This repository documents a Governance, Risk, and Compliance (GRC) program for a healthcare organization operating the OpenMRS platform.
- System: OpenMRS Electronic Medical Record
- Data: ePHI / PHI
- Frameworks: HIPAA Security Rule, NIST CSF
- Hosting: AWS
- Enterprise risk management
- HIPAA-aligned control design
- Control testing and evidence collection
- Incident response tabletop exercises
- Executive-level risk reporting
This repository contains documentation only. No real patient data, credentials, or production configurations are included.