See It in Practice. Trusted Implementation. Proven Results. Explore a complete example of the Pragmatic GRC Methodology in a real small business.
!
This is a fictional example, not a real client. OFMA and everyone named below are entirely made up, created to show what a completed set of Living Documents and Implementation Guides actually looks like in use. If you’re looking for blank, fillable versions of these documents, visit the Resource Library instead.

Meet OFMA

OFMA is a small general medical practice — starting with two physicians, two physician assistants, a clinical support team, and two administrative staff. Like most small practices, they don’t have a dedicated IT or compliance department. What follows is the real, chronological sequence of how they stood up the Pragmatic GRC Methodology™: writing a charter, building the Living Documents, weathering a real security incident, using the Four Implementation Guides to respond, and growing the team along the way.

The Team
  • Dr. Michael Howards & Dr. Sarah Leatt — Physicians
  • Amanda Cole, PA-C & David Nguyen, PA-C
  • Jackie Smiths, RN
  • Kevin Brooks, LPN
  • Maria Gonzalez & Tyler Simmons, CNAs
  • Linda Foster — Office Manager
  • Jessica Park — Administrative Assistant
  • Sofia Ramirez — Scheduling Coordinator (joined November 2026)
  • Supported by Summit IT Partners (MSP)
13 documents, one continuous story — from the program charter through a real incident to the newest hire’s first day. Every step below links to the actual completed record.
1
The Charter

Why This Exists, and Who’s Accountable

+

Before any inventory was taken or any control was implemented, OFMA wrote down why the program exists and assigned real names to every governance role — not job titles that would go stale, but actual accountability from day one.

2
Navigate

Mapping What They Actually Have

+

Before anything else, OFMA conducted a full technology and vendor discovery — cataloging 26 assets across clinical and administrative operations, from the EHR system down to the shared nursing workstations. Weeks later, a routine governance discussion prompted by a real-world case study surfaced one more overlooked asset: the practice’s own domain name.

3
Fortify & the Security Plan

Locking Down What They Found

+

With a full asset inventory in hand, OFMA built its Unified System Security Plan — documenting MFA enforcement, access controls, backup expectations, and vendor risk across every system they’d just cataloged. This baseline is what got tested a few months later.

4
The Incident

Put to the Test

+

On August 12, 2026, a phishing email compromised one staff member’s email credentials. Here’s the complete incident record — detection, containment, evidence collection, and the documented determination that this was not a reportable HIPAA breach, because MFA blocked the attacker before any patient data was ever touched.

5
The Treatment Plan

When One Line Isn’t Enough

+

Most risks in OFMA’s register resolve with a single owner and a short note. This one didn’t — the incident proved it needed a real, multi-step plan. Here’s the detailed treatment plan that turned “reduce phishing risk” into five concrete actions with owners and dates.

6
Sustain

Recovery, and an Overdue Test

+

The incident closed out cleanly — but it also became the trigger to finally run an overdue annual backup restoration test, closing a risk that had been sitting open since the very first risk assessment. Recovery isn’t just about the incident in front of you; it’s about the gaps it reveals.

7
Cultivate

Building the Habit, Not Just Fixing the Bug

+

The incident’s corrective actions called for something OFMA had never had: real, recurring security awareness training. This is the record of that program’s launch — enrollment, the first bi-weekly phishing micro-quiz, and an honest accounting of what’s still just getting started.

8
Closing the Gaps

Offboarding and a First Vendor Review

+

Two gaps that had been sitting in the risk register since the very beginning finally got addressed: a written offboarding protocol replaced the old “verbal notification” process, and the practice’s most critical vendor — its EHR provider — went through a full, documented risk assessment for the first time.

9
Growing the Team

A New Hire, and the Policies Finally Get Written Down

+

OFMA’s first new hire since the training program launched gave the whole system its first real test — a complete security orientation on day one, closing a gap the Cultivate guide had flagged as still open. Two weeks later, the practice’s four core policies got written down for the first time, in three pages, not thirty.

10
The Monthly Heartbeat

Keeping It Alive

+

None of this works as a one-time project. Here’s OFMA’s actual August 2026 governance review — what changed, what’s still open, and the KPIs that keep leadership honest about where things really stand, every single month.