Month-End Security Check: Ten Questions for Administrators

Administrators and directors of nursing are not expected to configure firewalls. But you are expected to know whether your organization is reasonably protected, and you are the person who answers to residents, families, regulators and insurers when something goes wrong. A short monthly conversation with your IT team or provider is one of the best ways to stay informed.

Here are ten questions you can ask at month-end. You do not need to understand every technical detail of the answers. You need to hear clear, specific responses, and to notice when you do not.

1. Are all important accounts protected by multi-factor authentication?

Ask specifically about email, remote access, administrator accounts and the EHR. A good answer lists what is covered and what is not yet, with a date for closing gaps.

2. When did we last test a restore from backup?

A backup that has never been restored is unproven. You want a date, what was restored and how long it took. Also ask whether at least one copy is offline or immutable, so ransomware cannot reach it.

3. Which computers and devices are out of date?

Ask for a count of systems missing critical updates and those running operating systems that no longer receive security fixes. The goal is not zero on the first day, but a list with a plan.

4. Who has access who should not?

Ask whether accounts of people who left this month have been disabled everywhere, including the EHR and vendor portals, and when access was last reviewed. Ask also how many people have administrator rights and why.

5. Did we have any security incidents or near misses?

This includes phishing messages reported by staff, lost devices, misdirected faxes and emails, suspicious login alerts and blocked attacks. A month with nothing reported usually means nothing was noticed, not that nothing happened. Encourage reporting and thank staff who do.

6. How many staff completed security training, and who has not?

Ask for completion numbers for the month, including new hires, night shift and agency staff. Ask also how many people clicked on simulated phishing tests, if you run them, and what you are doing to coach.

7. What vendors have access to our network or data?

Ask about new vendors, changes and any vendor that told you about a security event. Confirm that business associate agreements are in place for those who need them and that vendor remote access is limited and reviewed.

8. Is our incident response plan current?

Check that contact numbers, including the insurer, EHR vendor and IT provider, are up to date and that printed copies exist where staff can find them without the network. Ask when you last practiced a downtime drill or tabletop exercise.

9. What is our biggest risk right now?

This is the most revealing question. A good IT partner can name two or three specific risks, such as an unsupported firewall or incomplete MFA, and describe what it would take to fix them. If the answer is that everything is fine, ask again.

10. What do you need from me?

Security projects often stall for non-technical reasons: budget approval, staff time, a policy decision, a vendor contract, or leadership communication. Ask what decisions are waiting for you and what support the team needs.

Keep a simple record

Write down the answers, the date and any action items with owners and due dates. This builds a trail showing ongoing oversight, which supports the HIPAA requirement for regular review of information system activity and the evaluation of your safeguards. It also helps when it is time to update your risk analysis.

What good looks like

Over time, you should see:

Fewer unknowns and clearer answers.

Problems found internally before outsiders find them.

Steady progress on a prioritized list.

Staff who report instead of hide mistakes.

When the answers are unclear

Vague answers, delays or defensiveness are a signal. It may mean the information is not being tracked, the tools are not in place or the provider is overloaded. Either way, it is worth a deeper look.

Where UnityCare IT fits

UnityCare IT provides monthly reporting for healthcare clients, covering security, backups, patching and support activity in plain language. If you would like a checklist or a review of your current reporting, we are happy to help you set one up.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172