1 of 6

[SECURITY REQS]�RHN apps connecting to �AMC IT Resources

7/30/26  

Information Assurance

2 of 6

The goal: Protecting patients, workforce members, and the services they depend on.

Security Risk

Protects patient and workforce data from external threats and access vulnerabilities.

Compliance

Ensures consistent adherence to regulatory and institutional requirements.

Consistency

Aligns RHN-managed applications with AMC-standardized risk assessment methods.

Mitigating Shared Institutional Risk

3 of 6

MMIAR Required

MMIAR Not Required

Connects to AMC-hosted systems/databases

Depends on AMC Identity/Access services

Exchanges data with AMC systems

Changes existing connections meaningfully

Used strictly within RHN environments

No AMC connection or dependency

Limited to RHN inventory updates

Does It Need an MMIAR?

Michigan Medicine Information Assurance Request

A security review of all applications and services connecting to – or handling from - Michigan Medicine IT resources, including but not limited to Projects, new technology implementations, cloud software purchases, and major upgrades to existing systems/applications.

4 of 6

Note: TSPs remain responsible for the system of record in RHN ServiceNow for application inventory.

High-Level MMIAR Process Flow

5 of 6

Risk Management will demonstrate the SNOW environment to ensure a smooth transition.

Accessing the portal in AMC ServiceNow

Critical information typically required

Managing follow-ups and questions

Support resources available

SME Demonstration

6 of 6

For additional questions, please email:  

Ask-Cybersecurity@med.umich.edu  

THANK YOU

Information Assurance