Ten Security Questions Administrators Should Ask Their IT Provider

Administrators and owners are accountable for protecting resident information, but most are not technology specialists. That makes it easy to rely on reassurance: "We have it covered." A better approach is to ask specific questions and listen for specific answers. You do not need to understand every technical term. You do need to know whether your provider can explain things clearly and show evidence.

Here are ten questions to ask, along with what a good answer sounds like.

1. When was our last security risk analysis, and what did it find?

Good answer: A date within the past year, a written report, and a list of risks with owners and timelines. Concern: "We have never done one" or a vague reference to a scan.

2. Is multi-factor authentication turned on for email, remote access and administrator accounts?

Good answer: Yes for each, with exceptions listed and a plan to close them. Concern: "Mostly" with no list of what is missing.

3. Are our backups tested, and could they survive ransomware?

Good answer: A description of backup types, at least one copy that is offline or immutable, and a date of the last successful restore test. Concern: "The backup job runs every night" but no one has tried restoring.

4. How quickly do we apply security updates?

Good answer: A defined schedule, faster handling for critical issues and a report on exceptions. Concern: No one can say, or critical systems are far behind.

5. Who watches for threats outside business hours?

Good answer: A named monitoring service or team, alert routing to a person and an escalation path. Concern: Alerts go to an unread inbox.

6. What happens if we are hit with ransomware tonight?

Good answer: A written incident response plan, a contact list, a clear decision-maker and insurer instructions, plus a recent tabletop exercise. Concern: "We would figure it out."

7. Who has administrator access to our systems, and when did we last review it?

Good answer: A list of named accounts, reviewed at least quarterly, with former staff removed promptly. Concern: Shared administrator passwords or accounts of people who left long ago.

8. What equipment or software is out of date or no longer supported?

Good answer: An inventory with end-of-life dates and a budget plan for replacement. Concern: No inventory, or knowing about unsupported systems with no plan.

9. How do we train staff, and how do we know it works?

Good answer: Regular short training, phishing simulations, reporting statistics and documentation. Concern: "Everyone watched the video."

10. What do you need from us to protect our residents better?

Good answer: Specific, prioritized recommendations with costs and rationale, even if they require budget or leadership decisions. Concern: "Nothing, we are fine," which is rarely true for any organization.

How to Run the Conversation

Ask for answers in writing so you can share with owners, boards and insurers.

Request evidence, such as screenshots, reports and logs, not just assurances.

Ask for plain English. A good provider can explain technical topics without jargon.

Note what you do not understand and ask again.

Schedule this as a recurring review, perhaps quarterly.

Beyond the Questions

Look at the relationship

A provider who communicates proactively, reports honestly on problems and admits what they do not know is more valuable than one who promises perfect protection.

Watch for conflicts

Be wary of any provider that says breaches cannot happen. No organization can promise that. What matters is preparation, detection and response.

Connect to compliance

HIPAA expects documentation of security measures. The answers above feed directly into your risk analysis and your ability to demonstrate due diligence.

What to Do With Gaps

Do not panic if the answers reveal gaps. Nearly every organization has some. Rank them by risk and cost, assign owners, and set deadlines. Quick wins like enabling MFA and testing a restore often cost little.

How UnityCare IT Can Help

UnityCare IT welcomes these questions from current and prospective clients in long-term care, senior living and clinics. If you would like a second opinion on your own answers, we can walk through them together and give you a short, prioritized list.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034