Scenario Brief
Meridian Health Portal
Meridian Regional Health System
Meridian Health Portal is a public-facing web application that lets roughly 180,000 patients of Meridian Regional Health System book appointments, message their care team, view lab results, and pay bills. It is operated by a mid-sized regional hospital network under contract to a state health agency, which makes it subject to both HIPAA and FISMA oversight.
Choose your training scenario
Each scenario runs the same seven-step workflow, control library, POA&M tracker, and documents. Your progress is saved separately for each one.
Legal and regulatory framing
Legal and regulatory framing: HIPAA and FISMA
Meridian Health Portal is operated by a covered entity, so the protected health information it handles falls under the HIPAA Privacy and Security Rules, including the accounting of disclosures and breach notification obligations.
Because the portal is operated under contract to a state health agency, FISMA and the NIST control baselines apply in parallel. Vendors touching protected health information are bound by business associate agreements.
System Facts
- System owner
- David Eggerton
- Meridian Regional Health System, IT Services Division
- Authorizing official
- Dana Okafor
- State Health Agency, Chief Information Officer
- Users
- 180,000 patients, 2,400 clinical staff, 60 administrators
- Hosting
- Commercial cloud IaaS, single region, two availability zones
- Interconnections
- Electronic health record, lab results feed, payment processor
- Data
- Protected health information, payment card data, patient identity records
Information Types Library
Each type carries the provisional confidentiality, integrity, and availability impact levels from NIST SP 800-60. You confirm or adjust them during Categorize.
Patient health records (PHI)
Clinical records released to patients through the portal: problem lists, medications, allergies, visit summaries, imaging reports, and laboratory results, together with the identifiers that bind a record to a person.
C ModerateI ModerateA Moderate
NIST SP 800-60 Vol. II, Health Care Delivery Services (D.19.1)
Appointment and scheduling data
Appointment requests, confirmations, cancellations, clinic and provider calendars, and the reminder notifications generated from them.
C LowI ModerateA Moderate
NIST SP 800-60 Vol. II, Program Administration (C.3.5.1)
Billing and payment card data
Statements, balances, insurance and coverage identifiers, payment history, and the tokenized card references exchanged with the payment processor.
C ModerateI ModerateA Low
NIST SP 800-60 Vol. II, Payments (C.2.4.4)
Secure clinician-patient messaging
Message threads between patients and their care team, including attachments, triage notes, and the read and delivery receipts kept with each thread.
C ModerateI ModerateA Low
NIST SP 800-60 Vol. II, Health Care Delivery Services (D.19.1)
System audit and access logs
Authentication events, record view and export events, administrative configuration changes, and the accounting of disclosures derived from them.
C ModerateI ModerateA Low
NIST SP 800-60 Vol. II, System and Network Monitoring (C.3.5.8)
Known Conditions and Weaknesses
- The portal must remain reachable 24/7 for lab result release; a full-day outage triggers state reporting.
- A recent internal review found shared service accounts and no multifactor authentication for administrators.
- Backups exist but have never been restore-tested.
- The payment path is partially outsourced, so some controls will be inherited from the processor.