Rimidi

A small team needs support to manage multi-framework compliance

Several years ago when Jennifer Ide, Chief Legal and Financial Officer at Rimidi, began seeking HITRUST certification, her goals were to meet client demand, improve the company’s security posture, protect clients’ patient data, and ensure compliance. 

At first, the Rimidi team attempted to collect evidence for the framework independently, but found they needed outside support. Jennifer, along with Devin Blanchard, Cyber Security Analyst at Rimidi, worked with a consultant who helped them achieve HITRUST certification—but it was a slow, manual process. 

In the meantime, many of Rimidi’s clients were also requesting SOC 2 attestation. Pursuing an additional framework with their consultant would mean starting the process over with a different department. Jennifer and Devin knew that managing two frameworks separately would be impossible with their small team.

They needed a solution to help them both streamline the SOC 2 process and maintain their HITRUST certification. They were looking for a time-saving, easy-to-use platform with a team of experts that could handle multiple frameworks.

Rimidi chooses Thoropass to help them tackle SOC 2 and maintain HITRUST

Jennifer and Devin found the right combination of software and support in Thoropass. They were impressed by the intuitive user interface, platform integrations, and the knowledgeable team to help them every step of the way. Plus, they were thrilled to learn they could accomplish both frameworks without unnecessary duplicative work.

Implementation was easy, and Devin was using the Thoropass platform within weeks. He was a one-man cybersecurity team, but with their dedicated Customer Success Manager (CSM), he felt he essentially gained a coworker.

Devin explained, “our CSM was super communicative and stayed on top of everything. She made it very easy to understand everything we needed, and nothing fell through the cracks.”

Devin immediately noticed how Thoropass’ platform simplified the evidence collection process for both HITRUST and SOC 2, making it possible to manage both frameworks and avoid duplicating efforts. 

Integrations were also important to the Rimidi team. Instead of manually pulling reports, the team used the Thoropass platform to automatically collect evidence from AWS and ADP. The platform then automatically uploaded data to myCSF, HITRUST’s platform, eliminating the need to copy and paste.

Speaking to the importance of these integrations, Jennifer explained “the AWS and ADP integrations saved time and cut down on potential mistakes.”

When it came time for their audits, Jennifer and Devin were impressed by the auditors’ communication. Despite having two auditors for two separate frameworks, they had one clear view into their overall progress for both. The Rimidi team completed their HITRUST renewal much more easily than their previous experience, and successfully passed their first SOC 2 Type 1 audit.

“The auditors told us everything that we needed to know. None of the evidence was left up to interpretation. I knew exactly what to pull, how to pull it, and what the frameworks required. They communicated well and we were able to do everything within our timeline,” explained Devin.

New clients and increased stakeholder confidence

With SOC 2 and HITRUST, Rimidi has closed new deals, simplified their security questionnaire process, and shortened their sales cycle.

Moreover, they now have stronger security policies and procedures in place and increased visibility for internal and external stakeholders.

Speaking to this, Jennifer stated “we grow as a company every time we go through this process. There were things that Thoropass helped us discover during HITRUST and SOC 2 that made us more secure as a company. It gives our leadership team and our board increased confidence that we’re doing all the right things to avoid an incident.”

Compliance is more than audits

With the time saved streamlining their audits, the Rimidi team is able to focus on more strategic tasks.

Jennifer’s advice to other companies: Find a compliance partner that delivers value.

“It’s definitely worth the money. Compliance is not cheap, but we’ve been able to get these two certifications and keep up with our customer needs with a one-man compliance team. There’s no way we would have been able to do that without Thoropass,” explained Jennifer.

Product

HITRUST, SOC 2

Industry

HealthTech

Company size

11-50

Location

Atlanta