Cascadia Health Systems — Q4 2024
| Risk ID | Risk Description | Severity | Exposure ($M) | Likelihood | Mitigation Status | Owner |
|---|---|---|---|---|---|---|
| R-2024-087 | Third-party EHR vendor data breach exposure | CRITICAL | $4.2M | High (68%) | In Progress (45%) | VP IT Security |
| R-2024-104 | Ransomware targeting medical imaging systems | HIGH | $3.8M | Medium (42%) | Planned (12%) | CISO |
| R-2024-061 | Insider threat — privileged access abuse | HIGH | $2.9M | Low (18%) | Active (72%) | Dir. Identity Mgmt |
| R-2024-119 | Legacy PACS system end-of-life vulnerability | HIGH | $2.4M | High (61%) | Active (58%) | VP Clinical IT |
| R-2024-092 | Phishing campaign targeting finance dept | MEDIUM | $1.8M | Medium (34%) | Active (81%) | Security Ops Mgr |
| R-2024-073 | Cloud storage misconfiguration — PHI exposure | MEDIUM | $1.5M | Low (22%) | Complete (100%) | Cloud Security Lead |
| R-2024-135 | DDoS attack on patient portal infrastructure | MEDIUM | $1.2M | Medium (38%) | Active (67%) | Network Security |
| R-2024-058 | Mobile device MDM policy non-compliance | LOW | $0.6M | Low (15%) | Active (89%) | Endpoint Security |