Corpus Intelligence Cyber Risk 2026-04-26 00:40 UTC
Cyber Risk
🛡️ Public data only — no PHI permitted on this instance.

Cybersecurity / HIPAA Risk Scorecard

12-domain control maturity · incident history · ransomware preparedness · threat vectors · compliance frameworks · 3P vendor risk — 1,705 corpus deals

Cyber Score
72/100
Risk Tier
ADEQUATE
Records in Scope
2,850,000
Insurance
$50M
Annual Spend
$8.5M
Control Domains
12
Vendors at Risk
1
Corpus Deals
1,705
Cyber Posture
Score 72/100 · Tier ADEQUATE · 2,850,000 PHI records in scope
$50M insurance tower · $8.5M annual spend · 3 HHS-reportable incidents LTM
Control Domain Maturity vs Industry Benchmark
DomainMaturityBenchmarkGapNIST TierLast AuditFindings
Identity & Access Management7275-3Tier 3 (Repeatable)2024-11-154
Endpoint Security (EDR/XDR)8582+3Tier 4 (Adaptive)2024-12-082
Network Segmentation6872-4Tier 3 (Repeatable)2024-10-226
Vulnerability Management7878+0Tier 3 (Repeatable)2025-01-153
Data Protection / Encryption8280+2Tier 3 (Repeatable)2024-11-302
Security Operations / SIEM6572-7Tier 2 (Risk-Informed)2024-09-188
Incident Response7070+0Tier 3 (Repeatable)2024-10-015
Business Continuity / DR6268-6Tier 2 (Risk-Informed)2024-08-157
Third-Party Risk Management5865-7Tier 2 (Risk-Informed)2024-07-2012
Security Awareness Training7875+3Tier 3 (Repeatable)2024-12-013
Governance / Risk / Compliance7572+3Tier 3 (Repeatable)2024-11-084
Cloud Security Posture7270+2Tier 3 (Repeatable)2024-10-305
Incident History (LTM)
DateIncident TypeScopeRecordsHHS ReportableCost ($M)Status
2024-02-21Phishing (credential harvesting)Single department485NO$0.120closed — no notification
2024-06-10Lost unencrypted device1 employee laptop2,850YES$0.385notifications complete
2024-09-22Vendor breach (exposed portal)EHR vendor Y outage12,500YES$1.250notifications complete + OCR response
2024-11-08Ransomware attempt (blocked by EDR)Zero successful encryption0NO$0.085closed — no impact
2025-01-22Insider improper accessSingle physician285YES$0.045HHS notification; employee terminated
2025-03-08Business email compromiseFinance phishing attempt0NO$0.220closed — no funds lost
Ransomware Preparedness
CapabilityMaturityRTO (hr)RPO (hr)Last TabletopGap
Immutable Backups (WORM)strong842025-01-15well-implemented
Offline Backup Validationstrong842025-01-15quarterly tests passing
Network Segmentation (EHR/Corp)moderate1262024-10-22IoT/medical device VLAN incomplete
EDR on All Endpointsstrong10continuous100% coverage
Email Security (Phishing Defense)strong00continuousProofpoint + Abnormal
MFA on All Privileged Accessmoderate002024-12-0885% coverage, service accts remaining
Ransomware Tabletop Exercisemoderate002024-10-01annually — increase to semi-annual
Cyber Insurance (Ransomware Cov)strong002025-01-01$50M aggregate — renewal Q1 2026
Legal / FBI Notification Playbookstrong202024-11-15retainer active
Crypto Payment Preparednessstrong00n/a (no-pay policy)cold-wallet partner
Threat Vector Exposure
Threat VectorProbabilityFinancial Impact ($M)Industry IncidenceMitigation
Ransomware (Sector-Wide)high$18.5032.0%active defense
Third-Party Vendor Breachhigh$12.5042.0%enhanced TPRM 2025
Phishing / Credential Theftvery high$2.8068.0%continuous training + email sec
Insider Threat (Malicious)medium$4.508.0%UEBA monitoring
Supply Chain Attackmedium$8.5012.0%SBOM review + vendor SOC 2
Medical Device Exploitationmedium$5.2015.0%network segmentation
Nation-State APTlow$35.002.0%MDR / 24x7 SOC
DDoS (Operational)medium$1.2018.0%Cloudflare mitigation
Compliance Framework Coverage
FrameworkScopeStatusCoverageLast AssessmentRemediation ($M)
HIPAA Security RuleAll PHIcompliant92%2024-11-15$0.18
HIPAA Privacy RuleAll PHIcompliant95%2024-11-15$0.08
HIPAA Breach NotificationAll systemscompliant100%2024-11-15$0.00
HITRUST CSF CertificationCore platformr2 certified 202488%2024-08-30$0.45
SOC 2 Type IICustomer-facing platformspassed 2024100%2024-10-20$0.32
PCI-DSS (Payment)Payment channelscompliant98%2024-09-15$0.08
ISO 27001Core platformcertified 202392%2023-12-15$0.28
NIST 800-66r2 (HIPAA)All systemsaligned85%2024-11-15$0.22
HHS 405(d) HICPClinical systemsaligned78%2024-08-30$0.35
CMMC 2.0 (federal)N/A (no federal contracts)not applicable0%N/A$0.00
Third-Party / Vendor Exposure
Third PartyAccess ScopeBAASOC 2 StatusLast ReviewRisk Score
Epic EHR (hosted)All PHIBAA currentSOC 2 Type II current2024-10-1522
Waystar (RCM)Claims dataBAA currentSOC 2 Type II current2024-09-2228
Microsoft AzureInfrastructureBAA currentSOC 2 Type II current2024-11-0818
Salesforce Health CloudPatient CRMBAA currentSOC 2 Type II current2024-08-2032
Zoom HealthcareTelehealth videoBAA currentSOC 2 Type II current2024-10-0225
Vendor X (RCM BPO offshore)Claims processingBAA currentSOC 2 Type I only2024-06-1862
Regional Lab NetworkTest resultsBAA currentSOC 2 Type II current2024-07-3042
Nuance / DAX CopilotClinical documentationBAA currentSOC 2 Type II current2024-11-1528
Twilio / SMSPatient commsBAA currentSOC 2 Type II current2024-10-2235
Abnormal Security (email)Email metadataBAA not requiredSOC 2 Type II current2024-09-1022
Cyber Risk Thesis: Overall score 72/100 (tier: adequate). Strong controls on endpoint, data protection, and training; underinvested in SOC/SIEM, BCP/DR, and third-party risk management. Ransomware readiness is strong — immutable backups, EDR everywhere, $50M cyber tower. Post-Change Healthcare (Feb 2024), the sector-wide ransomware impact benchmark is $22B — platform exposure proportional to PHI footprint and vendor density. Most material third-party risk: offshore RCM BPO (SOC 2 Type I only — upgrade required) and Salesforce Health Cloud (high-access PHI scope). Compliance posture solid — HIPAA, HITRUST r2, SOC 2 Type II, PCI-DSS, ISO 27001 all current. Remediation budget required $1.96M to close gaps over next 6-9 months.