Meridian Health Partners · Data Governance Knowledge Graph

One graph. Three beats.
From 53 findings to a decision.

A HIPAA Security Rule gap analysis run live against the governance graph: 199 nodes covering assets, lineage, controls, regulations, stewards, and reports. Synthetic environment; real method.

The sweep: completeness first

One query, no scoping assumptions: every PHI or PII asset with no control tracing to the HIPAA Security Rule. This is the honest number, and it is unusable on its own.

0
open findings across systems
The query cannot tell exposure from paperwork. Somewhere in this wall is a CRM with no encryption at all, sitting beside sixty rows of documentation debt. Narrowing the query would hide the difference; the next beat scores it instead.

The triage: same findings, scored

Every finding is scored on classification (PHI 3, PII 2), gap type (control absent 2, status unknown 1, unmapped 0), and regulatory exposure through lineage (regulatory report downstream 2, any report 1). Nothing is dropped; risk acceptances are tracked with expiry.

TierAssetClassSystemGap typeReports exposedStatus

The decision: what the CDO actually acts on

Active risk acceptances suppressed, findings grouped by tier and gap type. Three numbers, three owners, three different actions.

The graph itself

All 199 nodes and 440 relationships, force-directed. Hover to identify a node and light up its neighborhood; drag nodes to untangle. The dense cluster is the asset layer; the satellites around it are the governance overlay attached to it.

Ask the graph

Plain-English questions answered by Claude over a retrieved subgraph: keyword match seeds the relevant nodes, a two-hop expansion pulls their neighborhood, and the model answers only from what was retrieved, plus the computed triage worksheets.

This file is running outside Claude.ai, so the built-in model access isn't available. Paste an Anthropic API key (console.anthropic.com) to enable local mode. The key is held in this page's memory only: it is never saved to the file, to storage, or sent anywhere except api.anthropic.com. Use your own key on your own machine only.

local mode: direct API access enabled