Resources / Security Review · Updated August 18, 2026

EMR Security Questionnaire for Medical Practices

A security review should produce evidence, owners, contract terms, and follow-up items—not just yes-or-no answers. Adapt these questions with your privacy, security, legal, compliance, and technical advisers.

This is an evaluation aid, not legal advice or a certification checklist. Your obligations and risk decisions depend on the data, services, contracts, jurisdictions, and workflows involved.

Governance and responsibilities

  • Which entity provides each service, and which agreements apply?
  • How are security responsibilities divided between the vendor, customer, hosting providers, and connected services?
  • What policies, risk assessments, independent reviews, or assurance reports are available under appropriate confidentiality terms?
  • How are material changes to services, vendors, or security practices communicated?

Identity and access

  • How are users provisioned, approved, changed, disabled, and periodically reviewed?
  • What role-based controls and minimum-access options are available?
  • Which authentication and multi-factor options are supported, and where are exceptions possible?
  • How are administrative access, support access, service accounts, and emergency access controlled?
  • What session, password, lockout, and device controls can the customer configure?

Data protection

  • How is data protected in transit and at rest?
  • Where is customer data stored, processed, backed up, and supported?
  • How are encryption keys and secrets managed?
  • How are production data, test data, exports, attachments, and temporary files handled?
  • What secure methods are available for importing and exporting data?

Logging and monitoring

  • Which user, administrator, data-access, configuration, authentication, and export events are recorded?
  • How long are relevant logs retained and who can review them?
  • Can the customer obtain reports needed for internal review or investigation?
  • How are suspicious events detected, triaged, escalated, and documented?

Development and vulnerability management

  • How are changes reviewed, tested, approved, and deployed?
  • How are dependencies, infrastructure, application vulnerabilities, and reported weaknesses tracked?
  • What testing is performed and how are findings prioritized and remediated?
  • How are development, test, and production environments separated?

Vendors and connected services

  • Which other companies may store, transmit, support, or otherwise handle customer data?
  • How are those companies evaluated and monitored?
  • Which connections are required, optional, or contracted directly by the customer?
  • How are changes, outages, incidents, and terminations involving those services handled?

Continuity, backup, and recovery

  • What is backed up, how often, where, and with what protection?
  • How are backup restoration and recovery procedures tested?
  • What dependencies affect recovery?
  • What continuity steps should the practice maintain when the service or internet connection is unavailable?

Incident response and communication

  • How are suspected incidents reported by customers and staff?
  • What investigation, containment, preservation, and communication processes apply?
  • Which contractual notification terms, contacts, and cooperation duties apply?
  • How are lessons learned and corrective actions tracked?

Retention, export, and termination

  • What retention settings exist and who controls them?
  • What export formats and assistance are available during normal use and at termination?
  • How are deleted data, residual copies, backups, and connected-service copies addressed?
  • What customer actions and timelines are required before access ends?
Review OAK EMR. Start with our published security practices, then request additional information for your organization’s review.