Select Page

Clearwater on ISMG: Practice the Art of Diligence

In a recent conversation with ISMG’s Tom Field, SVP of Editorial, Clearwater’s Chief Risk Officer, and SVP of Consulting and Customer Success, Jon Moore shared some guidance around practicing due diligence while onboarding new partners and during M&A activities.

Field asked Moore why there is such an awakening around due diligence right now; Moore explained that there’s a rise in mergers, acquisitions, and joint ventures as healthcare entities work to deliver higher levels of care in more sustainable models. At the same time, healthcare cyberattacks have topped the list of most expensive breaches, tipping over the $10 million mark as the average cost of a breach. Finally, there’s growing concern over third-party risk, further driving the need for due diligence in the partnership process.

Field and Moore discussed what happens when organizations practice good cyber risk management during onboarding only to relax these efforts later. Moore warned that as the success of a new venture gains traction, risks grow simultaneously-something healthcare leaders should pay close attention to, ensuring good cyber risk management practices stay in place.

Field and Moore also covered topics like key red flags and how to ensure that security concerns don’t detail a partnership. Watch the interview in its entirety here.

Jon Moore on ISMG

Need help with due diligence?

Let’s connect

The HITRUST r2 framework is designed to be comprehensive, and this scoping factor is a perfect example of that design philosophy. It forces you to think beyond firewalls and IAM policies and consider the full environment in which your systems operate. For organizations in leased commercial office space, that environment includes a landlord, a property management company, a cleaning crew, a fire marshal, a building security team, and a building full of mechanical systems you don’t control.

The question isn’t whether you can justify answering “No.” The question is whether your control environment genuinely supports that answer and whether you can prove it to an assessor who’s going to walk your halls, try your door handles, peek into your wiring closets, and ask you who else has a key.

Get this scoping factor right, and you build a foundation of credibility that carries through the rest of your assessment. Get it wrong, and you spend the rest of the engagement explaining why your scoping doesn’t match reality.

Start with the building. The rest follows from there.

SME Highlight

Steve Meyer, CCSFP, CHQP

Steve Meyer is the Senior Director of Consulting Services at Clearwater, bringing over 37 years of experience across various aspects of Information Technology to Clearwater customers. Steve leads the HITRUST Assessment Services team.

Read More

Cyber Briefings for Healthcare Organizations

Stay informed on the latest healthcare cybersecurity, privacy, and compliance threats. Join Clearwater Cyber Briefings each month for expert insights and actionable risk intelligence.

Register Today to Stay Informed

Related Blogs

No results found.