orrective Action Plan Name of Contact Person Responsible for Corrective Action: John Hunt Centra Health Corporate Director, Information Security and Disaster Recovery 561-613-7342 john.hunt@centrahealth.com Anticipated Completion date: December 31, 2025 Corrective Action: 2024-001 – Special tests and provisions: As part of our ongoing GLBA compliance efforts, we completed a comprehensive risk assessment on December 24th, 2024. The assessment identified and ranked risks based on likelihood and potential impact to sensitive financial and customer information. In alignment with GLBA’s requirement to safeguard non-public personal information, our program has prioritized remediation and monitoring efforts toward the highest-risk control items identified. Key focus areas include: • Implementing multi-factor authentication for all privileged access, including access to sensitive back-end IT equipment and web application access. • Implementing a vulnerability management program that includes a regular scan of all systems on the network and a programmatic review of the resulting list of vulnerabilities to ensure that systems are reconfigured and patched to address risk to the organization in order of criticality. • Developing a comprehensive Incident Response Plan that is tested and reviewed at least annually or whenever significant changes to procedures are introduced. • Updating Centra’s third-party risk management procedures to include periodic review of supplier performance, appropriateness of information security and data protection controls, and compliance with required controls. • Improving security awareness training with specialized training for specific higher risk roles to the organization. We continue to make progress on 314.4(d)–(g) controls: safeguards have been designed and implemented for high-risk areas, and ongoing testing, training, vendor oversight, and program evaluation are being conducted. Some lower-priority improvements remain in progress, consistent with our risk-based approach and remediation roadmap. These initiatives are tracked, resourced, and scheduled, ensuring that residual gaps are closed in alignment with GLBA requirements.