EMR Security Questionnaire for Medical Practices
A security review should produce evidence, owners, contract terms, and follow-up items—not just yes-or-no answers. Adapt these questions with your privacy, security, legal, compliance, and technical advisers.
This is an evaluation aid, not legal advice or a certification checklist. Your obligations and risk decisions depend on the data, services, contracts, jurisdictions, and workflows involved.
Governance and responsibilities
- Which entity provides each service, and which agreements apply?
- How are security responsibilities divided between the vendor, customer, hosting providers, and connected services?
- What policies, risk assessments, independent reviews, or assurance reports are available under appropriate confidentiality terms?
- How are material changes to services, vendors, or security practices communicated?
Identity and access
- How are users provisioned, approved, changed, disabled, and periodically reviewed?
- What role-based controls and minimum-access options are available?
- Which authentication and multi-factor options are supported, and where are exceptions possible?
- How are administrative access, support access, service accounts, and emergency access controlled?
- What session, password, lockout, and device controls can the customer configure?
Data protection
- How is data protected in transit and at rest?
- Where is customer data stored, processed, backed up, and supported?
- How are encryption keys and secrets managed?
- How are production data, test data, exports, attachments, and temporary files handled?
- What secure methods are available for importing and exporting data?
Logging and monitoring
- Which user, administrator, data-access, configuration, authentication, and export events are recorded?
- How long are relevant logs retained and who can review them?
- Can the customer obtain reports needed for internal review or investigation?
- How are suspicious events detected, triaged, escalated, and documented?
Development and vulnerability management
- How are changes reviewed, tested, approved, and deployed?
- How are dependencies, infrastructure, application vulnerabilities, and reported weaknesses tracked?
- What testing is performed and how are findings prioritized and remediated?
- How are development, test, and production environments separated?
Vendors and connected services
- Which other companies may store, transmit, support, or otherwise handle customer data?
- How are those companies evaluated and monitored?
- Which connections are required, optional, or contracted directly by the customer?
- How are changes, outages, incidents, and terminations involving those services handled?
Continuity, backup, and recovery
- What is backed up, how often, where, and with what protection?
- How are backup restoration and recovery procedures tested?
- What dependencies affect recovery?
- What continuity steps should the practice maintain when the service or internet connection is unavailable?
Incident response and communication
- How are suspected incidents reported by customers and staff?
- What investigation, containment, preservation, and communication processes apply?
- Which contractual notification terms, contacts, and cooperation duties apply?
- How are lessons learned and corrective actions tracked?
Retention, export, and termination
- What retention settings exist and who controls them?
- What export formats and assistance are available during normal use and at termination?
- How are deleted data, residual copies, backups, and connected-service copies addressed?
- What customer actions and timelines are required before access ends?
Review OAK EMR. Start with our published security practices, then request additional information for your organization’s review.