0% found this document useful (0 votes)
94 views2 pages

Cloud Service Provider Security Questionnaire

This document is a cloud service provider questionnaire completed by [Cloud Provider] on [Date completed]. It addresses security requirements around general security, physical security, network security, and acknowledges that [Cloud Provider] will comply with these requirements in providing cloud services to the practice. The questionnaire requires information on the type of cloud service provided, security certifications, location of data centers, security controls, access controls, encryption of data, incident response and more.

Uploaded by

Lorenzo
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
94 views2 pages

Cloud Service Provider Security Questionnaire

This document is a cloud service provider questionnaire completed by [Cloud Provider] on [Date completed]. It addresses security requirements around general security, physical security, network security, and acknowledges that [Cloud Provider] will comply with these requirements in providing cloud services to the practice. The questionnaire requires information on the type of cloud service provided, security certifications, location of data centers, security controls, access controls, encryption of data, incident response and more.

Uploaded by

Lorenzo
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
  • General Security
  • Physical Security
  • Network Security

Practice Name

Cloud Service Provider Questionnaire


Cloud Provider
Business Associate
Date completed
Address:

Phone:
email:
Completed by

You are providing this service to us as a ☐ direct provider or as a ☐ reseller of the cloud service
provider.

Type of cloud service: ☐ IaaS ☐ SaaS ☐ PaaS

GENERAL SECURITY
☐ The service we are requesting involves electronic protected health information (ePHI) as well as
other personally identifiable information protected by various regulations.
☐ We will require you sign our Business Associate Agreement (BAA) as required by HIPAA.
☐ We will require verification of your established security program policies and procedures and we will
require that the policies and procedures meet the specific requirements of the HIPAA regulations. We
will also need a copy of your Disaster Recovery Plan to ensure alignment with ours.
☐ You must have full-time staff on-site at the host facility. All administrators and users must be
individually identified. All staff must be fully vetted by background screening and fully trained in HIPAA
prior to involvement with our account. We must be notified when any staff member working on our
account is terminated.
☐ We require that our data is on a private cloud segmented from any other customer that you may
have and we require that our service environment is using separate hosts, separate infrastructure or
other appropriate security controls to maintain segmentation. Please submit a full network diagram of
the Service Environment that clearly illustrates the relationship between our environment and any other
relevant networks. Please include a full data flowchart that details where our data resides.
☐ Please submit a diagram of the backup processes if you are conducting these on our behalf. Please
include details of the servers, location, encryption and media used. Log files of the backups will need to
be available to us upon request. Testing of the backups will be required on occasion.
☐ All vendor managed accounts will include strong password/passphrase and account controls,
including password/passphrase complexity requirements, change intervals and account
enabling/disabling processes in line with our password policy which we will make available to you.
☐ All data in transit and at rest must be encrypted using 256bit AES or better. The keys will be provided
to us in a secure manner upon inception.

☐ At the end of our contract, all data will be returned to us in a manner we agree upon. All media
containing our data must be destroyed prior to disposal. We will require a written destruction
certification if this service is provided by you.

March 2017
Practice Name
Cloud Service Provider Questionnaire

☐ You must have security incident response and breach notification policies and processes in place. In
the event of a security breach, we will require notification within 24 hours. This may change according
to specific state breach notification requirements.

PHYSICAL SECURITY
What type of certification has the data center obtained?
☐ SSAE16 ☐ SOC2 ☐ Other Date attained: _______________ ☐ None
Location of the primary site: ____________________ Secondary site: __________________________
☐ You must have policies and procedures in place to limit and log physical access to the data center.
We may require a copy for our records.

NETWORK SECURITY
☐ You must have current firewall technology in place to control access. We will require access to the
logs on occasion for auditing purposes.
☐ You must have IPS or IDS (Intrusion Prevention or Detection) in place systems in place. We will
require access to the logs on occasion for auditing purposes.
☐ The hosts and devices our data resides on must be hardened against attack and must be reviewed
for potential security enhancements on a regularly scheduled basis. We will require access to the logs
on occasion for auditing purposes.

☐ You must have a published security vulnerability and patch management program in place. We will
require access to the logs on occasion for auditing purposes.
☐ We reserve the right to perform external vulnerability scans without prior notice to ensure
compliance with these standards. The results of your most current security audits will also be requested.

☐ You must have current Anti-Malware software in use. We will require access to the logs on occasion
for auditing purposes.
☐ All vendor access must be authenticated using a published process that we agree to. Every access
must be individually identifiable. Log files of all access will be available to us upon request.
☐ Internal and external vulnerability assessments will be performed for the explicit purposes of finding
and remediating security vulnerabilities. We will require access to the logs on occasion for auditing
purposes.

Signed and acknowledged: ______________________________________Date: ____________________

March 2017

Common questions

Powered by AI

Maintaining a disaster recovery plan is significant for cloud service providers as it ensures business continuity and data protection during unforeseen events. Such a plan should align with client expectations and include strategies for data backup, emergency response, and recovery procedures. It should detail coordination with the client's disaster recovery plan and demonstrate compliance with regulatory requirements, ensuring resilience against data loss or downtime.

To manage physical access to data centers, providers must have policies and procedures that limit and log access. These logs should be available to the clients upon request for auditing purposes. Additionally, providers should maintain certifications such as SSAE16 or SOC2 to demonstrate compliance with industry standards in physical security.

A cloud service provider must have established security incident response and breach notification policies that include notifying affected parties within 24 hours of a security breach, with adjustments based on specific state requirements. They are required to provide these policies and processes to assure clients of their readiness and compliance with necessary regulations. This ensures timely action and communication in case of data breaches.

A cloud service provider ensures HIPAA compliance by signing a Business Associate Agreement (BAA) to confirm adherence to regulations. Additionally, they need to verify established security program policies and procedures that meet HIPAA-specific requirements. The provider must also provide a disaster recovery plan aligned with client requirements and ensure all employees are HIPAA trained and vetted. Furthermore, the service environment must be on a private, segmented cloud, and all data must be encrypted at rest and in transit with 256bit AES or better. Finally, a written destruction certification is required for data at the contract's end.

Regular security audits and vulnerability assessments are important for cloud service providers as they help identify potential security weaknesses and ensure compliance with security policies and regulations. These assessments foster proactive measures to mitigate threats and enhance security protocols, thereby ensuring data protection and minimizing risk to their clients. Clients require access to the results of these audits to verify ongoing compliance and responsiveness to evolving threats.

The segmentation of storage infrastructure is crucial in cloud services as it prevents co-mingling of data and enhances security by isolating client data from other customers. This segregation reduces the risk of unauthorized access and potential breaches, ensuring that sensitive data such as ePHI remains within a controlled, dedicated environment. Such an approach aligns with compliance requirements and reassures clients of data integrity and security.

Key components of network security measures for cloud service providers include current firewall technology to control access and IPS/IDS systems for intrusion detection and prevention. Hosts and devices must be hardened against attacks and regularly reviewed for enhancements. A published security vulnerability and patch management program is necessary. Providers are also required to authenticate all vendor access and perform regular internal and external vulnerability assessments, with access to associated logs for auditing purposes. Additionally, there's a right reserved by the client to perform external vulnerability scans.

Business Associate Agreements (BAAs) are crucial for cloud service providers managing ePHI as they legally bind the providers to adhere to HIPAA regulations. BAAs outline the responsibilities and obligations regarding security and privacy, ensuring that the provider has adequate policies to protect ePHI. They are essential in defining the provider's role in compliance, accountability, and liability concerning HIPAA requirements.

Log access enhances the transparency and accountability of a cloud service provider's security practices by allowing clients to audit logs related to firewall activity, intrusion prevention/detection systems, access control, malware protection, and network vulnerabilities. By ensuring these logs are available, clients can verify that security measures are adequately implemented and maintained, fostering trust and compliance with security standards.

For managing sensitive information, a cloud service provider must encrypt all data in transit and at rest using at least 256bit AES encryption. Additionally, the encryption keys must be provided to the client securely upon inception of the service. This level of encryption ensures that the data is adequately protected against unauthorized access and complies with standard security requirements.

Practice Name
Cloud Service Provider Questionnaire
Cloud Provider
Business Associate
Date completed
Address:
Phone:
email:
Co
Practice Name
Cloud Service Provider Questionnaire
☐  You must have security incident response and breach notification polici

You might also like