This document outlines plans for a HIPAA Remediation Project to strengthen an organization's IT security governance by implementing the ISO 27001/2 framework. The project aims to develop policies, processes, and controls to safely manage sensitive information and address security risks and audit findings. Key objectives include protecting information, managing risks, developing guidance policies, and demonstrating compliance to auditors. The roles of the Privacy and Security Officer, Chief Information Security Officer, General Counsel, and Director of Human Resources are defined to support implementing the new governance framework.