TrustDesk
Back to workspace

Meridian Health

On Track

qn-002 · Healthcare

Deal stage
New Logo
Deal value
$1,200,000
Questions
5
Received
May 26, 2026
Due
Jun 30, 2026 (29d)
Encryption & Data Protection · q-006

How is PHI encrypted at rest and how is access to it controlled?

97confidence
Auto-Approved
Drafted response

Sensitive data is encrypted at rest with AES-256, and access follows role-based access control and least privilege with quarterly reviews.

Confidence factors

  • Control Match4/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived4/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language4/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse4/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity3/4weight ×1.0

    How standard and well-bounded the question is.

Routed toAuto-Approved

Why this verdict

  • Strong control match on current, approved evidence with no sensitivity flags — cleared to auto-approve.
Incident Response · q-007

Describe your incident response and breach notification process.

83confidence
Suggested
Drafted response

A documented IR plan defines severity tiers and escalation, tested annually. Customers are notified of confirmed breaches without undue delay per the agreement and regulation.

Confidence factors

  • Control Match4/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived2/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language4/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse3/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity4/4weight ×1.0

    How standard and well-bounded the question is.

Routed toSecurity Enablement

Why this verdict

  • Evidence Freshness is below target (2/4).
Privacy & Data Retention · q-008

What is your data retention and deletion policy upon contract termination?

100confidence
Needs Review
Drafted response

Customer data is retained only as long as necessary; on termination it is deleted or returned within the period defined in the data processing agreement.

Confidence factors

  • Control Match4/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived4/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language4/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse4/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity4/4weight ×1.0

    How standard and well-bounded the question is.

Routed toPrivacy / Data Protection

Why this verdict

  • Capped at Needs Review: Privacy & Data Retention carries legal/privacy exposure and always requires human sign-off, regardless of the 100 confidence score.
Privacy & Data Retention · q-009

Are subprocessors disclosed and bound by data protection agreements?

56confidence
Escalate
Drafted response

A current subprocessor list is maintained and published; subprocessors are bound by data protection agreements and customers are notified of material changes.

Confidence factors

  • Control Match3/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived0/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language3/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse3/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity3/4weight ×1.0

    How standard and well-bounded the question is.

Routed toPrivacy / Data Protection

Why this verdict

  • Escalated: a sensitive Privacy & Data Retention question is grounded in expired evidence — it cannot be answered from the library as-is.
Business Continuity & Resilience · q-010

Is business continuity and disaster recovery tested regularly?

91confidence
Auto-Approved
Drafted response

Yes. BC/DR plans define RTO and RPO targets, are tested at least annually, and rely on geographically redundant infrastructure with validated backups.

Confidence factors

  • Control Match4/4weight ×2.0

    How directly approved controls answer the question.

  • Evidence Freshnessderived4/4weight ×2.0

    Currency of the mapped evidence (derived from review dates).

  • Approved Language3/4weight ×1.5

    Availability of vetted, pre-approved response language.

  • Answer Reuse3/4weight ×1.5

    Consistency with prior approved responses to the same ask.

  • Category Clarity4/4weight ×1.0

    How standard and well-bounded the question is.

Routed toAuto-Approved

Why this verdict

  • Strong control match on current, approved evidence with no sensitivity flags — cleared to auto-approve.