
HOM provides revenue cycle management (RCM) services to its healthcare customers. To know more, visit https://www.homrcm.com/
It engaged Coral eSecure to establish a structured cybersecurity governance program and assist in achieving SOC 2 Type 2 attestation.
Phase 1 – Scope and Business Understanding: Here we defined the SOC 2 scope by understanding HOM’s services, customers, technology, locations, people and applicable Trust Services Criteria (TSC). A well-defined scope helps all parties of the engagement for the next set of implementation milestones.
Phase 2 – Gap Analysis and Risk Assessment – In this phase, we reviewed the existing controls across teams, identified SOC 2 gaps and assessed security risks. The resulting gaps and risks formed the basis of the risk register and remediation plan.
Phase 3 – Control Design, Training, Documentation & Implementation: In this phase, we supported teams with employee awareness and discussed each newly drafted policy. This is an important milestone, as the overall program's success depends on the accountability of controls. In addition, all identified risks were tracked towards a logical closure.
Phase 4 – Control Measurement
Herein, we tested the implemented controls to verify their effectiveness. We gave them a scoring report.
Phase 5 – Internal Audit & Management Review
An independent auditor then conducted an internal audit through interviews, documentation review, scenario-based challenges and evidence verification.
Phase 6 – Independent CPA Examination Support
Finally, we were there with HOM to support their external audits by providing the evidence needed to make the final judgments.
The Outcome
With this, HOM established a structured governance program with clear responsibilities, documented controls, risk management, evidence of control performance, and ongoing monitoring. In addition, they had an annual SOC 2 plan to look ahead.
For Coral, the real change was to significantly reduce cybersecurity risks. We hope that, with the governance framework in place, the likelihood of a cybersecurity incident will be significantly reduced in the future.
© 2026 www.coralesecure.com. All rights reserved | Privacy Policy