[SECURITY REQS]�RHN apps connecting to �AMC IT Resources
7/30/26
Information Assurance
The goal: Protecting patients, workforce members, and the services they depend on.
Security Risk
Protects patient and workforce data from external threats and access vulnerabilities.
Compliance
Ensures consistent adherence to regulatory and institutional requirements.
Consistency
Aligns RHN-managed applications with AMC-standardized risk assessment methods.
Mitigating Shared Institutional Risk
MMIAR Required
MMIAR Not Required
Connects to AMC-hosted systems/databases
Depends on AMC Identity/Access services
Exchanges data with AMC systems
Changes existing connections meaningfully
Used strictly within RHN environments
No AMC connection or dependency
Limited to RHN inventory updates
Does It Need an MMIAR?
Michigan Medicine Information Assurance Request
A security review of all applications and services connecting to – or handling from - Michigan Medicine IT resources, including but not limited to Projects, new technology implementations, cloud software purchases, and major upgrades to existing systems/applications.
Note: TSPs remain responsible for the system of record in RHN ServiceNow for application inventory.
High-Level MMIAR Process Flow
Risk Management will demonstrate the SNOW environment to ensure a smooth transition.
Accessing the portal in AMC ServiceNow
Critical information typically required
Managing follow-ups and questions
Support resources available
SME Demonstration
THANK YOU
Information Assurance