Healthcare

Meridian Health

Passed a HITRUST audit with observability in scope, in one cycle.

  • 1 cycle

    to audit sign-off

  • 100%

    PHI redacted at source

  • 15 mo

    retention in region

“The question was never whether the tool was good. It was whether we could put patient data anywhere near it.”

Daniel Osei, VP Infrastructure, Meridian Health

The constraint

Meridian Health had failed a prior audit because log lines containing patient identifiers were leaving their VPC before redaction. Their observability stack was in scope for HITRUST and could not stay as it was.

What we changed

Redaction moved into the collector, so identifiers never crossed the network boundary in the first place. Data landed in a private region in their own cloud account, with fifteen-month retention to match their record-keeping obligation.

Where it landed

The audit passed in a single cycle with observability fully in scope. Because redaction happens at the source, the control is demonstrable at the collector config rather than argued from vendor policy.

Run the same exercise on your own bill.