IDC Recognizes TrustCloud Application Assurance as a Meaningful GRC Advancement. Read the report →

IMO Health

How IMO Health transformed enterprise risk management, created transparency, and built a security culture

Company: IMO Health

Location: Rosemont, IL

Solutions: TrustShare, TrustOps, TrustRegister, TrustLens and TrustCloud Platform

“The ability to see how risks, controls, and systems connect has been really transformative. It’s not just a tool, it’s a framework for informed decision-making.”
Lori Kevin
VP, Security and Compliance

The company

IMO Health (Intelligent Medical Objects) is a leading healthcare technology company dedicated to improving clinical data quality at the point of care. With a mission to transform healthcare delivery, IMO Health specializes in software solutions that enable precise documentation and structured data for analytics, research, and quality improvement.

Headquartered in Rosemont, Illinois, the company employs hundreds of individuals across the US, including an information security and compliance team led by Lori Kevin, VP of Security and Compliance. Lori and her team are the driving force behind IMO Health’s robust security practices, ensuring HIPAA compliance, creating an enterprise-wide security culture, and safeguarding data integrity.

Overview

At IMO Health, security has become more than a compliance function. Under Lori’s leadership, it has evolved into a more connected, business-aware program built on the conviction that security must be a shared responsibility across the organization.

“Trust is the foundation of everything my team does. We’re building a security function around the core values of trust, accessibility, clarity and strong communication. We want the whole organization to know how to access security policies and see the strategic value security offers to their department.”

Lori Kevin
VP, Security and Compliance

With TrustCloud, IMO Health gained the visibility and confidence needed to move beyond fragmented processes and into continuous, data-driven security assurance.

The challenge

As a leader in healthcare IT, the IMO Health security team faced significant challenges in managing risk and compliance:

  • Manual Processes: Security questionnaires and vendor assessments were labor-intensive, leaving room for inefficiencies.
  • Disconnected Systems: Risk management processes were siloed, creating gaps in visibility.
  • Limited Transparency: The sales and security teams struggled with fragmented communication, affecting efficiency.
  • Evolving AI Governance Needs: Developing clinical AI products brought new challenges around documenting and presenting AI governance and bias assessments.
  • Siloed Security Function: Lori envisioned building a security culture the whole organization could adopt, making security a shared responsibility with positive impact on the business.

“Our processes were functional but disconnected. We needed a unified system to improve collaboration and ensure transparency.”

Lori Kevin
VP, Security and Compliance

Those challenges also made it harder to communicate security work in a way the broader business could understand. As Lori has explained, much of security happens behind the scenes, and leaders outside the function often do not realize the full scope of what is already in place to protect the organization.

In one conversation, after Lori outlined the controls already supporting the business, the response was: “I had no idea we do all of that.” This gap created both a visibility problem and a missed opportunity to build trust across the organization.

The Turning Point: Choosing TrustCloud

In April 2024, Lori and her team partnered with TrustCloud to transform their approach to compliance and risk management. The decision was driven by a need for tools that could:

  • Simplify compliance mapping with TrustOps.
  • Centralize risk visibility through TrustRegister.
  • Enhance customer assurance with TrustShare.
  • Streamline vendor management using TrustLens.

Embed security awareness across the organization by freeing up the security team to focus on business impact reporting and collaboration with security champions.

Implementation

Under Lori’s leadership, IMO Health’s security team quickly harnessed the power of TrustCloud’s platform. By focusing on workflow integration and team enablement, they:

  • Mapped critical controls to SOC 2 and HIPAA standards in TrustOps.
  • Created a dynamic risk workflow in TrustRegister, tying risks directly to controls and systems.
  • Launched TrustShare, enabling seamless customer interactions and reducing back-and-forth exchanges.
  • Piloted TrustLens for vendor risk assessments, addressing gaps in their existing processes.

Launched a Security Champions program engaging 30+ members of the organization to improve awareness of security initiatives and collaborate on tailored solutions and training for each department.

Building a security culture across the organization

With a foundation of continuous control monitoring and improved risk management in place, Lori turned her attention to building a culture of security ownership across the organization. Stronger data and clearer communication made security a strategic voice within the organization, not just a reporting function.

“You can’t build a security culture just in your team. The security culture has to permeate across the organization.”

Lori Kevin
VP, Security and Compliance

  1. Security champions program 

A cornerstone of this approach was launching a cross-functional Security Champions program, with representatives from every department—not just engineering or product.

  • ~30 employees across functions participated
  • Champions acted as advocates and feedback loops, translating security priorities for their own departments
  • The program emphasized dialogue over top-down training
  1. Making security relevant to every employee 

IMO Health moved beyond generic awareness training to role-specific, real-world engagement.

  • Messaging tailored by department and function
  • Real examples used to demonstrate impact
  • Security positioned as part of everyday behavior, not annual compliance

“I want this to become muscle memory … not something we reteach every year.” 

  1. Enabling confident, business-aligned risk communication

With stronger visibility into controls and risk posture, Lori elevated how security is communicated to leadership.

Instead of presenting raw technical findings, she focused on structured, business-relevant storytelling: “Here’s the risk. Here’s what we’ve already got in place…and here’s what’s left and what we’re doing about it.” 

This approach allowed security to become clear, actionable, and aligned with executive priorities.

Results

Thanks to the team’s efforts, IMO Health has achieved:

  • Faster Sales Cycles: Using TrustShare, Lori’s team provided transparency to potential customers, cutting down sales cycle durations during a critical year-end period.
    “We’re no longer bogged down by email threads. TrustCloud gives our customers the clarity they need,” Lori explained.
  • Improved Collaboration: Security and sales now work hand in hand with centralized visibility through TrustCloud.
  • Streamlined Vendor Management: Piloting TrustLens has paved the way for automated vendor risk assessments.
    “Vendor risk management used to feel like guesswork. Now, it’s a structured process we trust,” Lori said.
  • AI Governance Readiness: Lori’s team has developed robust AI governance policies, preparing them for growing customer inquiries about bias and transparency.
  • Effective and Embedded Security Culture: The IMO Health Security team has successfully brought security into daily workflow, strategic conversations, and decision-making. This ensures that security evolves alongside the business, not behind it, to support new initiatives and business development.

Leadership in Action

Lori and her team exemplify how a proactive approach to risk management can transform an organization. Their ability to use TrustCloud as a supportive framework has helped them lead IMO Health through a critical evolution in compliance and security.

“TrustCloud has helped us move from fragmented processes to a more connected, trusted approach to risk, one that supports both the business and the teams doing the work every day.”

Lori Kevin
VP, Security and Compliance

IMO Health’s transformation highlights a broader shift for modern CISOs, proving that:

  • Security culture must extend beyond the security team.
  • Confidence in data is essential for credible leadership communication.
  • Risk must be translated into business impact to drive action.

Engagement, not enforcement, is what scales security across an organization.

Looking Ahead: The Vision for 2025

With the foundation laid, Lori and her team are setting ambitious goals:

  • Expanding readiness for NIST CSF and NIST AI frameworks.
  • Building a comprehensive library of vendor questionnaires.
  • Providing leadership with detailed risk dashboards for informed decision-making.

Prioritizing AI governance and partnering with TrustCloud to make it a strategic focus.

“Our goal is to embed risk management into every facet of our operations. TrustCloud helps us make that a reality.”

Lori Kevin
VP, Security and Compliance

Want to hear more?

Lori joined TrustCloud CEO Sravish Sridhar for a Strategic CISOs conversation on Building an Organization-wide Security Culture, where she shared her perspectives on creating a culture of security in the organization and lessons learned.

 

Got Trust?®

TrustCloud makes it effortless for companies to share their data security, privacy, and governance posture with auditors, customers, and board of directors.
Trusty