Abstract
This paper is looking at electronic health record (EHR) systems and their information security strategy. It focuses on the first step of building an information security strategy which is analysing the current situation of an EHR system. This research is based on different research methods applied to different EHR systems. In this paper we define eight elements that can be used as guidelines for how best to assess the current situation of any EHR system.