Course Name: IT Governance and Information System Audit
Answer all the questions based on the case study. Every question bears equal marks]
Radiant Life Hospital Ltd. (RLH) is a leading private healthcare organization in Dhaka, Bangladesh, well known for its
advanced medical services and commitment to digital transformation. Over the past decade, the hospital expanded
rapidly and implemented a range of IT systems to manage patient records, billing, telemedicine services, and supply
chain operations. This technological investment made RLH a pioneer in smart healthcare management. However,
beneath its modern infrastructure lay deep governance and risk management weaknesses that would soon surface in
a crisis. The hospital's IT department was headed by a capable but overburdened CIO who operated with limited
oversight from senior management. There was no IT Steering Committee, nor did the Board of Directors have a
structured mechanism to oversee IT performance, investments, or risks. As a result, IT decisions were made
independently of overall business strategy. Different departments procured their own systems without coordination
which resulted in redundant databases and incompatible platforms. This fragmented approach not only led to
inefficiencies but also created significant security vulnerabilities across the organization. In early 2025, RLH
experienced a major data breach that shook public confidence. Hackers penetrated the hospital's patient
management system and gained access to thousands of confidential medical records. The incident was traced back to
a weak password policy (many staff accounts used default passwords like "12345") and an absence of encryption in
the online appointment portal. To make matters worse, the hospital's Information Security Policy had not been
updated for several years and did not cover new technologies like telemedicine or cloud storage. The attack exposed
the hospital's reactive approach to risk management; there was no formal risk register, no documentation of risk
appetite or tolerance, and no predefined incident response plan. When investigators looked deeper, more issues
surfaced. The hospital had outsourced its data storage and backup services to a local IT vendor without a proper due
diligence process. The contract lacked a Right-to-Audit clause, and the vendor had quietly subcontracted data storage
to another provider located overseas. This arrangement violated national data protection laws and the hospital's own
policies. When the vendor's backup system failed, two weeks of patient records were permanently lost. Patients
complained about missing information, misbilled treatments, and repeated diagnostic procedures, all of which caused
serious reputational damage to RLH. Internally, the governance situation was equally concerning. A review revealed
that the same IT administrator who created user accounts could also approve access requests. The database Page 1
of 3 administrator held full access to both development and production environments. These structural flaws meant
that even when security policies were violated, there were no effective checks or balances in place to detect or prevent
misconduct. Moreover, the IS audit team reported to the CFO rather than the Audit Committee, limiting its
independence and effectiveness. Many earlier audit recommendations, including those related to cybersecurity, had
never been implemented. The hospital's risk management framework was practically nonexistent. Each department
handled its risks independently: Finance monitored billing discrepancies, HR dealt with employee compliance, and IT
addressed system errors, but no one looked at risks across the enterprise. The organization had never defined its risk
appetite or tolerance, and there were no KRIs to provide early warning of emerging threats. Risk assessments were
conducted only after incidents occurred, and management had little understanding of how to prioritize threats based
on impact and probability. When regulators later requested evidence of an ERM system, the hospital could not provide
one. Performance monitoring was also inadequate. The IT department reported its success based on system uptime
and the number of online appointments handled, but these metrics said nothing about IT's contribution to business
objectives or patient satisfaction. There were no KPIs or KCIs linked to governance or compliance outcomes. Nor was
there a Balanced Scorecard to align IT outcomes with patient care goals, operational efficiency, or regulatory
compliance. The Board is now determined to rebuild its IT governance structure, strengthen internal control systems,
and restore public trust. However, the challenge remains: how can Radiant Life Hospital transform its fragmented and
reactive IT environment into a secure, strategically aligned, and accountable governance framework? Required: 1)
Identify and discuss the major weaknesses in RLH's IT governance structure. How can the Board and IT Steering
Committee improve oversight and strategic alignment? 2) Analyze the problems related to the hospital's ISP and
suggest at least two improvements that would enhance its effectiveness and compliance. 3) What key governance
and risk issues arise from the outsourcing of the hospital's data storage? Propose specific contractual or monitoring
measures to address them. 4 ) Evaluate the implications of the SoD violations and lack of a risk register. What steps
should the hospital take to strengthen it risk management practices? 5) Suggest suitable KPIs or performance
evaluation methods that could help RLH measure IT's contribution to business goals. How should the IS audit function
be repositioned to ensure independence and effectiveness?