Meet OFMA
OFMA is a small general medical practice — starting with two physicians, two physician assistants, a clinical support team, and two administrative staff. Like most small practices, they don’t have a dedicated IT or compliance department. What follows is the real, chronological sequence of how they stood up the Pragmatic GRC Methodology™: writing a charter, building the Living Documents, weathering a real security incident, using the Four Implementation Guides to respond, and growing the team along the way.
- Dr. Michael Howards & Dr. Sarah Leatt — Physicians
- Amanda Cole, PA-C & David Nguyen, PA-C
- Jackie Smiths, RN
- Kevin Brooks, LPN
- Maria Gonzalez & Tyler Simmons, CNAs
- Linda Foster — Office Manager
- Jessica Park — Administrative Assistant
- Sofia Ramirez — Scheduling Coordinator (joined November 2026)
- Supported by Summit IT Partners (MSP)
The Charter
Why This Exists, and Who’s Accountable
Why This Exists, and Who’s Accountable
Before any inventory was taken or any control was implemented, OFMA wrote down why the program exists and assigned real names to every governance role — not job titles that would go stale, but actual accountability from day one.
Navigate
Mapping What They Actually Have
Mapping What They Actually Have
Before anything else, OFMA conducted a full technology and vendor discovery — cataloging 26 assets across clinical and administrative operations, from the EHR system down to the shared nursing workstations. Weeks later, a routine governance discussion prompted by a real-world case study surfaced one more overlooked asset: the practice’s own domain name.
Fortify & the Security Plan
Locking Down What They Found
Locking Down What They Found
With a full asset inventory in hand, OFMA built its Unified System Security Plan — documenting MFA enforcement, access controls, backup expectations, and vendor risk across every system they’d just cataloged. This baseline is what got tested a few months later.
The Incident
Put to the Test
Put to the Test
On August 12, 2026, a phishing email compromised one staff member’s email credentials. Here’s the complete incident record — detection, containment, evidence collection, and the documented determination that this was not a reportable HIPAA breach, because MFA blocked the attacker before any patient data was ever touched.
The Treatment Plan
When One Line Isn’t Enough
When One Line Isn’t Enough
Most risks in OFMA’s register resolve with a single owner and a short note. This one didn’t — the incident proved it needed a real, multi-step plan. Here’s the detailed treatment plan that turned “reduce phishing risk” into five concrete actions with owners and dates.
Sustain
Recovery, and an Overdue Test
Recovery, and an Overdue Test
The incident closed out cleanly — but it also became the trigger to finally run an overdue annual backup restoration test, closing a risk that had been sitting open since the very first risk assessment. Recovery isn’t just about the incident in front of you; it’s about the gaps it reveals.
Cultivate
Building the Habit, Not Just Fixing the Bug
Building the Habit, Not Just Fixing the Bug
The incident’s corrective actions called for something OFMA had never had: real, recurring security awareness training. This is the record of that program’s launch — enrollment, the first bi-weekly phishing micro-quiz, and an honest accounting of what’s still just getting started.
Closing the Gaps
Offboarding and a First Vendor Review
Offboarding and a First Vendor Review
Two gaps that had been sitting in the risk register since the very beginning finally got addressed: a written offboarding protocol replaced the old “verbal notification” process, and the practice’s most critical vendor — its EHR provider — went through a full, documented risk assessment for the first time.
Growing the Team
A New Hire, and the Policies Finally Get Written Down
A New Hire, and the Policies Finally Get Written Down
OFMA’s first new hire since the training program launched gave the whole system its first real test — a complete security orientation on day one, closing a gap the Cultivate guide had flagged as still open. Two weeks later, the practice’s four core policies got written down for the first time, in three pages, not thirty.
The Monthly Heartbeat
Keeping It Alive
Keeping It Alive
None of this works as a one-time project. Here’s OFMA’s actual August 2026 governance review — what changed, what’s still open, and the KPIs that keep leadership honest about where things really stand, every single month.