Hospital Information Security Risk Assessment Questionnaire
Please complete the Hospital Information Security Risk Assessment Questionnaire to help evaluate your hospital's current information security practices and identify potential areas of risk.
How would you rate your hospital's overall information security posture?
*
1
2
3
4
5
Does your hospital have a documented information security policy?
*
Yes
No
Not Sure
How frequently does your staff receive information security training?
*
Please Select
Annually
Every 2 years
Every 3 years or more
Never
Which of the following information security controls are in place at your hospital? (Select all that apply)
*
Multi-factor authentication
Regular software updates
Data encryption
Physical access controls
Network segmentation
None of the above
How often does your hospital perform information security risk assessments?
*
Annually
Every 2-3 years
Less frequently
Never
Please indicate your level of agreement with the following statements regarding your hospital's information security practices.
*
Rows
Strongly Disagree
Disagree
Neutral
Agree
Strongly Agree
We have an incident response plan in place.
1
2
3
4
5
Access to sensitive information is restricted based on role.
6
7
8
9
10
Physical security measures protect information systems.
11
12
13
14
15
Regular audits are conducted to assess security controls.
16
17
18
19
20
How confident are you in your hospital's ability to detect and respond to information security incidents?
*
Not confident
1
2
3
4
Very confident
5
1 is Not confident, 5 is Very confident
Which of the following are included in your hospital's risk management process? (Select all that apply)
*
Asset identification
Threat analysis
Vulnerability assessment
Risk mitigation planning
Monitoring and review
None of the above
Which best describes your hospital's approach to data backup and recovery?
*
Automated and regularly tested
Manual and occasionally tested
Ad-hoc and rarely tested
No formal backup process
Please provide any additional comments or concerns regarding your hospital's information security risks.
Submit Assessment
Should be Empty: