there is specific language that the office of CMS is using to determine what constitutes a secure system.
This is the opposite of what I've heard. CMS didn't introduce any new measures with meaningful use. They do have some suggestions however. The main thing you want to do is document what you have in place and any loopholes you can think of and how you plan to resolve them. The language is intentionally left vague as not to impose any restrictive measures.
Here's a guide that CMS often refers to:
http://csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdfThat'll help with the documentation.
EDIT: They emphasize physical security as a lot of people forget about things like natural disasters, theft, or power outages.