Skip to content

Repository files navigation

OmniCare AI GRC Intelligence Platform

Enterprise Healthcare Compliance • ServiceNow • AI • FastAPI • Streamlit • Power BI

Power BI ServiceNow FastAPI Python Gemini AI HIPAA NIST 800-53 SOC 2


Enterprise AI-Powered Healthcare Governance, Risk & Compliance Platform

OmniCare AI GRC Intelligence Platform is an enterprise-style cybersecurity Governance, Risk, and Compliance (GRC) platform designed for a fictional cloud-native healthcare organization.

The platform demonstrates how ServiceNow, FastAPI, Gemini AI, Power BI, Streamlit, and Python can be integrated to transform technical security telemetry into continuous compliance monitoring, AI-assisted regulatory analysis, executive reporting, and audit readiness.

Unlike traditional GRC demonstrations focused on static spreadsheets or isolated dashboards, this platform simulates an end-to-end healthcare compliance ecosystem—from Windows endpoint telemetry and regulatory control mapping through ServiceNow data modeling, AI-assisted compliance intelligence, and executive dashboards.


Portfolio Disclaimer

This project is a simulated enterprise healthcare environment created for portfolio and educational purposes. All organizations, infrastructure, compliance records, risks, and datasets are fictional and do not represent real healthcare systems.


🎯 Executive Summary

Healthcare organizations face increasing pressure to demonstrate continuous compliance with regulatory frameworks such as HIPAA, NIST SP 800-53, HITRUST CSF, and SOC 2 while simultaneously responding to evolving cybersecurity threats. Traditional GRC programs often rely on disconnected spreadsheets, manually maintained evidence repositories, and reactive audit preparation, creating significant operational overhead and reducing visibility into an organization's true security posture.

The OmniCare AI GRC Intelligence Platform addresses this challenge by integrating cybersecurity telemetry, compliance intelligence, artificial intelligence, ServiceNow, and executive analytics into a unified enterprise platform.

Rather than treating compliance as a periodic audit activity, the platform demonstrates how security events can be transformed into continuous compliance intelligence through automation, regulatory mapping, AI-assisted analysis, and executive reporting.


Business Objectives

The platform was engineered to demonstrate how modern healthcare organizations can:

  • Improve continuous compliance monitoring across multiple regulatory frameworks.
  • Correlate technical security findings with healthcare regulatory requirements.
  • Automate compliance intelligence using AI-assisted analysis.
  • Centralize governance, risk, and compliance data within ServiceNow.
  • Deliver executive-ready dashboards that support operational and strategic decision-making.
  • Reduce audit preparation effort through structured compliance evidence and control mapping.

Platform Highlights

  • 🏥 Healthcare-focused cybersecurity compliance platform
  • 🤖 AI-assisted compliance analysis using Gemini AI
  • 🛡️ Multi-framework support (HIPAA, NIST SP 800-53, HITRUST CSF, SOC 2)
  • ⚙️ ServiceNow GRC data model using Fluent SDK
  • 📊 Executive Power BI dashboards
  • 🚀 FastAPI backend services
  • 🖥️ Interactive Streamlit user interface
  • 💾 SQLite persistence with intelligent response caching
  • 📈 Risk intelligence and compliance analytics
  • 🔄 Designed for continuous compliance monitoring

🏥 Business Problem & Engineering Vision

Modern healthcare organizations generate enormous volumes of security telemetry every day—from endpoint devices, cloud infrastructure, identity systems, and enterprise applications. Although security operations teams can detect vulnerabilities and misconfigurations quickly, translating those technical findings into regulatory compliance evidence remains a significant operational challenge.

Healthcare compliance teams are often required to manually correlate technical security events with frameworks such as HIPAA, NIST SP 800-53, HITRUST CSF, and SOC 2, resulting in fragmented workflows, duplicated effort, and reactive audit preparation.

The OmniCare AI GRC Intelligence Platform was created to demonstrate a modern approach to this problem.

Rather than treating compliance as a collection of spreadsheets or point-in-time assessments, the platform models compliance as a continuous engineering process where technical telemetry, governance data, AI-assisted analysis, and executive reporting work together as a unified system.


Engineering Journey

This project evolved through several engineering phases, each building upon the previous stage to create an integrated healthcare GRC platform.

Phase 1 — Simulated Healthcare Environment

  • Simulated Windows 11 healthcare endpoint
  • Healthcare infrastructure scenarios
  • HIPAA, NIST, HITRUST, and SOC 2 control mapping
  • Compliance crosswalk generation
  • Risk register development

Phase 2 — Compliance Intelligence

  • Python automation
  • Regulatory control mapping
  • Simulated attack telemetry
  • Compliance analytics
  • Risk scoring

Phase 3 — Executive Analytics

  • Power BI dashboards
  • Compliance KPIs
  • Executive reporting
  • Continuous monitoring metrics

Phase 4 — AI Intelligence Layer

  • FastAPI backend
  • Gemini AI integration
  • Compliance blueprint generation
  • AI-assisted remediation guidance
  • Intelligent response caching

Phase 5 — ServiceNow GRC Platform

  • Fluent SDK implementation
  • Authority Document data model
  • Citation Control data model
  • Enterprise GRC foundation
  • ServiceNow application architecture

Project Evolution

What began as a Power BI compliance analytics project evolved into a full-stack AI-powered Healthcare GRC platform integrating ServiceNow, Python, FastAPI, Gemini AI, Streamlit, and Power BI into a unified enterprise architecture.


🏗️ Platform Architecture

The OmniCare AI GRC Intelligence Platform is designed using a layered enterprise architecture that combines cybersecurity telemetry, governance workflows, artificial intelligence, analytics, and ServiceNow into a unified compliance ecosystem.

                    Windows 11 Endpoint
                           │
                    Security Telemetry
                           │
                           ▼
               Python Data Processing Engine
                           │
                           ▼
              Compliance Mapping & Risk Engine
                           │
                           ▼
                 FastAPI Backend Services
                           │
        ┌──────────────────┼──────────────────┐
        │                  │                  │
        ▼                  ▼                  ▼
   Gemini AI          SQLite Cache      ServiceNow GRC
        │                                     │
        │                                     ▼
        │                           Authority Documents
        │                           Citation Controls
        │                           (Future)
        │                           Controls
        │                           Evidence
        │                           Findings
        │
        └──────────────┬──────────────────────┘
                       ▼
              Streamlit User Interface
                       │
                       ▼
             Power BI Executive Dashboard

Enterprise Platform Layers

Layer Primary Technologies Purpose
Presentation Streamlit, Power BI Executive dashboards and analyst interface
API Layer FastAPI REST APIs and orchestration
AI Intelligence Gemini AI Compliance analysis and remediation guidance
Compliance Engine Python Regulatory mapping, scoring, and analytics
Platform ServiceNow Fluent SDK GRC data model and governance workflows
Data SQLite Local persistence and AI response caching

Core Platform Components

🖥️ Endpoint Simulation

  • Windows 11 healthcare workstation
  • Simulated cybersecurity events
  • Infrastructure telemetry
  • Compliance evidence generation

⚙️ Compliance Intelligence Engine

  • HIPAA crosswalk processing
  • NIST SP 800-53 mappings
  • HITRUST CSF mappings
  • SOC 2 mappings
  • Risk scoring

🤖 AI Intelligence

  • AI-assisted compliance analysis
  • Compliance blueprint generation
  • Remediation recommendations
  • Regulatory interpretation
  • Intelligent response caching

🏛️ ServiceNow GRC

Current implementation

  • Authority Documents
  • Citation Controls

Planned expansion

  • Control Objectives
  • Controls
  • Evidence
  • Assessments
  • Findings
  • Risks
  • POA&M

📊 Executive Analytics

  • Compliance KPIs
  • Risk Intelligence
  • Executive reporting
  • Continuous monitoring
  • Power BI dashboards

🖥️ Platform Demonstration

The OmniCare AI GRC Intelligence Platform demonstrates a complete healthcare cybersecurity governance workflow—from simulated endpoint telemetry through AI-assisted compliance analysis, ServiceNow GRC data modeling, and executive reporting.

The following screenshots highlight key platform capabilities.


📊 Executive Compliance Dashboard

Purpose

Provides executive-level visibility into organizational compliance posture, audit readiness, and operational risk.

Dashboard Highlights

  • Overall Compliance Rate
  • Total Audited Controls
  • High Risk Controls
  • Open Findings
  • Overdue Remediation Tracking
  • Interactive Framework Filtering
  • Executive KPI Monitoring

📷 Insert Executive Power BI Dashboard Screenshot Here


⚠️ Risk Intelligence Dashboard

Purpose

Allows GRC analysts to identify high-risk control failures and prioritize remediation activities.

Dashboard Highlights

  • Risk Scoring
  • Compliance Status
  • Inherent Risk Analysis
  • Remediation SLA Tracking
  • Control Health Monitoring

📷 Insert Risk Dashboard Screenshot Here


🤖 AI Compliance Assistant

Purpose

Uses Gemini AI to transform technical findings into compliance intelligence and remediation guidance.

AI Capabilities

  • Compliance Blueprint Generation
  • AI-Assisted Remediation Recommendations
  • Regulatory Interpretation
  • Framework Mapping
  • Risk Narrative Generation

📷 Insert Streamlit AI Interface Screenshot Here


🏛️ ServiceNow GRC

Purpose

Provides structured governance data using the ServiceNow Fluent SDK.

Current implementation includes:

  • Authority Documents
  • Citation Controls

Upcoming implementation:

  • Control Objectives
  • Controls
  • Evidence
  • Assessments
  • Findings
  • Risks
  • POA&M

📷 Insert ServiceNow Table Screenshot Here


🔄 End-to-End Workflow

                OmniCare AI GRC Intelligence Platform

┌─────────────────────────────────────────────────────────────┐ │ Healthcare Security Environment │ │ │ │ Windows 11 Endpoint Cloud Assets Identity Policies │ └─────────────────────────────────────────────────────────────┘ │ ▼ ┌─────────────────────────────────────────────────────────────┐ │ Python Compliance & Analytics Engine │ │ │ │ • Telemetry Processing │ │ • Compliance Crosswalk │ │ • Risk Scoring │ │ • Control Mapping │ └─────────────────────────────────────────────────────────────┘ │ ▼ ┌─────────────────────────────────────────────────────────────┐ │ FastAPI Integration Layer │ └─────────────────────────────────────────────────────────────┘ │ │ │ ▼ ▼ ▼ Gemini AI SQLite Cache ServiceNow GRC │ ▼ Authority Documents Citation Controls (Future) Controls Evidence Findings Risks POA&M │ ▼ ┌─────────────────────────────────────────────────────────────┐ │ Streamlit Portal + Power BI Dashboards │ └─────────────────────────────────────────────────────────────┘ │ ▼ Executives • GRC Analysts • Auditors


             OmniCare AI GRC Intelligence Platform

             ┌──────────────────────────────┐
             │    Windows 11 Endpoint       │
             │ Security Telemetry & Events  │
             └──────────────┬───────────────┘
                            │
                            ▼
             ┌──────────────────────────────┐
             │ Python Compliance Engine     │
             │ Crosswalk • Risk • Analytics │
             └──────────────┬───────────────┘
                            │
                 ┌──────────┴──────────┐
                 ▼                     ▼
         FastAPI Backend         SQLite Cache
                 │
                 ▼
           Gemini AI Services
                 │
                 ▼
        ServiceNow GRC Platform
                 │
     ┌───────────┴────────────┐
     ▼                        ▼
Streamlit UI          Power BI Dashboard
                 │
                 ▼
        Executive Decision Support

This workflow demonstrates how cybersecurity telemetry is transformed into actionable governance, risk, and compliance intelligence.


Authority Document │ ▼ Citation Control │ ▼ Control Objective │ ▼ Control │ ▼ Evidence │ ▼ Assessment │ ▼ Finding │ ▼ Risk │ ▼ POA&M


Security Event │ ▼ Telemetry Collection │ ▼ Python Processing │ ▼ Compliance Mapping │ ▼ FastAPI │ ▼ Gemini AI │ ▼ ServiceNow │ ▼ Power BI │ ▼ Executive Decision Support


1. Executive Summary & Business Case Analysis

The Strategic Alignment

In cloud-native healthcare environments, maintaining continuous compliance is a critical business driver for market entry, trust optimization, and liability mitigation. Digital healthcare platforms operating within public clouds (e.g., GCP, AWS) process high volumes of Protected Health Information (PHI), placing them under strict federal and industry-mandated security scrutiny.

The Operational Challenge

Traditional GRC workflows rely on manual, retroactive documentation pipelines—predominantly static spreadsheets, isolated risk registers, and disconnected issue trackers. This creates severe friction points:

  • Siloed Technical Vulnerabilities: Engineering teams track infrastructure configurations, container scans, and patch logs in DevOps pipelines, while compliance officers track regulatory standards in standalone frameworks.
  • Delayed Remediation Execution: Security gaps are decoupled from formal Service Level Agreements (SLAs), causing critical findings to exceed remediation deadlines without visibility.
  • Audit Preparation Overheads: Preparing compliance evidence for external HIPAA or SOC 2 assessors takes weeks of manual retroactive mapping, leading to high human-error risk and audit strain.

The Engineered Solution

The OmniCare Digital GRC Workbench centralizes these disparate data streams into an interactive dashboard. By consolidating a master control framework with active technical risk registries, the workbench provides:

  1. Continuous Audit Readiness: Automates control-mapping to serve as dynamic audit evidence, drastically shrinking preparation cycles.
  2. Proactive SLA Tracking: Aggregates risk scores and countdown timelines right next to impacted assets to optimize engineering remediation velocity.
  3. Executive Posture Transparency: Summarizes global compliance health through high-impact KPI matrices designed for leadership and regulatory reviews.

2. Data Architecture & Relational Integrity

The architectural integrity of the workbench relies on a precise relational structure connecting regulatory frameworks directly to active security operations data.

Data Schema & Joining Logic

The data model connects two principal tables through an intentional Left Outer Join mapped on the primary key ControlID:

  1. master_hipaa_crosswalk (Left / Parent Table): The definitive organizational catalog of evaluated standards. It contains fields such as ControlID, ControlName, Domain, and formal regulatory text strings.
  2. risk_register (Right / Child Table): The operational log of live vulnerabilities, containing technical metadata including AssetTarget, CloudEnvironment, InherentRiskScore, and RemediationSLA.
       +-------------------------------+          +-------------------------------+
       |    master_hipaa_crosswalk     |          |         risk_register         |
       +-------------------------------+          +-------------------------------+
       |  ControlID (Primary Key) [PK] |          |  ControlID (Foreign Key) [FK] |
       |  ControlName                  |   LEFT   |  AssetTarget                  |
       |  Domain                       | -------->|  CloudEnvironment             |
       |  Status                       |   JOIN   |  InherentRiskScore            |
       |  ComplianceRate               |          |  RemediationSLA               |
       +-------------------------------+          +-------------------------------+

Preventing Artificial Posture Inflation

A critical engineering choice was implementing a Left Outer Join rather than a standard Inner Join.

  • The Pitfall of Inner Joins: If an Inner Join were used, any regulatory control that does not currently have an active finding or vulnerability in the risk_register would be entirely omitted from the data model. This would hide unreviewed controls, artificially inflating the global compliance rate.

  • The Left Join Solution: By utilizing a Left Outer Join, every single audited control remains anchored on the reporting canvas. Controls without active findings display blank fields (formatted as professional empty spaces), preserving the complete operational footprint and giving auditors an honest view of compliance health.


3. UI/UX Design Engineering Decisions

The frontend layout was engineered to optimize scannability for both internal compliance analysts and external federal assessors.

High-Impact Metric Hierarchy

The user interface avoids complex, cluttered layouts in favor of an intuitive, multi-tiered visual hierarchy:

  • The Top-Level Posture Row: Centers on a dynamic Global Compliance Rate Gauge calibrated to track real-time posture changes alongside a Total Audited Controls indicator. This instantly establishes baseline security confidence.
  • The Balanced Executive KPI Block: Displays operational liabilities transparently using three dedicated cards: Open Findings, High Risks, and Overdue Remediations. This guarantees that severe technical issues can never hide behind a high global compliance score.

Professional Data Hygiene & Readability Configurations

  • Column Auto-Sizing & Explicit Text-Wrapping: Regulatory framework descriptions (e.g., Transmission Confidentiality under NIST/HIPAA) feature long text strings. Text wrapping is fully enabled across the main Audit Details Matrix, preventing clipped strings or rigid borders from breaking text readability.
  • Clean Empty-Cell Strategy: Fields with missing risk data or unflagged controls are configured to render as clean spaces rather than displaying messy error flags or misleading 0 values, keeping the interface crisp and highly readable.
  • Proactive Conditional Heat Mapping: Localized formatting rules apply a soft alert-red gradient directly to the InherentRiskScore column. The logic is configured to completely ignore empty cells, while active, high-exposure technical vulnerabilities (such as a critical 16-point infrastructure vulnerability) automatically pop out visually to instantly draw an auditor’s attention.

4. Interactive Slicers & Operational Impact

The workspace features classic dropdown toolbar components for CloudEnvironment and Status fields, transitioning the platform from a static report into a multi-dimensional analysis application.

Slicer Configuration & Filter Behavior

To maintain exceptional data integrity during review cycles, the interactive slicers are configured as follows:

  • Single select = Off: Allows users to view the entire infrastructure footprint simultaneously by default.
  • Show "Select all" option = On: Places an instantaneous reset switch at the top of the dropdown menu to quickly clear active drill-downs.
  • Multi-select with Ctrl = On: Enables advanced reviewers to slice and aggregate specific permutations of multiple cloud environments or target vectors simultaneously.

📊 Interactive Dashboard Walkthrough

1. Baseline Compliance Posture (Global Corporate View)

When both slicers are resting in the "Select all" / Unfiltered state, the canvas delivers a comprehensive summary of the total organizational footprint. This gives leadership a unified dashboard of compliance wellness across all environments and frameworks.

Baseline Dashboard

Figure 1: Default dashboard view showcasing global compliance metrics across all integrated control sets.

2. Real-Time Risk Isolation (Active Audit Drill-Down View)

When an assessor interacts with the toolbar and filters the status specifically to Non-Compliant, the workbench dynamically pivots. The KPI counters instantly recalibrate to track targeted risk counts, and the central details matrix narrows down to isolate critical exposures (e.g., a critical infrastructure vulnerability with a score of 16 affecting the production endpoint clinical-db.omnicare.local).

Non-Compliant Risk Drill-Down

Figure 2: Active drill-down state displaying metric synchronization when isolating Non-Compliant controls.


5. Business Value & Technical Takeaways

Operational ROI

  • Audit Preparation Efficiency: Demonstrates how continuous monitoring and centralized evidence visibility can potentially reduce manual audit preparation effort and improve assessment readiness.

  • Risk-Based Remediation Visibility: Illustrates how linking risks, affected assets, and remediation SLAs can improve accountability and prioritize security efforts.

  • Data Quality & Reporting Integrity: Demonstrates the importance of structured data modeling and filtering to ensure dashboard metrics represent meaningful compliance insights.


6. Tech Stack

Category Technologies
Dashboard Power BI
Data Sources Excel, CSV
Data Modeling Power Query, Relational Data Modeling
Frameworks HIPAA, NIST 800-53, SOC 2
Risk Analytics Risk Scoring, SLA Tracking
Visualization KPI Cards, Gauges, Slicers, Conditional Formatting

7. Repository Structure

ai-powered-grc-workbench/
├── data/
├── images/
├── dashboard/
├── README.md
└── documentation/

8. Professional Skills Demonstrated

  • Cybersecurity GRC Analytics
  • HIPAA Security Rule Compliance
  • NIST 800-53 Control Mapping
  • SOC 2 Readiness Monitoring
  • Risk Register Management
  • Power BI Dashboard Development
  • Security Metrics & Executive Reporting
  • Data Modeling & Transformation
  • Continuous Compliance Monitoring

9. Future AI-Driven GRC Enhancements

Future versions of this workbench could evolve from a compliance reporting interface into a proactive, continuous compliance intelligence platform through capabilities such as:

🤖 AI-Powered Compliance Intelligence

  • LLM-powered compliance evidence search
  • Automated control-to-framework crosswalking
  • Conversational audit assistant for natural language compliance queries

🔍 Intelligent Risk Analytics

  • Machine learning-based risk prediction
  • Predictive SLA drift tracking based on historical remediation trends
  • Automated identification of emerging compliance gaps

🛠️ AI-Assisted Remediation

  • AI-generated remediation recommendations
  • Automated security configuration guidance
  • Context-aware engineering remediation playbooks

Developed as part of the CyberGRC Professional Portfolio Project.

About

Enterprise AI-powered Healthcare GRC platform integrating ServiceNow, FastAPI, Gemini AI, Power BI, and HIPAA/NIST compliance automation.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages