DCH is implementing a comprehensive risk analysis framework utilizing the ServiceNow GRC module. This framework will systematically assess risks across all relevant systems and evaluate the effectiveness of existing controls in mitigating identified risks.
While DCH has historically obtained and le...
DCH is implementing a comprehensive risk analysis framework utilizing the ServiceNow GRC module. This framework will systematically assess risks across all relevant systems and evaluate the effectiveness of existing controls in mitigating identified risks.
While DCH has historically obtained and leveraged independent security assessments—including SOC Type II reports, Security Assessment Reports, and HITRUST validations—to inform its security posture, we recognize the need for enhanced documentation and a formalized assessment process. To address this finding, DCH has taken the following corrective actions:
• Standardized Documentation Procedures: Implemented a formalized process to document the receipt, review, and analysis of SOC Type II reports, Complementary User Entity Controls (CUECs), and other relevant security assessments.
• Automated Assessment Framework: Leveraging the ServiceNow GRC module to establish a structured, repeatable process for evaluating the effectiveness of implemented controls and their role in mitigating identified risks.
• Training & Process Integration: Conducted staff training on the importance of documentation and the new assessment framework to ensure consistent execution and compliance.
We remain committed to strengthening our security posture and refining our processes to enhance compliance and risk management.
While the SSP approval occurred outside the audit period, DCH has since ensured that approved SSPs for critical Medicaid systems—including Georgia Medicaid Management Information System (GAMMIS), Gateway, and the Enterprise Analytics Solution for Everyone (EASE) are in place.
DCH has already begun implementing these corrective actions and anticipates full implementation by April 30, 2025