{"id":25993,"date":"2020-12-10T17:40:00","date_gmt":"2020-12-10T17:40:00","guid":{"rendered":"https:\/\/www.syscreations.ca\/blog\/?p=25993"},"modified":"2020-12-21T09:13:24","modified_gmt":"2020-12-21T09:13:24","slug":"healthcare-cybersecurity-checklist","status":"publish","type":"post","link":"https:\/\/www.syscreations.ca\/blog\/healthcare-cybersecurity-checklist\/","title":{"rendered":"Vendor Risk Management Checklist for Healthcare Entities, i.e., Hospitals and Healthcare Startups, i.e., Telehealth Apps"},"content":{"rendered":"\n<p><span style=\"color: #000000;\"><span style=\"font-weight: 400;\">Often, the use of service providers and IT suppliers creates an <\/span><span style=\"font-weight: 400;\">unacceptable potential for operational disruption and puts ePHI security at risk.&nbsp;<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">Thus, it is worth carrying out a vendor security assessment to ensure healthcare cybersecurity.&nbsp;<\/span><\/p>\n<h1><span style=\"color: #000000; font-size: x-large;\"><b>Questionnaire for selecting \u2018secure\u2019 vendor: <\/b><b>Vendor security assessment checklist<\/b><\/span><\/h1>\n\n<p><span style=\"color: #000000;\"><i>Dear IT vendors, this is important to you because healthcare entities would ask the following questions before purchasing your service or product.<\/i><\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>1) Risk Assessment and Treatment&nbsp;<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Does your organization have any risk assessment program? If yes, would you please describe it?&nbsp;<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>2) Security Policy&nbsp;<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have an information security policy and procedure? If yes, are you making it available to your clients and employees?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you notify the clients when you make any material changes to it?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a physical security program?&nbsp;&nbsp;<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>3) Organization of Information Security<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a Chief Privacy Officer (CPO) in your organization?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have an information security function responsible for security initiatives within the organization?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you define and document security roles and responsibilities for employees in accordance with the organization\u2019s information security policy?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you provide clients with documentation on how you maintain segregation of duties within your environment?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have established policies and procedures and implemented measures to strictly limit access to sensitive data from portable and mobile devices, such as laptops, cell phones, tablets, and personal digital assistants (PDAs)?&nbsp;<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>4) Human Resources Security&nbsp;<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you carry out background checks on applicants? If yes, do background checks include criminal, credit, professional\/academic, references, and drug screening?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you provide an information security awareness training program to employees?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a disciplinary process for non-compliance with information security policy, and are employees aware of the consequences for non-compliance?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have an employee termination or change of status process?<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>5) Asset Management<br><\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have an asset management program?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a fair use policy that restricts the way employees are using the network, website, and system?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you classify all information assets according to their level of confidentiality, sensitivity, value, and criticality?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you prohibit the use of removable media such as disk drives, USB devices?&nbsp;<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>6) Access Control&nbsp;<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you restrict access to systems with shared network infrastructure in accordance with security policies, procedures, and standards?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do networks shared with external entities have a documented plan detailing the compensating controls used to separate network traffic between organizations? (e.g., VLAN)<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you follow the process to make sure the accountability for generic\/shared IDs?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have information security management systems such as hypervisors, firewalls, vulnerability scanners, network sniffers, APIs? If yes, do you restrict, log, and monitor access to these systems?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you require strong passwords to interact with systems?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you require multi-factor authentication for all remote access?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you review the access regularly to ensure that access is only granted to authorized users?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you record all remediation and certification actions when users are found to have inappropriate entitlements?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Will you share user entitlement remediation and certification reports with us if inappropriate access may have been allowed to our data?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you support identity federation standards (SAML, SPML, WS-Federation, etc.)?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a mechanism to prevent unauthorized access?&nbsp;<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>7) Cryptography&nbsp;<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you manage and maintain encryption tools?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you encrypt client data on disk\/storage within your environment?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you use encryption to protect data and virtual machine images during transport across and between networks and hypervisor instances?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have the capability to manage encryption keys on behalf of clients?<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>8) Physical and Environmental Security&nbsp;<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a security mechanism to keep data safe in data centers? If yes, would you please describe?&nbsp;<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>9) Operation Security&nbsp;<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a set of basic security objectives that must be met by every component of your infrastructure (server, firewalls, operating systems, routers, DNS servers, etc.)?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you document and maintain operating procedures or SOP? If yes, do you make users aware of it?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a formal operational change management\/change control process?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you review system resources to ensure sufficient capacity is maintained?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you isolate sensitive data by logically separating system and network environments?&nbsp;<\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"font-weight: 400;\">\u274f Do you use antivirus and anti-malware products?<\/span> <span style=\"font-weight: 400;\">&nbsp;<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you perform system backups?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do your security information and event management (SIEM) system merge data sources (app logs, firewall logs, IDS logs, physical access logs, etc.) for granular analysis and alerting?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you restrict physical and logical user access to audit logs?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you conduct regular external audits as prescribed by industry best practices and guidance?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you perform periodic assessments of your environment (SSAE 16, ISO27001, Third Party audits)?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you patch all systems and applications?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you update the signatures, lists, or behavioural patterns of the security threat systems?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you perform regular vulnerability tests (internal\/external) on all applications, networks, operating systems?<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>10) Communication Security&nbsp;<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Does your wireless network use secure authentication?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a mechanism to restrict unauthorized traffic?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have established controls in place to protect client data stored via cloud services?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you require non-disclosure agreements?<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>11) Systems Acquisition, Development, and Maintenance<\/b> <span style=\"font-weight: 400;\">&nbsp;<\/span><\/span><\/h3>\n\n<p><span style=\"color: #000000;\">\u274f Do you provide open encryption methodologies (3DES, AES, etc.) to clients in order for them to protect their data if it is required to traverse public networks (e.g., the Internet) or if your infrastructure components need to communicate to each other over public networks?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you implement data input and output integrity routines (i.e., reconciliation and edit checks) for application interfaces and databases to prevent manual or systematic processing errors or data corruption?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you use an automated source-code analysis tool to discover code security defects before production?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you and your software suppliers adhere to industry standards for Systems\/Software Development Lifecycle (SDLC) security?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have established criteria for accepting new information systems, upgrades, and new versions?&nbsp;<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>12) Supplier Relationships&nbsp;<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you monitor and track third-parties who access our data?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you restrict third-party vendors such as backup vendors, service providers, equipment support vendors from accessing our data?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do your sign agreements with service providers and third-parties that require them to adhere to your information security and privacy policies?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Does legal counsel review all Third Party agreements?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a vendor selection process to evaluate vendor security controls regarding data security, reliability, and performance?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you select and monitor outsourced providers in compliance with laws in the country where the data is processed, stored, and transmitted?<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>13) Information Security Incident Management<\/b><\/span><\/h3>\n\n<p><span style=\"color: #000000;\">\u274f Do you have an incident management program? If yes, would you please describe?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you document roles and responsibilities, specifying what you and your clients are responsible for during security incidents?<\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"font-weight: 400;\">\u274f Do you implement file integrity (host) and network intrusion detection (IDS) tools to help facilitate timely detection, the investigation by root cause analysis, and response to incidents?<\/span> <span style=\"font-weight: 400;\">&nbsp;<\/span><\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>14) Information Security Aspects of Business Continuity Management<\/b><span style=\"font-weight: 400;\"><br><\/span><\/span><\/h3>\n\n<p><span style=\"color: #000000;\">\u274f Do you have a Business Continuity\/Disaster Recovery (BC\/DR) program? If yes, is it tested?&nbsp;<\/span><\/p>\n<h3><span style=\"color: #000000;\"><b>15) Compliance&nbsp;<\/b><\/span><\/h3>\n\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you conduct regular internal audits as prescribed by applicable federal and state laws?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have regulatory bodies that supervise the company?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do your information security and privacy policies align with particular industry standards (ISO27001, CoBIT, ITIL, etc.)?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have a records retention policy?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have documented policies or procedures to ensure that our data is only collected, stored, and used for the purposes it was collected?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have written procedures to process our questions, complaints, and requests to access, correct, and delete data?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have appropriate administrative, physical, and technical safeguards to protect privacy data in accordance with all privacy applicable laws?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have documented procedures to notify us if there is any data breach incident?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have internal or third-party review procedures to verify compliance with privacy applicable law, policy, and practice prior to establishing a business relationship?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you instruct employees and third-parties to immediately notify the appropriate individual in the organization if our data has been lost, accessed by, used by, or disclosed to unauthorized third-parties?&nbsp;<\/span><\/p>\n<p><span style=\"color: #000000;\"><span style=\"font-weight: 400;\">\u274f Do you provide formal privacy training to employees and third-party service providers who may access and use our private data?<\/span> <span style=\"font-weight: 400;\">&nbsp;<\/span><\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have documented breach notification procedures? If yes, does it ensure that we get notified immediately when a data breach occurs?&nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you review your policies and procedures at least every 12 months?<\/span><\/p>\n<p><span style=\"font-weight: 400; color: #000000;\">\u274f Do you have an independent audit function within the organization?&nbsp;<\/span><\/p>\n<h2><span style=\"color: #000000;\"><b>Yes, the assessment for healthcare entities and policy-making for IT vendors are tedious tasks. Thus, we helped both.<\/b><\/span><\/h2>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"color: #000000;\"><b>If you&#8217;re a healthcare entity<\/b><span style=\"font-weight: 400;\">, we help you save time and efforts by executing vendor risk management on behalf of your team and deploy an entire ecosystem to ensure ePHI security.&nbsp;<\/span><\/span><\/li>\n<li><span style=\"color: #000000;\"><b>If you\u2019re IT vendors including healthcare app owners<\/b><span style=\"font-weight: 400;\">, we help you document policies and procedures within a month. (Following is the real project timeline we\u2019re currently working on.)<\/span><\/span><\/li>\n<\/ul>\n<center><img loading=\"lazy\" class=\"aligncenter wp-image-25467\" style=\"width: 90%; height: 90%;\" src=\"https:\/\/www.syscreations.ca\/blog\/wp-content\/uploads\/2020\/12\/image1.jpg\" alt=\"\" width=\"100%\" height=\"100%\"><\/center>\n","protected":false},"excerpt":{"rendered":"<p>Often, the use of service providers and IT suppliers creates an unacceptable potential for operational disruption and puts ePHI security at risk.&nbsp; Thus, it is worth carrying out a vendor security assessment to ensure healthcare cybersecurity.&nbsp; Questionnaire for selecting \u2018secure\u2019 vendor: Vendor security assessment checklist Dear IT vendors, this is important to you because healthcare [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":25995,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[12],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v16.1.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Vendor Risk Management Checklist for Healthcare Entities, Startups<\/title>\n<meta name=\"description\" content=\"Here, we are sharing an exclusive vendor risk management checklist, which is helpful for hospitals, nursing homes, telehealth app owners to ensure healthcare cybersecurity.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.syscreations.ca\/blog\/healthcare-cybersecurity-checklist\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vendor Risk Management Checklist for Healthcare Entities, Startups\" \/>\n<meta property=\"og:description\" content=\"Here, we are sharing an exclusive vendor risk management checklist, which is helpful for hospitals, nursing homes, telehealth app owners to ensure healthcare cybersecurity.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.syscreations.ca\/blog\/healthcare-cybersecurity-checklist\/\" \/>\n<meta property=\"og:site_name\" content=\"SyS Creations - IT Management, Compliance &amp; Consulting Company in Canada\" \/>\n<meta property=\"article:published_time\" content=\"2020-12-10T17:40:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-12-21T09:13:24+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.syscreations.ca\/blog\/wp-content\/uploads\/2020\/12\/Blog-37-10-12-20.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1140\" \/>\n\t<meta property=\"og:image:height\" content=\"554\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\">\n\t<meta name=\"twitter:data1\" content=\"8 minutes\">\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#website\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/\",\"name\":\"SyS Creations - IT Management, Compliance &amp; Consulting Company in Canada\",\"description\":\"SyS Creations - IT Management, Compliance &amp; Consulting Company in Canada\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/www.syscreations.ca\/blog\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/healthcare-cybersecurity-checklist\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/wp-content\/uploads\/2020\/12\/Blog-37-10-12-20.jpg\",\"contentUrl\":\"https:\/\/www.syscreations.ca\/blog\/wp-content\/uploads\/2020\/12\/Blog-37-10-12-20.jpg\",\"width\":1140,\"height\":554,\"caption\":\"Vendor Risk Management Checklist for Healthcare Entities, i.e., Hospitals and Healthcare Startups, i.e., Telehealth Apps\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/healthcare-cybersecurity-checklist\/#webpage\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/healthcare-cybersecurity-checklist\/\",\"name\":\"Vendor Risk Management Checklist for Healthcare Entities, Startups\",\"isPartOf\":{\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.syscreations.ca\/blog\/healthcare-cybersecurity-checklist\/#primaryimage\"},\"datePublished\":\"2020-12-10T17:40:00+00:00\",\"dateModified\":\"2020-12-21T09:13:24+00:00\",\"author\":{\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#\/schema\/person\/58a4199dfaf1c035175e61bd9021fad3\"},\"description\":\"Here, we are sharing an exclusive vendor risk management checklist, which is helpful for hospitals, nursing homes, telehealth app owners to ensure healthcare cybersecurity.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.syscreations.ca\/blog\/healthcare-cybersecurity-checklist\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.syscreations.ca\/blog\/healthcare-cybersecurity-checklist\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/healthcare-cybersecurity-checklist\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"item\":{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"position\":2,\"item\":{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/healthcare-cybersecurity-checklist\/\",\"url\":\"https:\/\/www.syscreations.ca\/blog\/healthcare-cybersecurity-checklist\/\",\"name\":\"Vendor Risk Management Checklist for Healthcare Entities, i.e., Hospitals and Healthcare Startups, i.e., Telehealth Apps\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#\/schema\/person\/58a4199dfaf1c035175e61bd9021fad3\",\"name\":\"test@test.com\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.syscreations.ca\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b642b4217b34b1e8d3bd915fc65c4452?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b642b4217b34b1e8d3bd915fc65c4452?s=96&d=mm&r=g\",\"caption\":\"test@test.com\"},\"sameAs\":[\"http:\/\/localhost\/syscreations_blogs\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/posts\/25993"}],"collection":[{"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/comments?post=25993"}],"version-history":[{"count":4,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/posts\/25993\/revisions"}],"predecessor-version":[{"id":26028,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/posts\/25993\/revisions\/26028"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/media\/25995"}],"wp:attachment":[{"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/media?parent=25993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/categories?post=25993"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.syscreations.ca\/blog\/wp-json\/wp\/v2\/tags?post=25993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}