Administrators and owners are accountable for protecting resident information, but most are not technology specialists. That makes it easy to rely on reassurance: "We have it covered." A better approach is to ask specific questions and listen for specific answers. You do not need to understand every technical term. You do need to know whether your provider can explain things clearly and show evidence.
Here are ten questions to ask, along with what a good answer sounds like.
Good answer: A date within the past year, a written report, and a list of risks with owners and timelines. Concern: "We have never done one" or a vague reference to a scan.
Good answer: Yes for each, with exceptions listed and a plan to close them. Concern: "Mostly" with no list of what is missing.
Good answer: A description of backup types, at least one copy that is offline or immutable, and a date of the last successful restore test. Concern: "The backup job runs every night" but no one has tried restoring.
Good answer: A defined schedule, faster handling for critical issues and a report on exceptions. Concern: No one can say, or critical systems are far behind.
Good answer: A named monitoring service or team, alert routing to a person and an escalation path. Concern: Alerts go to an unread inbox.
Good answer: A written incident response plan, a contact list, a clear decision-maker and insurer instructions, plus a recent tabletop exercise. Concern: "We would figure it out."
Good answer: A list of named accounts, reviewed at least quarterly, with former staff removed promptly. Concern: Shared administrator passwords or accounts of people who left long ago.
Good answer: An inventory with end-of-life dates and a budget plan for replacement. Concern: No inventory, or knowing about unsupported systems with no plan.
Good answer: Regular short training, phishing simulations, reporting statistics and documentation. Concern: "Everyone watched the video."
Good answer: Specific, prioritized recommendations with costs and rationale, even if they require budget or leadership decisions. Concern: "Nothing, we are fine," which is rarely true for any organization.
Ask for answers in writing so you can share with owners, boards and insurers.
Request evidence, such as screenshots, reports and logs, not just assurances.
Ask for plain English. A good provider can explain technical topics without jargon.
Note what you do not understand and ask again.
Schedule this as a recurring review, perhaps quarterly.
A provider who communicates proactively, reports honestly on problems and admits what they do not know is more valuable than one who promises perfect protection.
Be wary of any provider that says breaches cannot happen. No organization can promise that. What matters is preparation, detection and response.
HIPAA expects documentation of security measures. The answers above feed directly into your risk analysis and your ability to demonstrate due diligence.
Do not panic if the answers reveal gaps. Nearly every organization has some. Rank them by risk and cost, assign owners, and set deadlines. Quick wins like enabling MFA and testing a restore often cost little.
UnityCare IT welcomes these questions from current and prospective clients in long-term care, senior living and clinics. If you would like a second opinion on your own answers, we can walk through them together and give you a short, prioritized list.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034