendering PHI between corporate operations directly breaking the exploit
inaccessible. and production for partner chain. SC-8 mandates
environments. hospitals. encrypted transmission (TLS)
Status: Weak. CVSS: 9.3. for all data in transit. Layered
approach: endpoint detection
(SI-3), network isolation (SC-7),
transmission security (SC-8).
Regulatory No formal A major HIPAA rule Compliance policies Moderate. SI-12 (Info SI-12 requires documented
compliance regulatory watch update introduces exist but lack a Regulatory Management retention and disposal
gap process; control new requirements defined review non- & Retention), schedules aligned with current
discovered framework mapping for PHI access cycle. CCO monitors compliance IA-5 regulations, directly addressing
during OCR not updated when logging and breach regulations results in (Authenticator the compliance gap by
audit due to HIPAA/HITECH/PCI notification informally through OCR Mgmt), IA-8 ensuring data handling
29
Health Network, Inc. — Final Risk Management Plan
missing DSS regulations timelines. Health industry newsletters. corrective (Auth — Non- practices are updated when
regulatory change; policy Network, Inc. is No formal process action plan, Org Users) regulations change. IA-5
watch process review cycle unaware because maps regulatory potential enforces authenticator policies
undefined. no regulatory changes to specific fines (complexity, rotation, secure
monitoring process NIST controls. Last ($100K– storage) aligned with evolving
exists. During a policy update was $1.5M), HIPAA security rule
routine OCR audit, 10 months ago. increased requirements, closing the gap
non-compliance is Status: Partial. audit between current practices and
discovered, scrutiny, and regulatory expectations. IA-8
resulting in a reputational establishes identity verification
corrective action harm with for external users meeting
plan and financial hospital regulatory standards for non-
penalties. clients. organizational portal access.
CVSS: 5.8. Together: governance loop
connecting regulatory
requirements to technical
implementation.
Lost or stolen MDM not fully An employee’s MDM deployed on High. SC-28 SC-28 mandates full-disk
corporate deployed (~70% of corporate laptop is approximately 70% Cached PHI (Protection of encryption on all endpoints
device endpoints); full-disk stolen from a of devices. Full-disk exposure Info at Rest), regardless of OS, directly
exposes encryption not vehicle. The laptop encryption enabled triggers AC-19 (Mobile rendering cached PHI
cached PHI enforced on all OS contains cached on Windows but not HIPAA Device Access unreadable without the
and VPN types; remote wipe PHI from consistently on breach Control), SC- encryption key and neutralizing
credentials not consistently HNetExchange macOS or mobile. notification. 12 (Crypto the data exposure vector. AC-
available; VPN sessions and saved Remote wipe Stolen VPN Key Mgmt) 19 enforces 100% MDM
credentials cached VPN credentials. configured but not credentials enrollment (closing the 30%
in browser without Without full-disk tested. VPN enable gap), enabling remote wipe
protection. encryption or credentials cached unauthorized before the attacker accesses
remote wipe in browser plaintext. network cached data. SC-12 governs
capability, the Status: Partial. access, the cryptographic key lifecycle
attacker accesses potentially including VPN credential
all cached data and escalating to storage, requiring hardware-
uses the VPN a broader backed keystores instead of
credentials to compromise. browser plaintext—blocking the
connect to the CVSS: 7.8. cached credential vector.
corporate network. Combination: data protection
(SC-28), device control (AC-
19), credential security (SC-
12).
30
Health Network, Inc. — Final Risk Management Plan
(five from each family), covering administrative, technical, and physical controls as
required. Every control cited in the risk assessment table (Section 4) appears in this
inventory. The remaining controls (IA-12, SC-13, PE-13, PE-14) provide supporting
31
Health Network, Inc. — Final Risk Management Plan
6 IA-2(1) MFA — Privileged Technical All systems T3 MFA required for all
Accounts privileged logins.
7 IA-2(2) MFA — Non- Technical HNetConnect T3 MFA required for
Privileged patient and provider
Accounts portal logins.
8 IA-5 Authenticator Technical All systems T7 Password complexity,
Management rotation, and secure
storage enforced.
9 IA-8 Auth — Non-Org Technical HNetConnect T7 External user identity
Users verification defined
and enforced.
1 IA-12 Identity Proofing Admin HNetConnect T3 Identity validated
0 through proofing
process before
credential issuance.
32
Health Network, Inc. — Final Risk Management Plan
6. Assessment Approach
NIST SP 800-53A Rev. 5 prescribes three assessment methods. Each control is
33
Health Network, Inc. — Final Risk Management Plan
level inherited controls are assessed first, then system-specific controls. No significant
changes to the environment should occur during the assessment window, as the
before Week 1.
34
Health Network, Inc. — Final Risk Management Plan
Week 1 Define and confirm assessment scope. Finalize Risk PM, CIO
Mar 16–20 systems-in-scope list. Notify all control owners.
Establish centralized evidence repository. Complete
any pending system changes before assessment
begins (point-in-time requirement).
Week 2 Asset inventory and data classification review. Verify Risk PM, SysAdmins,
Mar 23–27 asset list against CMDB. Document system access CCO
and availability requirements per asset.
Week 3 Threat and vulnerability identification workshops. SecOps Lead, Risk PM
Mar 30 – Apr 3 Review prior scan reports and audit findings. Validate
eight threat-vulnerability pairs. Assign initial qualitative
ratings using defined criteria.
Week 4 Control owner interviews (Interview method per SP Risk PM, Owners,
Apr 6–10 800-53A). Collect evidence for all 25 controls. Group Assessors
enterprise-level inherited controls for assessment first,
then system-specific controls.
Week 5 Technical testing of selected controls: MFA (IA-2), SecOps Lead,
Apr 13–17 session timeout (AC-12), encryption (SC-28), EDR (SI- SysAdmins
3), firewall rules (SC-7), patch scan (SI-2), physical
access walk-through (PE-3, PE-6).
Week 6 Risk rating workshop: finalize qualitative likelihood and Risk PM, SecOps Lead,
Apr 20–24 impact ratings for all eight pairs using defined criteria. CCO
Populate risk register. Flag controls requiring
immediate attention.
Week 7 Draft risk assessment findings report. Document all Risk PM, Full Team
Apr 27 – May 1 evidence, interview notes, test results, and control
effectiveness determinations. Peer review for accuracy
and completeness.
Week 8 Senior management review and approval. Present CIO, CEO, Risk PM,
May 4–8 findings to CIO, CEO, CCO. Obtain sign-off. Hand off CCO
findings to Part 3 (Mitigation Planning).
1. Introduction
After completing the risk assessment, senior management at Health Network, Inc.
reviewed the findings and decided to allocate resources for a formal risk mitigation plan.
The assessment found eight threat-vulnerability pairs across our three production
35
Health Network, Inc. — Final Risk Management Plan
and the three co-location data centers. Several of these risks came back as Critical or
This plan is about taking action after finding problems, this part is about fixing them. We
are defining which risks need treatment, what exactly we are going to do about each
one, why those fixes make sense, when the work will happen, who is responsible for
doing it, and what risk is still left over after we are done. This is not just a list of controls
— it is an actual structured plan for how the organization is going to reduce risk in a
practical way.
Everything in this plan builds on what we did before. We are not starting over or
repeating the background analysis. We are using the findings from the assessment as
fixing the risks we found in the assessment. At this point in the project we have already
done the risk management framework, identified all the assets, threats, and
SP 800-53 controls . Now we need to move from analyzing risks to actually treating
them.
This plan supports the organizations security, continuity, and compliance goals by
making sure that identified risks get addressed through deliberate actions that have
funding, accountability, and timelines rather than just hoping someone gets around to it.
36
Health Network, Inc. — Final Risk Management Plan
But we also discovered two new risks during the assessment that were not in the
original scenario. First, there is no formal incident response plan at all (T9). If we get
breached right now, the response would be completely improvised. Second, security
awareness training was done once during employee onboarding and never repeated
These two new risks are added to the remediation table bringing our total to ten risk
items. We also added new controls for these — IR-1, IR-4, IR-6 for incident response
and AT-2, AT-3 for training. The scope and boundaries stay the same as Parts 1 and 2.
We are only working on systems and infrastructure owned by Health Network. No third-
HNetPay, HNetConnect, all three data centers (Minneapolis, Portland, Arlington), the
disaster recovery site, around 1,000 production servers, approximately 650 corporate
endpoints, and all the supporting network infrastructure. All ten threat-vulnerability pairs
(eight original plus the two new ones) are being actively treated. We are not deferring
37
Health Network, Inc. — Final Risk Management Plan
• T2: Insider abuse of HNetPay privileges (Critical) — 14-month access review gap
is dangerous
all currently
• T6: Ransomware via phishing, EDR gap (Critical) — 40% of laptops are
unprotected
• T8: Lost device, encryption and MDM gaps (High) — unencrypted devices are
breach liability
communication first
control review
from scratch
38
Health Network, Inc. — Final Risk Management Plan
development
quarterly program
both. This is what we are doing for all ten risks. It is our primary approach for
everything.
• Risk Avoidance — eliminate the risk entirely by removing the risky condition. We
are not doing this for any of our risks because you cant just shut down
insurance or contracts. Health Network has cyber liability insurance that covers
breach-related costs. This supplements our risk reduction but does not replace it.
• Risk Acceptance — accept whatever risk is left after we implement the fixes.
Every single row in our remediation table identifies the specific residual risk that
remains and how we monitor it. The CIO formally accepts these after
39
Health Network, Inc. — Final Risk Management Plan
So to be clear: all ten risks use Risk Reduction as the primary treatment. Cyber
insurance (Risk Transfer) is supplementary. And we formally accept the residual risk for
40
Health Network, Inc. — Final Risk Management Plan
vulnerability pairs and adds the two new risks (T9 and T10). For each risk we specify what exactly we are going to do and when,
why that fix is appropriate for this specific problem, and what risk remains after implementation.
Threat Vulnerability Possible Identified NIST Remediation Plan / Mitigation Rationale / Effect / Residual Risk
Pair Impact / 800-53r5 Timeline Justification
CVSS Controls / Risk
Score Item
T1: Unpatched CVEs Critical / SI-2 (Flaw Phase 1 (Immediate, Weeks SI-2 fixes the root problem Risk goes from Critical to
on HNetExchange CVSS 9.1 Remediation) SI- 1–4): Set up a formal patch here which is that patches Low. What is left: zero-day
servers enable 3 (Malicious management SLA. Critical are not being applied on vulnerabilities where no
remote code Code Protection) patches have to be applied time. The 14-day SLA for patch exists yet. We cant
execution and PHI SI-4 (System within 14 days, high severity critical patches is what most patch what doesnt have a
exfiltration Monitoring) within 30 days. Put an healthcare organizations patch available. We accept
automated patch tracking follow as best practice. SI-3 this risk and monitor it
dashboard in place so we gives us a backup layer through SI-4 continuous
can actually see what is because even if we miss a monitoring and threat
patched and what isnt. patch or there is a zero-day, intelligence feeds. Network
Phase 2 (Near-term, Weeks the EDR can detect the segmentation (SC-7) limits
5–8): Replace the old attacker moving around the the damage if someone
signature-based antivirus on network after they get in. SI- does get in through a zero-
all production servers with 4 adds monitoring so we can day.
behavior-based EDR that actually see the scanning
can catch things antivirus and data theft happening
misses. Phase 3 (Near-term, and respond before all the
Weeks 6–10): Configure data is gone. Treatment
SIEM alerts for network approach: Risk Reduction.
scanning patterns and any We are layering three
outbound data transfers that controls together — patching
look unusual compared to to prevent, EDR to detect,
our baseline. Responsible:
41
Health Network, Inc. — Final Risk Management Plan
T2: Privileged Critical / AC-6 (Least Phase 1 (Immediate, Weeks AC-6 cuts down on how Risk goes from Critical to
insider abuses CVSS 9.0 Privilege) AC-5 1–3): Do an emergency much damage an insider can Low. What is left: two
elevated HNetPay (Separation of access review of every do by limiting their access to insiders could potentially
access to steal Duties) AC-2 single HNetPay privileged only what they need. Right collude where one approves
payment card data (Account account right now. Remove now people have way more and the other executes. This
via USB exfiltration Management) any permissions that are access than necessary. AC- is theoretically possible but
more than what the person 5 makes the specific attack very unlikely. We monitor for
actually needs for their job. described in our assessment it through SIEM alerts on
Phase 2 (Immediate, Weeks impossible because you unusual privileged activity
2–4): Set up separation of need two different people to patterns. Management
duties in the payment complete a payment. AC-2 reviews this residual risk
workflow so one person makes sure we review quarterly.
approves a payment and a access every quarter so
different person executes it. stale permissions dont build
No single person should be up over 14 months like they
able to do both. Phase 3 did before. Disabling USB
(Near-term, Weeks 4–8): Set blocks the physical
up automated quarterly exfiltration path. Treatment
access reviews so we never approach: Risk Reduction.
have a 14-month gap again. We are addressing the
Disable USB write on all vulnerability (too much
workstations through GPO. access), the exploit path
Turn on DLP monitoring for (one person doing
HNetPay database queries. everything), and the
Responsible: Dir. of Finance governance gap (nobody
Operations, Risk PM, reviewing access).
System Administrators.
T3: Credential High / IA-2(1) (MFA — Phase 1 (Immediate, Weeks IA-2(1) and IA-2(2) basically Risk goes from High to Low.
stuffing attack CVSS 8.1 Privileged) IA- 1–4): Roll out MFA for all kill the credential stuffing What is left: MFA fatigue
compromises 2(2) (MFA — privileged accounts across attack because even if an attacks where the attacker
HNetConnect patient Non-Privileged) all systems first because attacker has a stolen keeps sending push
portal accounts AC-12 (Session these accounts can do the password, they still cant get notifications until the user
using breached Termination) most damage if in without the second factor. accidentally approves, or
credentials compromised. We will use This is the most effective fix SIM-swapping if we used
42
Health Network, Inc. — Final Risk Management Plan
TOTP or push-based MFA, we can do for this threat. SMS. That is why we chose
not SMS. Phase 2 (Near- AC-12 fixes the session TOTP/push-based MFA
term, Weeks 4–8): Extend timeout inconsistency which instead of SMS. We monitor
MFA to all patient and was allowing attackers to through login anomaly
provider portal logins on hijack abandoned sessions. detection in SIEM.
HNetConnect. This takes Treatment approach: Risk
longer because we need to Reduction. MFA handles the
communicate the change to main vulnerability
patients beforehand. Phase (passwords only) and
3 (Immediate, Weeks 2–3): session termination handles
Fix the session timeout the secondary problem
problem. Right now some (inconsistent timeouts). We
HNetConnect modules do privileged accounts first
timeout at 30 minutes and because they are higher risk.
others at 4 hours which
makes no sense.
Standardize everything to 15
minutes. Responsible: Dir. of
Security Operations, System
Administrators,
HNetConnect application
team.
T4: Physical theft of Critical / PE-3 (Physical Phase 1 (Immediate, Weeks PE-3 stops the tailgating that Risk goes from Critical to
unencrypted storage CVSS 8.4 Access Control) 1–3): Upgrade from badge- lets unauthorized people Low. What is left: someone
media from PE-6 (Monitoring only entry to badge + PIN at walk in. Adding a PIN on top with legitimate authorized
Minneapolis data Physical Access) all three data centers. Install of the badge and putting in a access could still try to steal
center via tailgating PE-16 (Delivery an anti-tailgating mantrap at mantrap makes it much media, but with PE-16
and Removal) the Minneapolis primary harder to just follow logging, PE-6 weekly
facility so people cant just someone through. PE-6 fixes monitoring, media
follow someone through the the detection problem encryption, and quarterly
door. Phase 2 (Near-term, because in our assessment physical audits it would be
Weeks 3–6): Extend CCTV we found that the theft went very hard to do without
footage retention from 7 completely unnoticed since getting caught. We accept
days to 90 days. Right now nobody was checking the this residual risk and monitor
by the time we notice logs and CCTV was only through continuous CCTV
something is wrong the kept for 7 days. PE-16 review and quarterly audits.
footage is already gone. Also makes sure that every piece
43
Health Network, Inc. — Final Risk Management Plan
T5: Failed software High / SC-7 (Boundary Phase 1 (Immediate, Weeks SC-7 directly prevents the Risk goes from High to Low.
change causes CVSS 7.5 Protection) SI-7 1–4): Put network cascading failure from What is left: complex
cascading (Software segmentation between happening again by isolating software bugs that pass all
production outage Integrity) SC-28 HNetExchange, HNetPay, the three systems from each integrity checks but still
across all three (Protection of Info and HNetConnect so if one other. SI-7 catches the root cause problems at runtime.
systems (72-hour at Rest) system crashes the others cause by detecting bad or We handle this through
SLA breach) dont go down with it. Right unauthorized code before it mandatory pre-deployment
now they share infrastructure gets deployed to production. testing and rollback plans
dependencies which is why If we had this before, the which the Change Control
one bad update took problematic update would Board reviews for every
everything down. Phase 2 have been caught. SC-28 single production change.
(Near-term, Weeks 4–8): Set makes sure we have good
up software integrity encrypted backups so even
verification using hash if something does go wrong
validation and code signing we can restore quickly.
for all production Treatment approach: Risk
deployments. Also make it Reduction. Prevention (SI-7)
mandatory to have a rollback plus isolation (SC-7) plus
plan and do pre-deployment recovery (SC-28).
testing before any change
44
Health Network, Inc. — Final Risk Management Plan
T6: Ransomware Critical / SI-3 (Malicious Phase 1 (Immediate, Weeks SI-3 closes the 40% EDR Risk goes from Critical to
propagates via CVSS 9.3 Code Protection) 1–4): Deploy EDR on every gap so every endpoint can Low. What is left: zero-day
phishing email from SC-7 (Boundary corporate endpoint. Right detect ransomware ransomware that EDR has
corporate endpoint Protection) SC-8 now 40% of them dont have execution patterns like mass never seen before could still
to HNetExchange (Transmission it which is basically leaving file encryption before it encrypt one laptop. But
EHR databases Confidentiality) the door wide open. Set up finishes. SC-7 is the big one network segmentation
behavior-based ransomware here — it breaks the exploit means it cant spread to
detection rules. Phase 2 chain completely by production, and verified
(Immediate, Weeks 2–4): preventing the ransomware backups mean we can
Enforce network from jumping from a restore without paying the
segmentation between the corporate laptop to the ransom. We monitor through
corporate endpoint network production EHR databases. SIEM alerting and track
(VLAN 60–62) and Even if an endpoint gets phishing simulation click
production systems. Block all infected the production rates as a leading indicator.
direct traffic from corporate systems stay safe. SC-8
VLANs to production encrypts data in transit so
database VLANs. This is the intercepted traffic cant be
most important fix because it used for further attacks. The
breaks the chain. Phase 3 phishing training is a
(Near-term, Weeks 4–8): compensating control that
Upgrade email gateway with reduces the chance of the
attachment sandboxing and initial compromise
URL detonation so malicious happening. Treatment
attachments get caught approach: Risk Reduction.
before they reach the user. Layered approach: endpoint
Start quarterly phishing detection (SI-3), network
45
Health Network, Inc. — Final Risk Management Plan
T7: Regulatory Moderate / SI-12 (Info Phase 1 (Near-term, Weeks SI-12 directly fixes the Risk goes from Moderate to
compliance gap CVSS 5.8 Management & 4–8): Set up a formal compliance gap by making Low. What is left: regulatory
discovered during Retention) IA-5 regulatory watch process. sure we have documented changes that happen
OCR audit due to (Authenticator The CCO will be responsible retention and disposal between quarterly review
absent regulatory Mgmt) IA-8 (Auth for doing a quarterly review schedules that get updated cycles could temporarily
watch process — Non-Org of any regulatory changes whenever regulations leave us out of alignment.
Users) from HIPAA, HITECH, or change. IA-5 aligns our To handle this the CCO will
PCI DSS and mapping those password policies with subscribe to real-time
changes to our NIST current regulatory HHS/OCR regulatory alerts
controls and system expectations because right so we hear about changes
configurations. Phase 2 now there is a gap between right away. Residual risk
(Near-term, Weeks 6–10): what we actually do and accepted at Low.
Document data retention and what HIPAA requires. IA-8
disposal schedules that handles the external user
actually align with current identity verification that
HIPAA and PCI DSS regulators expect for non-
requirements. Set up organizational portal access.
automated enforcement so Treatment approach: Risk
old data gets disposed of Reduction. These three
properly. Phase 3 (Long- controls create a loop where
term, Weeks 8–12): Review regulatory changes get
and update our password connected to actual technical
and authentication policies to implementation.
match the latest HIPAA
Security Rule guidance. Set
up proper identity verification
for external users like
patients and partner
46
Health Network, Inc. — Final Risk Management Plan
providers on HNetConnect.
Responsible: CCO, Risk PM,
Dir. of Security Operations.
T8: Stolen corporate High / SC-28 Phase 1 (Immediate, Weeks SC-28 is the single most Risk goes from High to Low.
laptop exposes CVSS 7.8 (Protection of Info 1–4): Enforce full-disk important control here. If a What is left: there is a brief
cached PHI and VPN at Rest) AC-19 encryption on every laptop has full-disk window between when the
credentials enabling (Mobile Device corporate endpoint encryption and it gets stolen, device is stolen and when
network access Access Control) regardless of whether it is the thief just has an we remote wipe it. During
SC-12 (Crypto Windows, macOS, or mobile. expensive paperweight. that window someone could
Key Mgmt) Verify encryption status They cant read anything theoretically try to attack the
through MDM compliance without the encryption key. encryption. But modern full-
checks. Phase 2 (Immediate, The stolen device becomes disk encryption is very
Weeks 2–4): Enroll the a hardware loss not a data strong so this is extremely
remaining 30% of devices breach. AC-19 closes the low probability. We monitor
that are not in MDM. Actually 30% MDM gap so we can through MDM device status
test remote wipe by wiping a actually remote wipe any alerts.
sample device to prove it device that gets stolen
works. Phase 3 (Near-term, before the attacker can do
Weeks 4–8): Move VPN anything with it. SC-12
credentials from browser eliminates the VPN
plaintext storage (which is credential problem by
terrible) to hardware-backed requiring credentials to be
keystore or certificate-based stored in secure hardware
authentication. No more instead of in the browser
saved passwords in Chrome. where anyone can see them.
Responsible: System Treatment approach: Risk
Administrators, Dir. of Reduction.
Security Operations.
T9 (NEW): Lack of High / IR-1 (Incident Phase 1 (Near-term, Weeks IR-1 gives us the policy Risk goes from High to Low.
formal incident CVSS 7.0 Response Policy) 4–8): Write a formal incident foundation that currently What is left: novel attack
response plan IR-4 (Incident response plan from scratch does not exist at all. Without types that our IR plan doesnt
results in delayed Handling) IR-6 covering detection, analysis, a formal plan, breach cover might need improvised
breach detection (Incident containment, eradication, response is just people response. We handle this by
and regulatory Reporting) (New recovery, and post-incident figuring it out as they go running quarterly tabletop
notification controls added) review. Right now we have which is a recipe for missing exercises that test different
nothing documented so if we the HIPAA 60-day scenarios so the team gets
47
Health Network, Inc. — Final Risk Management Plan
T10 (NEW): Absence Moderate / AT-2 (Literacy Phase 1 (Near-term, Weeks AT-2 directly fixes the Risk goes from Moderate to
of recurring security CVSS 6.5 Training and 4–8): Start mandatory problem we found in the Low. What is left: even well-
awareness training Awareness) AT-3 quarterly security awareness assessment which is that trained people will
increases phishing (Role-Based training for all employees security training was done occasionally fall for a really
susceptibility across Training) (New covering phishing once during onboarding and sophisticated targeted
1,200+ employees controls added) recognition, credential never again. Employees phishing email. That is just
protection, and social dont know how to spot human nature. But we have
engineering. Phase 2 (Near- modern phishing because layered technical controls
term, Weeks 6–10): Deploy nobody refreshed their (SI-3 EDR and SC-7
monthly phishing simulation knowledge. Quarterly segmentation) that contain
campaigns. Track click rates training fixes this. AT-3 gives the damage even if
by department. Anyone who specialized deeper training someone does click. We
fails the simulation gets for high-risk roles because a track click rates as a leading
remedial training. Phase 3 system administrator needs indicator of how well the
(Long-term, Ongoing): Set to know a lot more about training is working.
up role-based training for security than a regular office
privileged users, system worker. The phishing
administrators, and people simulations give us actual
48
Health Network, Inc. — Final Risk Management Plan
49
Health Network, Inc. — Final Risk Management Plan
controls and to specific threat-vulnerability pairs. We did not pick these actions because
they are general best practices. We picked them because each one fixes a specific
• Patch management SLA (SI-2): 14-day critical, 30-day high patch cycle. Directly
• EDR deployment to 100% of endpoints (SI-3): Closes the 40% coverage gap.
Catches ransomware patterns (T6) and post-exploitation activity (T1) that basic
antivirus misses.
portal. Kills the credential stuffing attack in T3 because stolen passwords alone
traffic. Prevents cascading failures (T5) and stops ransomware from jumping to
production (T6).
regardless of OS. 100% MDM enrollment. Stolen laptop becomes hardware loss
50
Health Network, Inc. — Final Risk Management Plan
• Access review and separation of duties (AC-6, AC-5, AC-2): Emergency access
• Incident response plan (IR-1, IR-4, IR-6): Writing the IR plan from scratch
because nothing exists. Includes tabletop exercises and SIEM integration. Fixes
T9.
monthly phishing simulations, role-based training for privileged users. Fixes T10.
• Data center access upgrades (PE-3, PE-6, PE-16): Badge + PIN entry, anti-
Every action connects to a specific vulnerability. Controls that already partially exist get
strengthened. Controls that are completely missing get built from scratch with testing
and validation.
51
Health Network, Inc. — Final Risk Management Plan
9. Mitigation Prioritization
Not everything can happen at the same time. We prioritized based on how severe the
risk is, how critical the affected system is, whether the fix is feasible right away, and
what the organization needs most urgently. The table below shows the sequence:
Immediate T1: Patch SLA (SI-2) Critical Weeks 1– Unpatched CVEs are
4 actively exploitable right
now. Highest urgency.
Immediate T2: Access review and Critical Weeks 1– 14-month access review
separation of duties (AC-6, AC- 4 gap with active PCI data
5, AC-2) exposure.
Immediate T3: MFA for privileged High Weeks 1– Privileged accounts can do
accounts (IA-2(1)) 4 the most damage if
compromised.
Immediate T6: EDR deployment to 100% Critical Weeks 1– 40% of endpoints have no
(SI-3) 4 protection at all.
Immediate T8: Full-disk encryption (SC- High Weeks 1– Unencrypted devices are an
28) 4 immediate breach liability.
Near-term T3: MFA for non-privileged (IA- High Weeks 4– Patient portal accounts need
2(2)) 8 user communication first.
Near-term T4: Physical access upgrades Critical Weeks 3– Need to procure hardware
(PE-3, PE-6, PE-16) 8 for mantrap and CCTV
storage.
Near-term T6: Email gateway upgrade, Critical Weeks 4– Vendor selection and
network segmentation 8 procurement takes time.
Near-term T9 (NEW): Incident response High Weeks 4– Need to develop policy from
plan (IR-1, IR-4, IR-6) 10 scratch and run tabletop.
Long-term T7: Regulatory watch process Moderate Weeks 6– Process development and
(SI-12, IA-5, IA-8) 12 policy review cycle.
52
Health Network, Inc. — Final Risk Management Plan
implements, who validates, and who accepts residual risk. The table below covers all of
that. These roles are consistent with Parts 1 and 2 but with additional mitigation-specific
duties.
CCO Makes sure all our remediation actions comply with HIPAA, HITECH, and
PCI DSS. Leads the regulatory watch process for T7. Reviews residual risk
to confirm we are not creating any compliance issues.
Dir. of Security Does the heavy lifting on technical implementation — EDR deployment
Operations (SI-3), SIEM configuration (SI-4), MFA rollout (IA-2), network segmentation
(SC-7). Also leads the IR plan development for T9. Validates that the fixes
actually work after implementation.
System Administrators Hands-on execution — applying patches (SI-2), enforcing encryption (SC-
28), configuring GPO to disable USB (T2), enrolling devices in MDM (AC-
19), setting up firewall rules for segmentation (SC-7).
HR Director Runs the security awareness training program (AT-2, AT-3). Coordinates
the phishing simulations. Tracks training completion metrics so we know
who has done it and who hasnt.
Data Center Manager Implements the physical controls — badge + PIN upgrades (PE-3), CCTV
53
Health Network, Inc. — Final Risk Management Plan
Change Control Board Reviews and approves every single production change related to
remediation. Makes sure a rollback plan exists for each implementation.
Validates that changes were completed successfully.
Independent Assessors These are the people who verify our fixes actually work. They test
independently from the people who implemented the controls because you
cant grade your own homework. Controls are not considered effective until
assessors confirm it.
not about writing the report, it is about doing the work. Enterprise-level controls go first
Phase 6.
54
Health Network, Inc. — Final Risk Management Plan
that the fixes are still working and that residual risk is being managed. Here is how we
will do that:
• POA&M Tracking: The Risk PM keeps a Plan of Action and Milestones tracker
for all remediation items. During implementation the status gets reported to CIO
independent assessors come in and test it using the Examine, Interview, and
55
Health Network, Inc. — Final Risk Management Plan
Test methods from NIST SP 800-53A Rev. 5. The fix is not considered done until
to make sure they are still working properly. Results go into the risk register.
• Residual Risk Reassessment: At the end of Phase 5 and then annually after that,
we formally reassess the residual risk for each threat-vulnerability pair. The CIO
• Escalation of Delayed Remediation: If any fix falls more than two weeks behind
schedule it automatically gets escalated to the CIO with a revised plan explaining
• Management Review of Open Risks: The CIO, CCO, and Risk PM sit down
quarterly to review all open risks, residual risk status, and POA&M progress. This
13. Conclusion
This plan takes the findings and turns them into a real remediation strategy for Health
Network. All eight original threats and two newly discovered risks are addressed with
specific actions, timelines, ownership, and documented residual risk. We showed that
our mitigation decisions are based on the assessment findings, that we chose treatment
approaches intentionally, and that we have a realistic plan for reducing risk through
prioritized implementation.
The implementation goes in phases: immediate actions tackle the most severe risks
(T1, T2, T3, T6, T8) in the first four weeks, near-term actions handle physical security,
segmentation, and incident response (T4, T5, T9) through Week 10, and long-term
56
Health Network, Inc. — Final Risk Management Plan
actions set up the ongoing governance and training programs (T7, T10). Independent
validation and continuous monitoring make sure the fixes actually work and that residual
1. Introduction
Health Network, Inc. depends on the continuous availability of its three core production
physicians, and patients across multiple states. A disruption to any of these systems
VA office, creating a single point of failure for critical business functions that support the
entire organization.
Senior management has recognized this risk and has allocated full funding for both a
Business Impact Analysis (BIA) and a Business Continuity Plan (BCP). This document
delivers both. The BIA identifies which business functions are most critical, what
systems and resources support them, how long the organization can tolerate outages,
57
Health Network, Inc. — Final Risk Management Plan
and how much data loss is acceptable. The BCP then explains how the organization will
continue critical business operations during and after a disruption, using the BIA
findings to prioritize recovery. This is a planning document, not a full technical recovery
manual.
It is important to distinguish between BCP and Disaster Recovery (DR). BCP focuses
on continuing critical business functions during a disruption, starting with the most
possible. DR focuses on full system recovery, starting with the least important systems
first to avoid breaking dependencies during restoration (Gibson & Igonor, 2020). This
plan addresses BCP; DR procedures are a separate effort that builds on the recovery
business functions, map them to the systems and resources they depend on, and
establish recovery requirements (MAO, RTO, RPO) based on the business impact of
disruption. The BIA provides the analytical foundation for the BCP by answering: what
must be recovered first, how quickly, and with how much acceptable data loss.
The purpose of the BCP is to document how the organization will continue critical
operations following a disruption, and the plan should address recovery priorities based
58
Health Network, Inc. — Final Risk Management Plan
on the results of a business impact analysis (NIST, 2010). The BCP translates the BIA’s
presence)
IDS/IPS
• Inter-site VPN connectivity between all three corporate locations and all
locations
59
Health Network, Inc. — Final Risk Management Plan
• Arlington office is the primary location for Finance, Legal, and Customer Support
business units
no secondary instance
• Each corporate location can access the other two via VPN
Outside scope: external hospital systems, third-party payment processors beyond the
integration boundary, patient-owned devices, and full disaster recovery procedures (DR
4. BIA Methodology
The BIA follows the methodology described in NIST SP 800-34 Rev. 1 and Gibson and
Igonor (2020). The process involves: (1) identifying critical business functions and
prioritizing them by business impact, (2) identifying the critical support functions
necessary for each business function, (3) mapping business and support functions to
the systems and resources they depend on, (4) determining the Maximum Acceptable
Outage (MAO), Recovery Time Objective (RTO), and Recovery Point Objective (RPO)
for each function, and (5) identifying current continuity gaps that affect the
60
Health Network, Inc. — Final Risk Management Plan
• Maximum Acceptable Outage (MAO): The longest time a business function can
• Recovery Time Objective (RTO): The target time within which a system or
function must be restored after a disruption. RTO must be less than or equal to
MAO.
• Recovery Point Objective (RPO): The maximum acceptable amount of data loss
measured in time. RPO defines how far back in time the recovery point may be
All MAO, RTO, and RPO values are based on the operational characteristics of Health
Network, Inc.’s systems, regulatory requirements (HIPAA, PCI DSS), contractual SLA
obligations with hospital clients, and industry benchmarks for healthcare IT continuity
planning.
importance for BCP activation. Per Professor Brough’s guidance, BCP starts with the
most important functions first (to restore revenue and essential services), which is the
opposite of DR (which starts with the least important to avoid breaking dependencies
during recovery).
61
Health Network, Inc. — Final Risk Management Plan
This is the highest-priority function because it directly supports patient care. Hospitals
records. Disruption creates patient safety risk. Critical support functions: internet
Patient-facing portal for scheduling, records, and telehealth. Important for patient
satisfaction and telehealth revenue but not life-safety critical. Critical support functions:
62
Health Network, Inc. — Final Risk Management Plan
Supports regulatory response, contract review, and breach notification procedures. Can
operate manually for limited periods. Critical support functions: corporate LAN, VPN,
Handles provider and patient inquiries. Can operate via phone and email during
• Email and Internal Communications: supports all business functions and BCP
activation communications
depend on it
63
Health Network, Inc. — Final Risk Management Plan
includes the MAO, RTO, and RPO with the calculation logic and basis for each value.
Business Support Supporting Business Impact MAO RTO RPO Basis for MAO / RTO / RPO
Function Function(s) System(s) / if Disrupted
Resource(s)
EHR Exchange Internet HNetExchange Hospitals and 4 2 15 MAO: HIPAA requires reasonable
and Clinical Data connectivity (web/app providers cannot hours hours minutes availability of PHI; clinical workflows
Sharing (Priority (ISP); DNS; servers, EHR transmit or retrieve cannot tolerate outages beyond 4
1) PKI/certificate database); patient records. hours without patient safety risk. RTO:
services; API Minneapolis Clinical decision- Active-passive failover to Portland
gateway data center making is delayed. secondary requires approximately 2
(primary); Patient safety risk. hours for DNS propagation, database
Portland data HIPAA availability synchronization verification, and
center violation. application restart. RPO: 15 minutes
(secondary) Estimated financial based on synchronous database
impact: $150,000– replication between Minneapolis and
$250,000 per day Portland; maximum data loss equals
in SLA penalties the replication lag window. Calculation:
and provider RPO = replication interval (15 min) +
claims. commit verification (< 1 min) ≈ 15 min.
Payment Internet HNetPay Claims processing 8 4 1 hour MAO: Payment processing can tolerate
Processing and connectivity; (payment halts. Provider hours hours a longer outage than clinical systems
Claims third-party web/app reimbursements because claims can be queued and
Management payment servers, delayed. Revenue resubmitted. 8-hour MAO aligns with a
(Priority 2) gateway; payment card generation stops. single business day. RTO: Failover to
banking database); PCI DSS secondary data center requires
network Minneapolis compliance risk if database consistency verification for
connectivity; data center; failover exposes financial records (4 hours). RPO: 1
PKI services third-party cardholder data. hour based on hourly incremental
payment Estimated financial backup schedule for payment
64
Health Network, Inc. — Final Risk Management Plan
Patient Portal Internet HNetConnect Patients cannot 24 8 4 hours MAO: Patient portal is important but
Access (Priority connectivity; (web portal, schedule hours hours not life-safety critical. 24-hour outage is
3) DNS; identity patient profile appointments, tolerable with proactive patient
management / database, access records, or communication. RTO: Application
MFA services; session use telehealth. restore from backup and DNS failover
telehealth management); Patient satisfaction (8 hours). RPO: 4-hour incremental
platform Minneapolis declines. Moderate backup cycle for patient profile data.
data center; reputational Calculation: RPO = backup interval (4
Arlington impact. Estimated hours) + restore verification (< 30 min)
corporate financial impact: ≈ 4 hours.
network $30,000–$60,000
per day in lost
telehealth revenue
and support call
volume increase.
Corporate Corporate LAN; Payroll and Payroll processing 48 24 24 hours MAO: Payroll runs biweekly; a 48-hour
Finance, Payroll, VPN between accounting delayed. Financial hours hours outage is tolerable if it does not
and Accounting offices; Active applications reporting halted. coincide with a pay cycle. RTO:
(Priority 4) Directory; email (Arlington office Vendor payments Currently 24 hours because corporate
only — NOT missed. Employee systems are NOT backed up and must
backed up); morale impact if be rebuilt from scratch if lost. This is a
corporate file payroll is late. critical gap. RPO: 24 hours (currently
servers; Estimated financial no backup exists; data loss equals time
Arlington impact: $20,000– since last manual export). Calculation:
corporate $50,000 per RPO = ∞ (no backup) →
network occurrence in late recommended target after remediation:
payment penalties 4 hours with new backup solution.
and overtime.
Legal and Corporate LAN; Legal case Regulatory 72 48 24 hours MAO: Legal functions can operate
Compliance VPN; email; management response hours hours manually (phone, paper) for up to 72
Operations document system deadlines missed. hours. RTO: Systems can be restored
65
Health Network, Inc. — Final Risk Management Plan
Customer Internet CRM system Customer inquiries 72 24 8 hours MAO: Support can operate via
Support and connectivity; (Arlington unanswered. hours hours personal cell phones and email for up
Help Desk VPN; office); VoIP Provider support to 72 hours. RTO: CRM and ticketing
(Priority 6) telephony/VoIP; phone system; delayed. restoration from backup within 24
email; CRM email; ticketing Reputational hours. RPO: 8 hours for ticket and
system impact. Estimated interaction history. Calculation: RPO =
financial impact: backup interval (8 hours) + data replay
$5,000–$15,000 (< 1 hour) ≈ 8 hours.
per day in
customer churn
risk.
Email and Internet Microsoft All internal 4 2 1 hour MAO: Email is a critical support
Internal connectivity Exchange / coordination hours hours function for all business functions and
Communication (ISP); DNS; email servers; disrupted. Incident BCP activation. 4-hour MAO matches
s (Critical Active Directory corporate response the most critical dependent function
Support network; VPN communication (EHR Exchange). RTO: Cloud-based
Function) impaired. BCP email failover or secondary MX routing
activation (2 hours). RPO: 1-hour email journal
notifications backup. Calculation: RTO = DNS MX
delayed. Cross-site record update (30 min) + mailbox sync
coordination (90 min) ≈ 2 hours.
between
Minneapolis,
Portland, and
66
Health Network, Inc. — Final Risk Management Plan
Arlington fails.
Network ISP (primary Firewalls; VPN All remote access 2 1 hour N/A MAO: Network is the foundational
Connectivity and and gateways; fails. Inter-site hours (stateless support function; all other functions
VPN (Critical secondary); routers; communication ) depend on it. 2-hour MAO reflects that
Support power; UPS; switches; DMZ; between no business function can operate
Function) data center inter-site WAN Minneapolis, without connectivity. RTO: Failover to
network links Portland, and secondary ISP and backup VPN
infrastructure Arlington severed. gateway (1 hour). RPO: N/A —
No system is network is stateless; no data to
accessible recover. Calculation: RTO = ISP
remotely. All failover (15 min) + VPN re-
business functions establishment (30 min) + routing
dependent on convergence (15 min) ≈ 1 hour.
network are
affected.
67
Health Network, Inc. — Final Risk Management Plan
established in the BIA. These gaps must be addressed to make the BCP effective.
Gap or Weakness Affected Function / Continuity Risk Created Effect on MAO / RTO / Recommended Improvement
System RPO
Corporate systems Finance/Payroll, Complete data loss if Arlington RPO becomes Implement daily automated backup of
(payroll, accounting, Legal/Compliance, systems fail. RPO is effectively unrecoverable. RTO all Arlington corporate systems to the
legal) are NOT backed Customer Support infinite—all data since last extends to full system Minneapolis or Portland data center
up (Arlington) manual export would be lost. rebuild (days, not via VPN. Target RPO: 4 hours with
hours). MAO is incremental backups.
exceeded immediately.
Payroll and Corporate Finance Single point of failure. If MAO for payroll is Deploy payroll application to a
accounting and Payroll Arlington facility is inaccessible effectively zero during secondary location (Portland or cloud-
applications exist in (e.g., winter storm), payroll pay cycles because no hosted). Establish ability to process
only one location cannot be processed from any alternate processing payroll remotely.
(Arlington) other location. capability exists.
No formal BCP exists All corporate functions No documented procedures for All corporate MAO/RTO This document establishes the initial
for corporate (Finance, Legal, continuing corporate values are theoretical BCP. Tabletop testing should validate
operations Customer Support) operations during disruption. because no tested plan all stated MAO/RTO/RPO values.
Staff have no guidance on exists to achieve them.
alternate work methods.
VPN is the only inter- All functions requiring If VPN infrastructure fails, no RTO for all cross-site Establish secondary VPN concentrator
site connectivity cross-site access site can access another. dependent functions at each site. Evaluate SD-WAN or
method Remote work becomes increases because there dedicated MPLS circuit as backup
impossible. is no alternate connectivity.
connectivity path.
No alternate work site Finance, Legal, If Arlington office is physically MAO for all Arlington- Designate Portland and Minneapolis
designated for Customer Support inaccessible, approximately based functions extends offices as alternate work sites. Enable
Arlington staff 400+ employees have no until physical access is VPN remote work for all Arlington staff.
designated alternate work restored, which may be Pre-provision laptops with VPN
location. days. access.
68
Health Network, Inc. — Final Risk Management Plan
center power outage scenario, and an additional ransomware scenario—with corresponding continuity strategies, alternate work
Scenario 1 Finance/Payroll, Activate remote work for All Arlington staff VPN infrastructure must Assumes Arlington building
(Required): Winter Legal/Compliance all Arlington staff via work from home via remain operational. is inaccessible but systems
storms on the , Customer VPN. Redirect customer VPN using pre- Arlington systems must inside are still running
East Coast Support, Email, support calls to provisioned corporate remain powered and (power, HVAC, network
prevent Arlington VPN Minneapolis and Portland laptops. Customer accessible remotely intact). If systems are also
employees from offices. Finance team support uses VoIP (facility itself is down, this scenario
reaching the processes payroll softphones and CRM inaccessible, but systems escalates to Scenario 3.
office safely for 3– remotely using VPN web access. Finance are running). ISP Assumes all staff have
5 days. access to Arlington accesses payroll connectivity to Arlington home internet access.
systems (if systems are application remotely data center must be Payroll backup at Portland
operational) or from or uses Portland maintained. All staff must may not be available until
Portland backup (once backup instance. have VPN-capable gap remediation is
implemented). Legal laptops at home. complete.
operates via email,
phone, and remote
document access.
Scenario 2 EHR Exchange, Failover HNetExchange HNetExchange: Portland data center Assumes Portland can
(Generic): Payment to Portland secondary automatic DNS must have sufficient absorb full production load.
Prolonged power Processing, data center (active- failover to Portland (2- capacity to handle Assumes database
outage at Patient Portal, passive failover). hour RTO). HNetPay: primary production load. replication lag is within
Minneapolis Network/VPN, Failover HNetPay to manual failover with Database replication RPO (15 min for
primary data Email Portland. HNetConnect database consistency between Minneapolis and HNetExchange, 1 hour for
center lasting 24– restored from Portland check (4-hour RTO). Portland must be current. HNetPay). Performance
72 hours due to backup. Activate disaster HNetConnect: restore DR site must be degradation is expected
utility failure recovery site for from backup at activated if outage during failover period.
beyond UPS and extended outage. Notify Portland (8-hour exceeds 72 hours. Portland does not host
generator all hospital and provider RTO). Email: Generator fuel supply at corporate applications
capacity. clients of temporary secondary MX routing Portland must be verified. (Finance, Legal)—these
69
Health Network, Inc. — Final Risk Management Plan
70
9. Business Continuity Plan
The BCP defines how Health Network, Inc. will continue critical business operations
during and after a disruption. It is driven by the BIA: the most critical functions with the
shortest MAO receive the highest recovery priority. The BCP is activated when any
triggered when a disruption event affects or is projected to affect the availability of any
critical business function beyond its MAO. Upon activation, the Risk PM coordinates all
• Priority 1: Network Connectivity and VPN (RTO: 1 hour) — foundational; all other
functions depend on it
BCP coordination
critical
life-safety
• Priority 6: Corporate Finance and Payroll (RTO: 24 hours) — critical only during
pay cycles
• Priority 7: Legal and Compliance (RTO: 48 hours) — can operate manually short-
term
• Priority 8: Customer Support (RTO: 24 hours) — can operate via phone short-
term
sequence—starting with the least critical systems first to avoid breaking dependencies
during recovery. The CIO authorizes the transition from BCP to DR mode. The Risk PM
coordinates with all business unit leads to confirm function stability before transitioning.
maintenance procedures.
Roles Business unit Finance Dir., Each business Ongoing Function status
leads Legal, unit lead during confirmation
Customer confirms BCP
Support Mgr. function status, activation
activates
alternate work
methods,
reports
readiness to
Risk PM.
Maintenance Plan review Risk PM, CIO Review and Annually Updated BCP
and update update BCP and after document;
document. every BCP change log
Incorporate activation
lessons or
learned from significant
tests and real system
incidents. change
Update contact
lists, system
inventories,
and recovery
procedures.
Network, Inc. will test the BCP using multiple methods at defined intervals:
scenario walkthrough. Each of the three scenarios (winter storm, power outage,
functionality, and DNS propagation are verified. Actual RTO is measured against
restored from backup. Data integrity is verified. Actual RPO is measured against
targets. This test is critical because corporate systems are currently NOT backed
up—once backups are implemented per the gap analysis, regular restoration
• Lessons Learned: After every test and every real BCP activation, a lessons-
• Plan Review (Annually and after significant changes): The full BCP document is
responsibilities:
Reports to CIO.
payroll processing.
arrangements.
13. Conclusion
This Business Impact Analysis and Business Continuity Plan provides Health Network,
identifies eight critical business and support functions, maps them to supporting
systems and resources, and establishes MAO, RTO, and RPO values with calculation
logic for each. The continuity gap analysis identifies five critical weaknesses—most
notably that corporate systems at Arlington are not backed up and payroll applications
exist in only one location—that must be remediated for the BCP to be effective.
The BCP addresses three disruption scenarios (Arlington winter storm, Minneapolis
power outage, and ransomware attack) with specific continuity strategies, alternate work
methods, and recovery sequences. The plan prioritizes recovery starting with the most
critical functions first, consistent with BCP principles. Testing and maintenance
procedures ensure the plan remains current and validated through semi-annual tabletop
exercises, quarterly communication drills and backup restoration tests, and annual
This plan builds directly on the risk management (Part 1), risk assessment (Part 2), and
risk mitigation (Part 3) work completed earlier in this project. Together, these four
deliverables provide Health Network, Inc. with a comprehensive risk management and
continuity framework.
References