Which risk management framework is most commonly adopted by US healthcare organizations to align information security with regulatory requirements?