Healthcare
Meridian Health
Passed a HITRUST audit with observability in scope, in one cycle.
-
1 cycle
to audit sign-off
-
100%
PHI redacted at source
-
15 mo
retention in region
“The question was never whether the tool was good. It was whether we could put patient data anywhere near it.”
The constraint
Meridian Health had failed a prior audit because log lines containing patient identifiers were leaving their VPC before redaction. Their observability stack was in scope for HITRUST and could not stay as it was.
What we changed
Redaction moved into the collector, so identifiers never crossed the network boundary in the first place. Data landed in a private region in their own cloud account, with fifteen-month retention to match their record-keeping obligation.
Where it landed
The audit passed in a single cycle with observability fully in scope. Because redaction happens at the source, the control is demonstrable at the collector config rather than argued from vendor policy.