1. Have you performed an external network vulnerability scan in the last 90 days?
2. How frequently do you conduct phishing awareness training or simulations for your staff?
3. Are all critical systems containing patient data backed up daily, with backups stored securely off-site or in the cloud?
4. Is the use of administrative (IT) privileges on computers and servers restricted to only those who require it?