I judge GRC maturity by what works - not what’s written down. Start with named risk owners, control-test records, and recovery results. On this assessment’s 1–5 scale, policies alone cannot justify a score above 2.
I use this self-assessment to check whether your program protects patient data, keeps care available, and turns risk reports into decisions:
- Ownership and governance: Who can fund fixes, accept risk, and resolve overdue actions?
- Risk and controls: Are inventories accurate, supplier risks assessed, and safeguards tested?
- Recovery: Can clinical systems and downtime workflows meet approved recovery goals?
- Scoring and priorities: What works, what remains unknown, and which fixes reduce patient-care risk most?
I track the percentage of criteria supported by current records alongside scores, then assign each priority an owner, deadline, and success measure. A strong average should never hide a weak critical service. <u>The goal is less risk - not more paperwork.</u>
Conducting Gap Analysis and maturity assessment. A Practical Guide
sbb-itb-535baee
Define Maturity Through Healthcare Risk Outcomes
Use the same evidence-first standard for every GRC practice that follows. Treat NIST CSF 2.0 as a shared risk-management language - not a compliance checklist or certification. Score current and target capabilities based on how they affect ePHI confidentiality and integrity, clinical availability, patient safety, healthcare supply chain security challenges, and incident recovery. For each practice, identify the affected service, asset, or workflow; describe the failure scenario; and show evidence that residual risk remains within approved tolerance.[4][7]
Map Assessment Areas to NIST CSF 2.0
Organize the self-assessment around NIST CSF 2.0 and healthcare risk outcomes you can observe.
- Govern: accountability, risk tolerance, executive oversight, funding, and time-bound risk exceptions.
- Identify: ePHI repositories, clinical systems, medical devices, suppliers, and dependencies.
- Protect: access control, multifactor authentication (MFA), encryption, and workforce training.
- Detect: monitoring of critical assets and alert investigation.
- Respond: containment, clinical continuity, communications, and supplier escalation.
- Recover: restoration of prioritized services to approved recovery objectives.
These Functions run at the same time and continue over time. They are not six stages you complete once.[4][7]
Use the voluntary HHS Healthcare and Public Health Cybersecurity Performance Goals to set healthcare-specific priorities and evidence requirements. Essential goals establish basic safeguards, while Enhanced goals add more advanced protections. Map each applicable goal to an owner, evidence source, affected clinical service, and residual risk.[5][6]
Define 5 Maturity Levels
This article’s scale rates individual GRC practices. It is not the NIST CSF Implementation Tier model, which has four Tiers: Partial, Risk Informed, Repeatable, and Adaptive.[4][7] Assign the highest level backed by repeatable evidence across the assessed scope - not a single successful test. Written artifacts alone do not justify a score above 2.
| Level | What it means | Evidence needed |
|---|---|---|
| 1 - Initial | Work is reactive and fragmented, starting after incidents, audits, or urgent findings. | Unclear ownership, incomplete inventories and assessments, and little documentation of clinical impact. |
| 2 - Documented | Policies and roles are written, but execution varies and evidence is incomplete. | Policies, procedures, and assigned roles without reliable execution records. |
| 3 - Implemented | Teams use processes consistently across relevant business and clinical areas. | Scheduled risk assessments, control reviews, exception handling, supplier reviews, and incident exercises. |
| 4 - Measured | Leaders track effectiveness, residual risk, remediation aging, and recovery performance. | Metrics for assessment completion, control failures, detection and response times, and supplier exposure; results guide priorities and funding. |
| 5 - Adaptive | Controls and decisions change in response to incidents, near misses, threat intelligence, and operational change. | Documented improvements after technology changes, mergers, new care models, or clinical workflow changes, validated through testing. |
Use these levels to score governance, risk, controls, evidence, and executive decision-making in the sections that follow.
Assess Governance and Executive Decisions
Once ownership is clear, check whether leaders make decisions - and document them.
Score governance and executive decision-making separately. For each criterion, record the score, evidence, owner, clinical or operational impact, and next improvement. Sample recent records covering a clinical system, a third party, and an ePHI or privacy issue.
Check Risk Ownership, Tolerance, and Exceptions
Look for a named executive risk owner with decision authority across cybersecurity, third-party, application, medical-device, privacy, compliance, and resilience risks. Review the charter, risk register, and approval records to confirm who can fund treatment, accept residual risk, and escalate unresolved issues. Cross-functional reviews should involve security, privacy, compliance, IT, biomedical engineering, clinical operations, vendor management, and business leaders. Every decision shouldn't fall to the CISO.[4][8]
Compare approved risk tolerances and escalation thresholds with what leaders actually did. When a risk exceeded tolerance, did it trigger funding, a compensating control, a remediation deadline, or a continuity action?
Sample risk-register entries for the risk statement, affected asset or service, patient-care impact, accountable owner, target date, and approval to accept residual risk. Review exceptions for business justification, compensating controls, approval authority, expiration dates, and renewal records. Risk management must still address ePHI confidentiality, integrity, and availability.[9][2]
Check Whether Reports Lead to Decisions
After identifying the decision owner, check whether executive reports lead to timely action. Review reports alongside meeting minutes, funding approvals, and action logs. A decision report names the affected service, consequence, owner, options, recommendation, decision authority, and deadline.
Use this table to distinguish reports that track activity from reports that support decisions.
| Activity report | Decision report |
|---|---|
| Number of assessments completed | Overdue high-risk findings affecting clinical services, with required actions and accountable owners |
| Number of vulnerabilities identified | Funding and resource requests tied to remediation deadlines and patient-care impact |
| Minutes stating that a risk was reviewed | Approved treatment or signed residual-risk acceptance, with review and expiration dates |
| Overall compliance rate | Failed controls, affected services, and the executive decision needed to reduce exposure |
Minutes alone aren't decision evidence. Track the percentage of high-risk findings that receive a documented decision within the required timeframe, along with overdue actions and expired exceptions. Then confirm that actions were completed and exposure declined. Score reporting separately when metrics are strong but exception handling is weak. This assessment helps establish real-time portfolio risk management across the enterprise.
Assess Risk Identification, Controls, and Compliance Evidence
Once governance and decision rights are clear, check the accuracy of the inventories, controls, and evidence behind those decisions.
Score risk identification, control effectiveness, and compliance evidence separately for internal systems and vendor dependencies.
Check Inventories and Risk Assessment Consistency
Start with the data model behind the risk program. Within a defined scope, such as the EHR environment, review inventories of applications, medical devices, patient data, cloud services, and critical dependencies.
Apply the same scope and risk criteria across assessments. Check that supplier tiers reflect both data access and clinical criticality. Compare inventory records with operational data to find missing assets. Asset management and supply chain risk management remain common weak spots.[10]
Test Controls and Review Evidence
For each sampled control, verify its owner, linked risks, applicable obligations, and testing frequency. Follow vulnerabilities through prioritization, remediation, and verification. Weigh clinical impact alongside technical severity.
Review what incident exercises and recovery tests achieved - not just whether they happened on schedule. Evidence should show who performed the control, when, the result, and how exceptions were resolved.
Use this table to distinguish controls that exist on paper from those that work in practice.
| Checkpoint | What to verify |
|---|---|
| Written policy | Requirements are documented, but implementation has not been verified. |
| Implementation | Controls are in place, but execution may still be ad hoc. |
| Consistent execution | Controls are performed regularly across all systems. |
| Reviewable evidence | Evidence shows who performed the control, when it was done, and the result. |
| Measured performance | Performance is tracked, exceptions are resolved, and processes are improved. |
Centralize Workflows and Keep Human Review
Require reassessments at least annually and after incidents, major control failures, new integrations, or vendor changes. Assign one owner to each update.
Use centralized workflows to support shared ownership, benchmarking, and executive visibility.[1] Keep human approval for decisions that affect risk, patient safety, or clinical operations.
Score Maturity and Prioritize Improvements
Healthcare GRC Maturity: From Scores to Action
Turn the findings from each domain into a baseline score and a funded remediation plan.
Calculate Scores and Rate Confidence
Score each criterion from 1 to 5. Scores above Level 2 need evidence that the practice works and is performed - not just written down. Average the scores within each domain, then calculate the overall average. Report the lowest-scoring critical domain, too. This baseline is a starting point, not an industry benchmark or universal ranking.[4][7]
Keep current scores, targets, and gaps separate. Set targets based on risk tolerance and clinical context. Record evidence coverage: the percentage of assessed criteria supported by sufficient current evidence. Mark missing evidence as unknown, not failure, and keep unscored criteria visible in the report.
Rate confidence as high when evidence is current, representative, and independently reviewed; medium when coverage is partial; and low when judgments rely on interviews or policies.
Rank Gaps by Risk Reduction and Effort
Use scores and confidence levels to decide what to fix first. Build the priority matrix around expected risk reduction and effort.
Assess risk reduction based on patient safety, care continuity, PHI sensitivity, exploitability, dependencies, regulatory exposure, control weakness, and evidence quality.
- High reduction, low effort: Do this work first.
- High reduction, high effort: Plan and fund it as a long-term priority.
- Low reduction, low effort: Handle it through routine work.
- Low reduction, high effort: Question whether the work justifies the cost.
Give each action an owner, deadline, interim safeguards, residual-risk estimate, and success metric.
Use measurable completion criteria, such as tested restoration of tier-one applications or fully governed high-risk exceptions.
These are targets - not claims that results have already been achieved. Do not defer serious clinical risks solely because remediation is expensive. Escalate the investment and residual risk for an explicit executive decision.
Conclusion: Repeat the Assessment and Track Progress
After setting the baseline, repeat the assessment on a fixed schedule. Reassess annually and review critical domains quarterly. Reassess sooner after major incidents, acquisitions, EHR or cloud changes, device deployments, regulatory changes, or threat shifts.
Follow the same sequence each time: clarify ownership and decision rights, standardize terminology, maintain inventories, test controls, measure residual risk, and present executive choices in clinical, operational, financial, and regulatory terms.
Track progress through higher scores, stronger confidence, lower residual risk, completed control tests, and documented executive decisions - not software adoption, policy volume, or assessment counts.[4]
FAQs
How can I validate GRC scores across departments?
Build a cross-functional governance team with representatives from compliance, legal, IT, clinical operations, and executive leadership. Use one risk taxonomy and one prioritized inventory so every department scores assets and vendors consistently based on their impact on patient care and exposure of protected health information (PHI).
Meet regularly to review metrics and address new risks. At quarterly governance meetings, compare departmental risk scorecards and framework coverage to keep cybersecurity priorities aligned with the organization’s goals.
What evidence should I request from critical vendors?
Request completed assessment questionnaires and check independent sources, such as breach feeds or attack-surface monitoring [1]. Review controls using evidence, which may include vendor attestations backed by reviews, signed contract amendments, and documented security requirements [1][2].
Keep an accurate vendor inventory that maps each supplier’s data access and ePHI exposure [2][3]. Maintain a time-stamped audit trail of all collected evidence to show that risk management follows a consistent process and continues over time [4][3].
How do I justify GRC funding to executives?
Connect technical security needs to business outcomes and patient safety. Position governance, risk, and compliance (GRC) as a way to help the organization withstand disruptions and protect patients. Explain the potential costs of noncompliance and data breaches, along with how adopting a framework can help slow increases in cybersecurity insurance premiums.
Use a one-page monthly dashboard to show risk trends, clinical impact, and progress on fixing issues. Highlight how GRC can reduce audit burdens, cut manual work, and support better-informed decisions.