CHPC PHI Safeguards and Security Questions and Answers — Questions and Answers
Question 1: A healthcare clinic is relocating to a new facility, and its IT department is moving servers and backup tapes containing ePHI. According to the HIPAA Security Rule's Physical Safeguards, which of the following is a key requirement for managing this process?
- Encrypting all data on the servers and tapes prior to the move.
- Maintaining a record of the movement of the hardware and electronic media. (Correct answer)
- Notifying all patients of the clinic's change of address and potential data risk.
- Performing a full risk analysis of the new facility's network infrastructure before connecting devices.
Correct answer: Maintaining a record of the movement of the hardware and electronic media.
The HIPAA Security Rule's Physical Safeguards include the Device and Media Controls standard. A specification under this standard requires policies and procedures that govern the movement of hardware and electronic media. While not a 'required' specification, maintaining a record of these movements is a critical part of accountability to ensure ePHI is tracked and protected during transport.
Question 2: A hospital's electronic health record (EHR) system experiences a network outage, preventing clinicians from using their standard credentials. To ensure patient care continues, the organization must have a pre-established method for accessing necessary ePHI. Which HIPAA Security Rule standard specifically addresses this requirement?
- Unique User Identification
- Audit Controls
- Automatic Logoff
- Emergency Access Procedure (Correct answer)
Correct answer: Emergency Access Procedure
The HIPAA Security Rule's Technical Safeguards require covered entities to establish (and implement as needed) procedures for obtaining necessary ePHI during an emergency. This is the 'Emergency Access Procedure' standard, which is a required implementation specification under the Access Control standard, designed for situations where normal access methods fail.
Question 3: A Privacy Officer is reviewing the organization's HIPAA Security Rule contingency plan to ensure all required components are present. Which of the following collections of plans MUST be included?
- A data backup plan, a disaster recovery plan, and an emergency mode operation plan. (Correct answer)
- A security incident response plan, a breach notification plan, and a workforce sanction plan.
- A facility security plan, a workstation use policy, and a device and media control plan.
- An access control plan, an audit control plan, and a transmission security plan.
Correct answer: A data backup plan, a disaster recovery plan, and an emergency mode operation plan.
The HIPAA Security Rule's Contingency Plan standard (an Administrative Safeguard) mandates several implementation specifications. Three of these required specifications are a data backup plan, a disaster recovery plan, and an emergency mode operation plan, which are essential for ensuring ePHI is protected and accessible during and after an emergency.
Question 4: A hospital's janitorial staff discards unshredded patient documents containing names, diagnoses, and account numbers into a publicly accessible dumpster. This event constitutes a breach. Which specific safeguard failure is MOST directly responsible for this type of incident?
- Failure of technical access controls on the electronic health record system.
- Failure of the organization's disaster recovery plan.
- Failure to implement proper policies for the final disposition of PHI. (Correct answer)
- Failure to obtain patient authorization for research purposes.
Correct answer: Failure to implement proper policies for the final disposition of PHI.
Both the HIPAA Privacy and Security Rules require covered entities to implement reasonable safeguards for PHI in any form. This includes having and implementing policies and procedures for the final disposition of PHI, such as shredding or otherwise destroying documents to render them unreadable and unreconstructible before they are discarded.
Question 5: A covered entity is drafting a Business Associate Agreement (BAA) with a new cloud storage vendor. According to HIPAA, which of the following is a mandatory provision that the BAA must contain regarding the business associate's duties?
- The business associate must use the same brand of firewall and antivirus software as the covered entity.
- The business associate must implement appropriate administrative, physical, and technical safeguards. (Correct answer)
- The business associate must conduct a penetration test annually and provide the full report to the covered entity.
- The business associate must ensure all its employees complete the covered entity's specific HIPAA training module.
Correct answer: The business associate must implement appropriate administrative, physical, and technical safeguards.
A compliant Business Associate Agreement must state that the business associate will use appropriate safeguards to prevent the use or disclosure of PHI other than as provided for by the contract. This explicitly includes implementing the requirements of the HIPAA Security Rule (administrative, physical, and technical safeguards) for any ePHI it handles.
Question 6: An employee at a physician's office is found to have accessed the medical record of a coworker out of curiosity, with no legitimate job-related reason. This is a clear violation of the organization's privacy policy. Which HIPAA Administrative Safeguard requires the organization to have a formal policy for addressing this employee's misconduct?
- Information Access Management
- Security Awareness and Training
- Security Incident Procedures
- Sanction Policy (Correct answer)
Correct answer: Sanction Policy
The HIPAA Security Rule's Administrative Safeguards require a covered entity to 'Apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity.' This is a required implementation specification known as the Sanction Policy.
A healthcare clinic is relocating to a new facility, and its IT department is moving servers and backup tapes containing ePHI.
According to the HIPAA Security Rule's Physical Safeguards, which of the following is a key requirement for managing this process?