Administrators and directors of nursing are not expected to configure firewalls. But you are expected to know whether your organization is reasonably protected, and you are the person who answers to residents, families, regulators and insurers when something goes wrong. A short monthly conversation with your IT team or provider is one of the best ways to stay informed.
Here are ten questions you can ask at month-end. You do not need to understand every technical detail of the answers. You need to hear clear, specific responses, and to notice when you do not.
Ask specifically about email, remote access, administrator accounts and the EHR. A good answer lists what is covered and what is not yet, with a date for closing gaps.
A backup that has never been restored is unproven. You want a date, what was restored and how long it took. Also ask whether at least one copy is offline or immutable, so ransomware cannot reach it.
Ask for a count of systems missing critical updates and those running operating systems that no longer receive security fixes. The goal is not zero on the first day, but a list with a plan.
Ask whether accounts of people who left this month have been disabled everywhere, including the EHR and vendor portals, and when access was last reviewed. Ask also how many people have administrator rights and why.
This includes phishing messages reported by staff, lost devices, misdirected faxes and emails, suspicious login alerts and blocked attacks. A month with nothing reported usually means nothing was noticed, not that nothing happened. Encourage reporting and thank staff who do.
Ask for completion numbers for the month, including new hires, night shift and agency staff. Ask also how many people clicked on simulated phishing tests, if you run them, and what you are doing to coach.
Ask about new vendors, changes and any vendor that told you about a security event. Confirm that business associate agreements are in place for those who need them and that vendor remote access is limited and reviewed.
Check that contact numbers, including the insurer, EHR vendor and IT provider, are up to date and that printed copies exist where staff can find them without the network. Ask when you last practiced a downtime drill or tabletop exercise.
This is the most revealing question. A good IT partner can name two or three specific risks, such as an unsupported firewall or incomplete MFA, and describe what it would take to fix them. If the answer is that everything is fine, ask again.
Security projects often stall for non-technical reasons: budget approval, staff time, a policy decision, a vendor contract, or leadership communication. Ask what decisions are waiting for you and what support the team needs.
Write down the answers, the date and any action items with owners and due dates. This builds a trail showing ongoing oversight, which supports the HIPAA requirement for regular review of information system activity and the evaluation of your safeguards. It also helps when it is time to update your risk analysis.
Over time, you should see:
Fewer unknowns and clearer answers.
Problems found internally before outsiders find them.
Steady progress on a prioritized list.
Staff who report instead of hide mistakes.
Vague answers, delays or defensiveness are a signal. It may mean the information is not being tracked, the tools are not in place or the provider is overloaded. Either way, it is worth a deeper look.
UnityCare IT provides monthly reporting for healthcare clients, covering security, backups, patching and support activity in plain language. If you would like a checklist or a review of your current reporting, we are happy to help you set one up.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172