Scenario Brief

Meridian Health Portal

Meridian Regional Health System

Meridian Health Portal is a public-facing web application that lets roughly 180,000 patients of Meridian Regional Health System book appointments, message their care team, view lab results, and pay bills. It is operated by a mid-sized regional hospital network under contract to a state health agency, which makes it subject to both HIPAA and FISMA oversight.

Choose your training scenario

Each scenario runs the same seven-step workflow, control library, POA&M tracker, and documents. Your progress is saved separately for each one.

Legal and regulatory framing

Legal and regulatory framing: HIPAA and FISMA

Meridian Health Portal is operated by a covered entity, so the protected health information it handles falls under the HIPAA Privacy and Security Rules, including the accounting of disclosures and breach notification obligations.

Because the portal is operated under contract to a state health agency, FISMA and the NIST control baselines apply in parallel. Vendors touching protected health information are bound by business associate agreements.

System Facts

System owner
David Eggerton
Meridian Regional Health System, IT Services Division
Authorizing official
Dana Okafor
State Health Agency, Chief Information Officer
Users
180,000 patients, 2,400 clinical staff, 60 administrators
Hosting
Commercial cloud IaaS, single region, two availability zones
Interconnections
Electronic health record, lab results feed, payment processor
Data
Protected health information, payment card data, patient identity records

Information Types Library

Each type carries the provisional confidentiality, integrity, and availability impact levels from NIST SP 800-60. You confirm or adjust them during Categorize.

  • Patient health records (PHI)

    Clinical records released to patients through the portal: problem lists, medications, allergies, visit summaries, imaging reports, and laboratory results, together with the identifiers that bind a record to a person.

    C ModerateI ModerateA Moderate

    NIST SP 800-60 Vol. II, Health Care Delivery Services (D.19.1)

  • Appointment and scheduling data

    Appointment requests, confirmations, cancellations, clinic and provider calendars, and the reminder notifications generated from them.

    C LowI ModerateA Moderate

    NIST SP 800-60 Vol. II, Program Administration (C.3.5.1)

  • Billing and payment card data

    Statements, balances, insurance and coverage identifiers, payment history, and the tokenized card references exchanged with the payment processor.

    C ModerateI ModerateA Low

    NIST SP 800-60 Vol. II, Payments (C.2.4.4)

  • Secure clinician-patient messaging

    Message threads between patients and their care team, including attachments, triage notes, and the read and delivery receipts kept with each thread.

    C ModerateI ModerateA Low

    NIST SP 800-60 Vol. II, Health Care Delivery Services (D.19.1)

  • System audit and access logs

    Authentication events, record view and export events, administrative configuration changes, and the accounting of disclosures derived from them.

    C ModerateI ModerateA Low

    NIST SP 800-60 Vol. II, System and Network Monitoring (C.3.5.8)

Known Conditions and Weaknesses

  • The portal must remain reachable 24/7 for lab result release; a full-day outage triggers state reporting.
  • A recent internal review found shared service accounts and no multifactor authentication for administrators.
  • Backups exist but have never been restore-tested.
  • The payment path is partially outsourced, so some controls will be inherited from the processor.