I may be misquoting them a bit on this. What I think they said/meant was that with the EMR hosted in the cloud, we didn't need to do a whole risk analysis of the local server, how is it secured both physically and on the network, how is it backed up, are the backups encrypted etc. We did go through stuff like who has access to the computers and to the EMR.

Michael