← Resources · Reviewed 2026-09-28

What should a physician owner ask their MSP?

Keep the provider you trust. Add an independent list of questions so “we’re patched” becomes evidence you can file.

  1. Is MFA required for email, EMR, and remote access for every user, including physicians?
  2. Which devices can reach patient information, and are they encrypted?
  3. When was the last documented restore test, and what failed?
  4. Which remote-access tools are installed, and who can approve vendor logins?
  5. Which AI tools are approved for clinic use, and where does data go?

Product demonstration

CyberHealth lets you invite your MSP into a permission-limited role: see shared findings, upload evidence, remediate without changing KCC’s independent conclusion.

Build my question list