You are on page 1of 12

RegulatoryComplianceSoftwareandSolutions

http://www.leapcompliance.comcorporate@leapcompliance.com
FORM010CHACTREV0110B
PAGE1OF12

INFORMATIONSYSTEMSASSESSMENT
HIPAASecurity,HIPAAPrivacyandHIPAAHITECH


THIS ASSESSMENT SHOULD BE COMPLETED BY LEAP PERSONNEL USING A TABLET OR LAPTOP COMPUTER AND MOBILE INTERNET
CONNECTIONVIAHTTP://WWW.LEAPCOMPLIANCE.COM/IT/SECURITY/ASSESSMENT.ASPX.IFNOINTERNETCONNECTIONISAVAILABLEOR
THESITEASSESSMENTURLISOFFLINE,USETHISWORKSHEET.

DATE ASSESSMENTID SECA-HT-

SiteInformation
BUSINESSNAME

PRIMARYCONTACT

STREETADDRESS

MAILINGADDRESS

CITY,STATE,ZIP

CONTACTEMAIL

CONTACTPHONE

CONTACTFAX

DESCRIBESITE

OTHER

Section1:InformationSystemInventoryandOverview

TABLE1A:WORKSTATIONS
QUANTITY BRAND MODEL WIRELESS WIRED BOTH O/S DETAILS/NOTES










RegulatoryComplianceSoftwareandSolutions
http://www.leapcompliance.comcorporate@leapcompliance.com
FORM010CHACTREV0110B
PAGE2OF12

Question11:

AT THIS SITE, IF THERE ARE MULTIPLE


COMPUTER WORKSTATIONS, ARE THE
WORKSTATIONS CONNECTED USING A LOCAL
AREANETWORK?
YES NO

Question12:

IF RESPONSE TO 21 WAS YES, IS THERE A


WIRELESS NETWORK USED TO CONNECT THE
WORKSTATIONS?
YES NO

Question13:

ARE LAPTOPS, TABLET PCs,IPHONES, PDAs OR


ANY OTHER DEVICES CONNECTED TO THE
NETWORKANDTHENTAKENOFFSITE?
YES NO

Question14:

IF ANSWER TO QUESTION 23 WAS YES, ARE


XRAYS OR ANY TYPE OF PATIENT
INFORMATION STORED ON LAPTOPS, TABLET
PCsORSIMILARDEVICES?
YES NO

IFTHEREPONSETOQUESTION13WASYES,COMPLETETABLE1B:

TABLE1B:LAPTOPS/TABLETPCs/MOBILEDEVICES
QUANTITY BRAND MODEL WIRELESS WIRED BOTH O/S NOTES






Question15:

ARE PORTABLE FLASH MEMORY, DONGLE,


HARD DISK, CD/DVD OR ANY OTHER TYPE OF
MEDIA/DEVICES USED TO STORE, TRANSPORT
OR COPY DATA TO/FROM THE NETWORK,
WORKSTATIONSORSERVER?
YES NO

Question16:

IF THE ANSWER TO QUESTION 15 WAS YES,


ARE XRAYS, PATIENT DATA OR PATIENT
IDENTIFIABLE DATA STORED/TRANSPORTED
ONTHESETYPESOFDEVICES?
YES NO

TABLE1C:SERVER(S)
QUANTITY BRAND MODEL WIRELESS WIRED BOTH O/S SERVICEPACK


RegulatoryComplianceSoftwareandSolutions
http://www.leapcompliance.comcorporate@leapcompliance.com
FORM010CHACTREV0110B
PAGE3OF12

Section2:LocalConnectivity

IFTHEANSWERTOQUESTION11WASNO,SKIPTOSECTION3OFTHISDOCUMENT

Question21:

ISTHEREAROUTERORSWITCH(ORMULTIPLE
ROUTERS/SWITCHES) UTILIZED ON THE LOCAL
AREANETWORK?
YES NO

IFTHEREPONSETOQUESTION21WASYES,COMPLETETABLE2A:

TABLE2A:ROUTERS/SWITCHES
ID BRAND MODEL WIRELESS WIRED BOTH
INTERNET
CONNECTED
LANIPRANGE
1

2

3

Question22:

IF WIRELESS NETWORK PRESENT, IS AN


ENCRYPTION PROTOCOL ENABLED FOR THE
WIRELESSNETWORK(I.E.WPA,WEP,ETC.)?
YES NO

IFTHEREPONSETOQUESTION22WASYES,COMPLETETABLE2B:

TABLE2B:WIRELESSENCRYPTIONPROTOCOLS
ROUTERID ENCRYPTIONPROTOCOL(WPA,WPA2,WEP64,WEP128,ETC.)
1

Question23:

IF THE LAN IS CONNECTED TO THE INTERNET,


IS N.A.T. (NETWORK ADDRESS TRANSLATION)
USED FOR THE LOCALLY CONNECTED
WORKSTATIONSONTHENETWORK?
YES NO

Question24:

ISANETWORKFIREWALLENABLED(WHETHER
SOFTWARE BASED (ISA SERVER) OR
HARDWARDBASED(ROUTER)?
YES NO

Question25:

DO WORKSTATIONS CONNECT VIA PHYSICAL


WIRETOTHELOCALAREANETWORK(WIRED
NETWORK)?
YES NO

RegulatoryComplianceSoftwareandSolutions
http://www.leapcompliance.comcorporate@leapcompliance.com
FORM010CHACTREV0110B
PAGE4OF12

ON ANY WORKSTATION CONNECTED TO THE LOCAL AREA NETWORK, OPEN CONTROL PANEL,
NETWORKING, RIGHT CLICK ON EACH ACTIVE ADAPTER (IF MORE THAN ONE) AND IDENTIFY EACH
NETWORKING PROTOCOL THAT IS ENABLED OR MARKED ACTIVE. EXAMPLES OF COMMUNICATION
PROTOCOLS YOU WILL SEE IN THE ADAPTERS PROPERTY LIST ARE: TCP/IP (V 4/6), NETBIOS, IPX/SPX,
ATM,ETC.).

TABLE2C:ACTIVELANCOMMUNICATIONPROTOCOLS
PROTOCOLID COMMUNICATIONPROTOCOLS(TCP/IPV4ORV6,IPX/SPX,NETBIOS,APPLETALK,ETC.)
1

Question26:

]IS TCP/IP PROTOCOL ENABLED AND ACTIVE


ON THE LOCAL AREA NETWORK (TCP/IP
VERSION4ORVERSION6)?
YES NO

Question27:

IF THE ANSWER TO QUESTION 27 WAS YES,


IS IPSEC ENABLED ON THE LOCAL AREA
NETWORK FOR EACH TCP/IP PROTOCOL
ENABLEDONTHENETWORK?
YES NO

Question28:

IFAWIRELESSNETWORKISPRESENT,HASTHE
WIRELESS ROUTER BEEN CONFIGURED TO
ALLOW ACCESS ONLY WHEN A DEVICES MAC
ADDRESSISINCLUDEDONALIST/TABLE?
YES NO

Question29:

IS EACH ROUTER/SWITCH LOCATED IN A


SECURED OR LOCKED LOCATION PROTECTED
BY KEY, DIGITAL CODE OR OTHER
MECHANISM?
YES NO

Question210:

DO ANY OF THE ROUTERS/SWITCHES HAVE


EASILY ACCESSIBLE SETTING RESET
BUTTONS THAT COULD BE
ACTUATED/PRESSED BY AN UNAUTHORIZED
INDIVIDUAL?
YES NO

Question211:

HAS THE PASSWORD USED TO ACCESS


ROUTERCONFIG.BEENCHANGEDFROMTHE
DEFAULTSETBYTHEROUTERMFG?
YES NO

RegulatoryComplianceSoftwareandSolutions
http://www.leapcompliance.comcorporate@leapcompliance.com
FORM010CHACTREV0110B
PAGE5OF12
Section3:External/InternetConnectivity

Question31:

IS THE SITE CONNECTED TO THE INTERNET?


(INCLUDES: DSL, CABLE MODEM, G3/G4
DEVICE,PHONEMODEM,SATELLITE,ETC.)
YES NO

IFTHEANSWERTOQUESTION31WASNO,SKIPTOSECTION7OFTHISDOCUMENT

TABLE3A:INTERNETSERVICEPROVIDERS
ISPID NAMEOFISP(I.E.COX,COMCAST,CLEAR,AT&T,ETC.) STATICIP(IFAPPLICABLE)
1

2

3

Question32:

ISTHETYPEOFSERVICEPROVIDEDBYTHEISP
DELIVERED VIA A WIRELESS SIGNAL OR
CONNECTION>(SATELLITE,WIRELESSMODEM)
YES NO

Question33:

IS THE INTERNET CONNECTION DEVICE (CABLE


OR DSL MODEM, WIRELESS DEVICE, ETC.)
CONNECTEDTOAROUTER?
YES NO

Question34:

IF ANY WORKSTATION USES ANY VERSION OF


MICROSOFT WINDOWS, IS INTERNET
CONNECTION SHARING ENABLED ON ANY OF
THEWORKSTATIONS(INCLUDINGLAPTOPS)?
YES NO

Question35:

IF APPLICABLE, DOES ANY ROUTER


CONNECTED TO THE INTERNET HAVE THE
REMOTEROUTERCONFIG.OPTIONENABLED?
YES NO

Question36:

IFAPPLICABLE,ISEVERYROUTERCONNECTED
TO THE INTERNET SET TO DENY INBOUND
CONNECTION REQUESTS ON PORTS 80, 443,
8080ANDOTHERWELLKNOWNPORTS?
YES NO

Question37:

IFAPPLICABLE,AREALLROUTERSSETTODENY
INBOUND FILE TRANSFER PROTOCOL? (FTP
GENERALLYUSESPORT21)
YES NO

Question38:

DOES ANY WORKSTATION USING MICROSOFT


WIN 2000 OR HIGHER HAVE THE INTERNET
INFORMATIONSERVICEENABLED/ACTIVE?
YES NO

RegulatoryComplianceSoftwareandSolutions
http://www.leapcompliance.comcorporate@leapcompliance.com
FORM010CHACTREV0110B
PAGE6OF12

Question39:

DOES ANY APPLE OS/X OR HIGHER


WORKSTATION HAVE APPLES OR ANY THIRD
PARTYSWEBSERVERSOFTWAREENABLED?
YES NO

Question310:

DOES ANY LINUX WORKSTATION HAVE


APACHE, MAIL SERVER OR THIRD PARTY
WEBSERVERSOFTWAREENABLED?
YES NO

Question311:

IS ANY WORKSTATION (DESKTOP, LAPTOP,


PDA OR SIMILAR DEVICE) SET TO ALLOW
EXTERNAL, REMOTE ACCESS CONNECTION?
(REMOTEDESKTOP,ETC.)
YES NO

Question312:

IF THE ANSWER TO QUESTION 311 WAS


YES, IS THE ROUTER SET TO FORWARD
EXTERNAL REMOTE ACCESS REQUESTS TO
SPECIFICSTATION(S)ONTHEINTERNALLAN?
YES NO

Section4:VirtualPrivateNetworking

Question41:

HASTHEROUTER,SERVEROROTHERDEVICE
BEEN CONNECTED TO THE LAN TO ALLOW
EXTERNAL (WAN) CONNECTIVITY VIA
VIRTUALPRIVATENETWORK?(PPTP,ETC.)
YES NO

IFTHEANSWERTOQUESTION41WASNO,SKIPTOSECTION5OFTHISDOCUMENT

Question42:

IF A VIRTUAL PRIVATE NETWORK SYSTEM


EXISTS, IS VPN ACCESS SECURED BY LOGIN
NAMEANDPASSWORD?
YES NO

Question43:

IFTCP/IPISUSEDONCETHEVPNTUNNELIS
ESTABLISHED AND USER AUTHENTICATED,
ARE THE IP PACKETS ENCRYPTED USING
IPSECORSIMILARENCRYPTION?
YES NO

Question44:

DOES THE SOFTWARE OR HARDWARE VPN


PROVIDER/DEVICE LOG AND TRACK VPN
LOGINS,USEANDLOGINATTEMPTS?
YES NO

Question45:

AREANYSERVERDRIVES,STORAGEDEVICES,
PORTABLE STORAGE DEVICES AND/OR
WORKSTATION DRIVES FILE SHARED FOR
READ/COPY/LIST ACCESS BY REMOTE VPN
USERS?
YES NO

Question46:

ARE RAW PROTECTED HEALTH INFO. FILES


AND/OR DATABASES SECURED TO PREVENT
COPYINGTOREMOTEVPNUSERS?
YES NO

RegulatoryComplianceSoftwareandSolutions
http://www.leapcompliance.comcorporate@leapcompliance.com
FORM010CHACTREV0110B
PAGE7OF12

Section5:EMailandWebmailCommunications

Question51:

DOES ANY STATION/DEVICE AT THE SITE


HAVETHEABILITYTOSEND/RECEIVEEMAIL
ORWEBMAILMESSAGES?
YES NO

IFTHEANSWERTOQUESTION51WASNO,SKIPTOSECTION6OFTHISDOCUMENT

TABLE5A:EMAILSERVICEPROVIDERS
PROVIDERID NAMEOFPROVIDER(AOL,MSN,COX,ETC.) NOTES
1

2

3

Question52:

IS A THIRD PARTY CERTIFICATE PROVIDER


SECURITY CERTIFICATE USED TO
AUTHENTICATEEMAILSSENT?
YES NO

Question53:

IS A COMPLEX, MINIMUM 128BIT


ENCRYPTION METHOD USED TO ENCRYPT
ANY OUTBOUND EMAIL THAT INCLUDES
PROTECTEDHEALTHINFORMATION?
YES NO

Question54:

IS THERE ANY BLOCKING MECHANISM THAT


PREVENTS THE USE OF WEBMAIL OR
PERSONAL EMAIL TO SEND UNENCRYPTED
P.H.I.?
YES NO

TABLE5B:THIRDPARTYEMAILPROTECTION/SECURITYSOFTWARE(IFINSTALLEDANDENABLED)
PROVIDERID NAMEOFEMAILSECURITYSOFTWARE(I.E.TUMBLEWEED) VERSION
1

2

Question55:

DOES THE SITE HAVE A WRITTEN POLICY


PROVIDED TO EACH SITE USER REGARDING
EMAILUSE,PRIVACYANDSECURITY?
YES NO

Question56:

DOES THE SITE HOST ITS OWN EMAIL, POP


OR SMTP SERVER? (EXCHANGE SERVER OR
SIMILARSOFTWARE)
YES NO

RegulatoryComplianceSoftwareandSolutions
http://www.leapcompliance.comcorporate@leapcompliance.com
FORM010CHACTREV0110B
PAGE8OF12

Section6:Web,HTML/HTTPSecurity

Question61:

DOES ANY WORKSTATION, PDA OR OTHER


DEVICECONNECTEDTOTHELANORSERVER
STORINGP.H.I.ALLOWUSERWEBACCESS?
YES NO

IFTHEANSWERTOQUESTION61WASNO,SKIPTOSECTION7OFTHISDOCUMENT

Question62:

CAN ANY WORKSTATION ALLOWING USER


WEB ACCESS INITIATE ANY HTTP POST OF
STOREDFILES/DATATOAREMOTESERVER?
YES NO

Question63:

IS ANY MECHANISM (HARDWARE OR


SOFTWARE)ENABLEDTHATBLOCKS,TRACKS
OR OTHERWISE CONTROLS/PREVENTS THE
POSTING/SENDING OF P.H.I. WITHOUT AN
HTTPS/SSLCONNECTION?
YES NO

Question64:

DOES THE SITE HAVE EITHER SERVER BASED


OR WORKSTATION INSTALLED ANTIVIRUS
AND/OR INTERNET PROTECTION SOFTWARE
INSTALLED?
YES NO

Question65:

DOES THE SITE HAVE AN UP TO DATE AND


ACTIVE SUBSCRIPTION TO A REPUTABLE
ANTIVIRUSDEFINITIONUPDATESERVICE?
YES NO

Question66:

IS ANY SITE ROUTER CONNECTED TO THE


INTERNETSETTOBLOCKKNOWNSITESAND
SERVICES THAT COULD POTENTIALLY
COMPROMISELOCALLYSTOREDP.H.I.?
YES NO

Question67:

DOES THE SITE HOST ITS OWN PUBLICALLY


ACCESSIBLE WEBSITE, WEB SERVICE OR
HTTP/HTMLBASEDAPPLICATION?
YES NO

Question68:

IF THE ANSWER TO QUESTION 67 WAS


YES, DOES THE SITE HAVE A VALID SSL
CERTIFICATE AND REQUIRE HTTPS/SSL
ACCESSWHENP.H.I.ISTRANSMITTED?
YES NO

Question69:

IF THIRD PARTY BILLING/CLEARNINGHOUSE


IS USED BY SITE, IS ALL P.H.I. TRANSMITTED
USINGSSLOROTHERWISEAPPROVEDLEVEL
OFDATAENCRYPTION?
YES NO

RegulatoryComplianceSoftwareandSolutions
http://www.leapcompliance.comcorporate@leapcompliance.com
FORM010CHACTREV0110B
PAGE9OF12

Section7:WorkstationLogin,AccessandControl

Question71:

DOES EVERY COMPUTER USER HAVE A


UNIQUE LOGIN NAME AND PASSWORD
THAT MUST BE ENTERED BEFORE NETWORK
ORWORKSTATIONISGRANTED?
YES NO

Question72:

ARE THE WORKSTATIONS ON THE LOCAL


NETWORK CONNECTED TOGETHER USING A
PEERTOPEERTYPENETWORK?
YES NO

Question73:

ARE THERE ANY WORKSTATIONS ON THE


NETWORKTHATUSEMICROSOFTWINDOWS
95,98,MEORNT4?
YES NO

Question74:

ARE THERE ANY WORKSTATIONS ON THE


NETWORK THAT USE AN APPLE OPERATING
SYSTEMBELOWVERSIONOSX?
YES NO

Question75:

DO LOGIN PASSWORDS MEET MINIMUM


PASSWORD COMPLEXITY REQUIREMENTS?
(UPPERCASE LETTER, LOWERCASE LETTER
ANDNUMBER/SYMBOLINPASSWORD)
YES NO

IFTHISISANINITIALASSESSMENTVISITONLY,MOVETOASSESSMENTSECTION8

Advanced/Optional: THE FOLLOWING ITEMS SHOULD BE CHECKED AFTER THE SITE HAS ENTERED INTO A SITE
MAINTENANCEAGREEMENTWITHLEAPCOMPLIANCESYSTEMS.THEFOLLOWINGITEMSSHOULDNOTBECHECKED
DURINGINITIALASSESSMENTVISITS.

Question76:

DOES ANY MICROSOFT WINDOWS BASED


WORKSTATION OR DEVICE ALLOW A
DUPLICATE OF A USERS ACCESS PASSWORD
TO BE STORED IN LAN MANAGER
ACCESSIBLEWEAKENCRYPTIONFORMAT?
YES NO

Question77:

DOES ANY MICROSOFT WINDOWS BASED


WORKSTATION ALLOW REMOTE ACCESS OF
THATSTATIONSWINDOWSREGISTRY?
YES NO

Question78:

IF THE NETWORK IS WINDOWS BASED, HAS


GROUP POLICY BEEN CONFIGURED TO
PREVENT THE USE OF REMOVEABLE MEDIA
AND/OR DEVICES ON COMPUTERS IN
COMMONORHIGHTRAFFICAREAS?
YES NO

RegulatoryComplianceSoftwareandSolutions
http://www.leapcompliance.comcorporate@leapcompliance.com
FORM010CHACTREV0110B
PAGE10OF12

Section8:DataStorageandTransport

Question81:

IS PATIENT DATA STORED ON ANY


COMPUTER OR DEVICE? (INCLUDES PDA,
PHONE,LAPTOPANDDESKTOPDEVICES)
YES NO

IFTHEANSWERTOQUESTION81WASNO,SKIPTOASSESSMENTSECTION9

Question82:

ARE ANY PRINTING DEVICES USED TO PRINT


PATIENT RECORDS, DATA OR ANY OTHER
PROTECTED HEALTH INFORMATION
LOCATED IN SECURE AREAS? (NOT IN
COMMONAREASWHEREPRINTINGRESULTS
MIGHT BE SEEN/TAKEN BY UNAUTHORIZED
PERSONNED)
YES NO

Applications/Software: LIST EVERY APPLIATION USED BY THE FACILITY THAT CREATES, EDITS OR OTHERWISE
STORES/USESPROTECTEDHEALTHINFORMATION.NOTE:THISINCLUDESGENERALAPPLICATIONSINCLUDINGBUT
NOT LIMITED TO MICROSOFT WORD, ADOBE ACROBAT, ETC. IT ALSO INCLUDES CLINICAL, BILLING AND/OR
APPOINTMENT SCHEDULING SOFTWARE (I.E. DENTRIX, IDX, ETC.). INCLUDE ANY DIGITAL XRAY SYSTEMS,
ULTRASOUND SYSTEMS, EKG/CARDIAC OR ANY OTHER TYPE OF SOFTWARE/HARDWARE DEVICE THAT STORES PHI
ONTOAHARDDISK,FLASHMEDIADRIVE,EEPROMORANYOTHERDIGITALSTORAGEMEDIA.

TABLE8A:APPLICATIONSSTORINGPROTECTEDHEALTHINFORMATION(PHI)
APPID NAMEOFSOFTWAREAPPLICATIONANDMFG.NAME MULTIUSER? VERSION(IFAVAIL.)
1

2

3

4

5

6

7

8

9

IFTHEREARENOSOFTWAREAPPLICATIONSLISTEDINTABLE8A,MOVETOSECTION9

Question83:

FOREVERYAPPLICATIONLISTEDINTABLE8
A, IS THE DATA STORED BY THE
APPLICATION EITHER ENCRYPTED BY THE
APPLICATION ITSELF OR ENCRYPTED BY THE
OPERATING SYSTEM WHEN WRITTEN ONTO
THESTORAGEMEDIA?(I.E.BITLOCKER,ETC.)
YES NO

RegulatoryComplianceSoftwareandSolutions
http://www.leapcompliance.comcorporate@leapcompliance.com
FORM010CHACTREV0110B
PAGE11OF12

Section9:VisualInspectionandClientRequests

Visual Inspection: VISUALLY INSPECT THE FACILITY/OFFICE. IF THERE ARE WORKSTATIONS OR DEVICES THAT
ARE POSITIONED IN A MANNER THAT MAY ALLOW IMPROPER ACCESS BY PATIENTS, PHARMACEUTICAL
REPRESENTATIVES,VENDORSORANYOTHERUNAUTHORIZEDINDIVIDUAL,PLEASENOTEBELOW:

VISUALINSPECTIONNOTES:

ClientRequests:ASKTHECLIENTIFANYHARDWAREISNOTWORKING,WHETHERANYHARDWARENEEDSTOBE
REPLACED, IF THE SITE NEEDS ANY NEW WORKSTATIONS OR OTHERWISE REQUIRES SERVICE TO REPAIR OR
MAINTAINEXISTINGEQUIPMENT/SOFTWARE.NOTEANYREQUESTSBELOW:

CLIENTREQUESTSFORHARDWARE,SOFTWAREORSERVICE:

Section10:ExternalWebsite(InternetAccessible)

Question101:

DOES THE SITE/BUSINESS HAVE AN


EXTERNAL WEBSITE AVAILABLE FOR
PATIENTSTOACCESSVIATHEINTERNET?
YES NO

Question102:

IF ANSWER TO 101 IS YES, DOES THE


INTERNET SITE PROVIDE PATIENTS THE
ABILITY TO ACCESS MEDICAL RECORDS, SET
APPOINTMENTS AND/OR SEND REQUESTS
TOTHEPROVIDER?
YES NO

Question103:

IF ANSWER TO 102 IS YES, DOES THE WEB


SITEEMPLOYSSLENCRYPTIONANDSTRONG
PASSWORDREQUIREMENTFORPHIACCESS?
YES NO

Question104:

IS THE PROVIDER INTERESTED IN HAVING


LEAP COMPLIANCE DEVELOP OR IMPROVE
THEIR WEBSITE, SECURELY HOST THAT SITE
AND ENSURE THE SITE MEETS APPLICABLE
PRIVACYANDSECURITYREQUIREMENTS?
YES NO

RegulatoryComplianceSoftwareandSolutions
http://www.leapcompliance.comcorporate@leapcompliance.com
FORM010CHACTREV0110B
PAGE12OF12
Section11:ServiceAgreement

Question111:

DOESTHESITE/PROVIDERCURRENTLYHAVE
AN AGREEMENT WITH AN I.T. OR SIMILAR
COMPANY THAT PROVIDES FOR ONSITE I.T.
SERVICES?
YES NO

Question112:

IF 111 WAS YES, DOES THE CURRENT I.T.


SERVICE PROVIDER SPECIALIZE IN
HEALTHCAREI.T.?
YES NO

Question113:

IF 111 WAS YES, HAS THE CURRENT I.T.


PROVIDER PERFORMED THIS TYPE OF
ASSESSMENTFORTHEPROVIDER?
YES NO

PostAssessmentReview

THEASSESSMENTPROCESSISNOWCOMPLETE.IFYOUHAVEUSEDTHEPAPERFORMASSESSMENTASA
RESULT OF HAVING NO INTERNET CONNECTION OR BECAUSE THE LEAP ASSESSMENT WEBSITE IS
UNAVAILABLE, ADVISE THE CLIENT: 1) THE ASSESSMENT INFORMATION WILL BE PROCESSED AT OUR
OFFICE;AND2)ALEAPREPRESENTATIVEWILLTELEPHONEINTHENEXT2448HOURSANDSETATIME
TO RETURN TO THE SITE WITH THE ASSESSMENT RESULTS AND RECOMMENDATIONS. NOTE: THE
ORIGINALOFTHISASSESSMENTWORKSHEETMUSTBERETURNEDTOYOURLOCALLEAPOFFICE.

IF THE ASSESSMENT WAS COMPLETED ONLINE RATHER THAN USING THE PAPER WORKSHEET, REVIEW
THE ASSESSMENT RESULTS WITH THE CONTACT PERSON AT THE SITE. IF A SERVICE AGREEMENT,
SERVICE CALL OR HARDWARE/SOFTWARE ORDER IS NECESSARY/REQUESTED, USE THE APPROPRIATE
ONLINEORDERINGSYSTEM(S).IFYOUAREUNABLETOACCESSTHEWEBBASEDSERVICEAGREEMENTOR
WORK ORDER ENTRY SYSTEM(S), USE THE ALTERNATE PAPER FORMS RETURNING THE ORIGINALS TO
YOURLOCALLEAPOFFICE.

LeapTechnicianDetail

LEAPAFFILIATEID#

TECHNICIAN(1)NAME

LEAPCERTFICATION#

TECHNICIAN(2)NAME

LEAPCERTFICATION#

ASSESSMENTSTARTTIME ASSESSMENTENDTIME

FOROFFICEUSEONLY:

DATERECVD DATEPROCESSED PROCESSEDBY


ASSESSMENTS/N CLIENTACCTID CONFIRMCODE