4-Attachment C H25-25-150 Information Technology Security Interrogative.pdf

PDF 83 KB Posted

Attached to
Electronic Health Record (EHR) Solution State and local contract opportunity
Solicitation number
H25-25-150
Issued by
Cook County, Illinois

About this file

This is an Information Technology Security Interrogative questionnaire for Cook County Health's Electronic Health Record (EHR) solution procurement in Illinois. The questionnaire is designed to evaluate vendor responses across multiple critical dimensions of system architecture, security, compliance, and operational capabilities. The document does not specify response dates, due dates, site visits, bidder's meetings, award dates, or contract terms, as it functions as a technical evaluation tool rather than a formal RFP notice.

The questionnaire comprises ten major evaluation categories encompassing 48 detailed questions addressing general system architecture and design, scalability and performance benchmarks, information security and regulatory compliance (including HIPAA and NIST standards), integration and interoperability with third-party applications, infrastructure and hosting requirements, maintenance support and upgrade protocols, disaster recovery and business continuity measures, data protection and privacy safeguards, cybersecurity insurance and liability coverage, and third-party vendor management practices. Vendors are required to demonstrate their EHR solution's capability to support end-to-end functionality across patient registration, clinical care, discharge, billing, and payment remittance while maintaining a single standardized instance across all Cook County Health facilities. No pricing terms, set-asides, incumbent information, or funding amounts are specified within this technical questionnaire document.

View the file

Other files for this state and local contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment C – Information Technology Security Interrogative

Architecture, Infrastructure & Information Security

Request for Proposal (RFP) Questionnaire

1. General Architecture & System Design

1. Please provide a high-level architectural overview of your solution, including key components and dependencies?

2. What design principles guide your system (e.g., modularity, redundancy, scalability)?

3. Does your system support cloud-native, on-premises, or hybrid deployments? Please elaborate on available options.

4. What are the primary technologies, frameworks, and programming languages used in your solution?

5. How does your solution ensure optimal performance and system resilience?

6. Explain your network security architecture and any perimeter defenses in place.

7. How do you monitor for and respond to security incidents or anomalies on your network?

8. Are there redundancy and failover mechanisms for critical systems?

2. Scalability & Performance

6. How does your system scale to accommodate increased demand (horizontal vs. vertical scaling)?

7. What are the system’s performance benchmarks under normal and peak load conditions?

8. What caching and optimization techniques are used to enhance performance?

9. Can your system operate in a distributed environment? How does it handle data replication and synchronization?

10. What are the system’s uptime guarantees, and what measures are in place for high availability?

3. Information Security & Compliance

11. How does your solution ensure data security at rest and in transit?

12. What industry security frameworks and regulations (e.g., HIPAA, NIST, ISO 27001, SOC 2) does your system comply with?

13. What authentication mechanisms are available (e.g., MFA, SSO, RBAC)?

14. How does your solution mitigate security threats such as DDoS attacks, ransomware, and insider threats?

15. What encryption standards are used for data protection, both in transit and at rest?

16. Does your platform provide security event monitoring and logging capabilities?

17. How does your system handle access control, including privileged account management?

18. Can you provide details on your incident response plan, including breach notification procedures?

19. How do you ensure vendor and third-party security compliance within your system?

20. How do you identify and mitigate security vulnerabilities in your systems and software?

21. What is your process for patch management and updates?

22. Can you provide a history of security incidents and resolutions?

23. What security training or awareness programs are in place for end users?

4. Integration & Interoperability

21. Does your solution support open APIs for seamless integration with third-party applications?

22. What protocols are available for data exchange (e.g., REST, SOAP, GraphQL)?

23. How does your system handle integration with legacy systems?

24. Can your platform support federated identity and single sign-on (SSO) with existing enterprise authentication systems?

25. What third-party systems have you successfully integrated with, and how is interoperability managed?

5. Infrastructure & Hosting

26. What are the minimum infrastructure requirements (CPU, RAM, storage, network) for deployment?

27. Can your solution be deployed in a virtualized environment or containerized using Docker/Kubernetes?

28. How does your solution optimize resource utilization to reduce infrastructure costs?

29. What redundancy and failover mechanisms are built into your infrastructure design?

30. Can your solution operate in a multi-cloud environment, and which cloud service providers are supported?

6. Maintenance, Support & Upgrades

31. How frequently do you release updates, and how are patches and upgrades managed?

32. What is your policy on backward compatibility with previous versions?

33. What level of support do you provide (e.g., 24/7 support, dedicated account manager)?

34. How do you handle system downtime or disruptions, and what are your SLAs for issue resolution?

35. What monitoring and logging capabilities are included to detect and troubleshoot system issues?

7. Disaster Recovery & Business Continuity

36. What disaster recovery (DR) strategies do you provide, and how frequently is DR tested?

37. Can you describe the backup and restore process, including Recovery Time Objective (RTO) and Recovery Point Objective (RPO)?

38. How does your system handle failover and continuity in the event of a major outage?

39. What are your data retention policies, and how do you ensure compliance with regulatory requirements?

40. What measures are in place to prevent and recover from ransomware or data corruption incidents?

8. Data Protection and Privacy:

41. How do you ensure the confidentiality, integrity, and availability of our sensitive data?

42. Do you have a data breach response plan in place, and can you provide details?

43. What measures do you have in place to comply with data protection regulations (HIPAA, Illinois Data Protection and Privacy Act)?

44. If you will have access to or will transmitting data how will the data be accessed and exchanged?

45. What are your data retention policies?

46. How are you protecting client data?

47. What are your data retention policies?

48. What are your data destruction policies?

9. Insurance and Liability:

a. Do you carry cybersecurity insurance, and what is the coverage?

b. What is your liability policy in the event of a security breach?

10. Third-Party Vendor Management:

a. Do you use third-party vendors for any security-related services, and how do you ensure their security practices meet your standards?

b. Can you provide a list of these vendors?

File details come from the government source that posted it. Updated .