CSC HIPAA Security Rule 2 — Questions and Answers
Question 1: Under the HIPAA Security Rule, which type of safeguard specifically addresses workforce training and security awareness programs?
- Technical safeguards
- Physical safeguards
- Administrative safeguards (Correct answer)
- Operational safeguards
Correct answer: Administrative safeguards
Administrative safeguards include workforce training, security awareness, and policies governing the management of ePHI.
Question 2: A covered entity discovers a workforce member has been accessing patient records outside their job role for three months. Which HIPAA Security Rule standard is most directly implicated?
- Access Control
- Audit Controls
- Information Access Management (Correct answer)
- Workforce Clearance Procedure
Correct answer: Information Access Management
Information Access Management requires implementing policies that authorize access to ePHI based on job role, preventing unauthorized access.
Question 3: What does the HIPAA Security Rule require regarding the transmission of ePHI over open networks?
- ePHI must never be transmitted over open networks
- Encryption or equivalent measures must protect ePHI in transit (Correct answer)
- A business associate agreement must accompany every transmission
- Transmission logs must be reviewed daily
Correct answer: Encryption or equivalent measures must protect ePHI in transit
The Security Rule requires covered entities to implement technical security measures to guard against unauthorized access to ePHI transmitted over open networks.
Question 4: Which of the following is an example of a physical safeguard under the HIPAA Security Rule?
- Automatic logoff after inactivity
- Encryption of ePHI at rest
- Workstation use policies
- Facility access controls with badge readers (Correct answer)
Correct answer: Facility access controls with badge readers
Physical safeguards include facility access controls such as badge readers, locks, and security cameras that limit physical access to systems containing ePHI.
Question 5: The HIPAA Security Rule's 'minimum necessary' concept most directly applies to which safeguard category?
- Technical safeguards via encryption
- Administrative safeguards via access management (Correct answer)
- Physical safeguards via workstation controls
- Audit controls via log retention
Correct answer: Administrative safeguards via access management
Administrative safeguards including Information Access Management implement the minimum necessary standard by granting role-based access to ePHI.
Question 6: A hospital's contingency plan fails during a ransomware attack because backups were also encrypted. Which required implementation specification was inadequately addressed?
- Disaster Recovery Plan
- Data Backup Plan (Correct answer)
- Emergency Mode Operation Plan
- Testing and Revision Procedures
Correct answer: Data Backup Plan
The Data Backup Plan specification requires creating and maintaining retrievable exact copies of ePHI, which must be protected and stored separately.
Question 7: Under HIPAA Security Rule, how often must covered entities review and modify their security policies and procedures?
- Annually, regardless of changes
- Every three years as part of a formal audit cycle
- Periodically, in response to environmental or operational changes (Correct answer)
- Only when a breach occurs
Correct answer: Periodically, in response to environmental or operational changes
The Security Rule requires covered entities to review and update policies and procedures in response to environmental or operational changes affecting ePHI security.
Under the HIPAA Security Rule, which type of safeguard specifically addresses workforce training and security awareness programs?