CSC HIPAA Security Rule 3 — Questions and Answers
Question 1: Which HIPAA Security Rule implementation specification requires a covered entity to obtain satisfactory assurances from business associates before sharing ePHI?
- Workforce Security
- Business Associate Contracts (Correct answer)
- Information Access Management
- Security Awareness Training
Correct answer: Business Associate Contracts
Business Associate Contracts (or other arrangements) are an addressable implementation specification requiring documented assurances that business associates will protect ePHI.
Question 2: A healthcare organization uses a cloud storage provider to store patient imaging files. Under HIPAA, the cloud provider is best classified as:
- A covered entity subject to full HIPAA compliance
- A business associate requiring a signed BAA (Correct answer)
- An exempt technology vendor under Safe Harbor
- A subcontractor with no direct HIPAA obligations
Correct answer: A business associate requiring a signed BAA
Cloud service providers handling ePHI on behalf of covered entities are business associates and must sign a Business Associate Agreement (BAA).
Question 3: The HIPAA Security Rule's 'integrity' controls are designed to protect ePHI from which specific threat?
- Unauthorized disclosure to third parties
- Unauthorized alteration or destruction (Correct answer)
- Interception during network transmission
- Loss due to system failure
Correct answer: Unauthorized alteration or destruction
Integrity controls ensure that ePHI is not improperly altered or destroyed, protecting the accuracy and completeness of health information.
Question 4: Under the Security Rule, which standard governs the processes for creating, changing, and safeguarding passwords?
- Access Control — Password Management (Correct answer)
- Technical Safeguards — Authentication
- Administrative Safeguards — Security Awareness
- Physical Safeguards — Workstation Access
Correct answer: Access Control — Password Management
Password management is an addressable implementation specification under the Access Control standard of HIPAA Technical Safeguards.
Question 5: A small medical practice claims it does not need to conduct a formal risk analysis because it uses a certified EHR system. This claim is:
- Valid, because certified EHR systems meet all HIPAA technical safeguard requirements
- Invalid, because every covered entity must conduct its own risk analysis regardless of software used (Correct answer)
- Valid only if the EHR vendor provides a signed attestation of compliance
- Invalid only if the practice has more than 10 employees
Correct answer: Invalid, because every covered entity must conduct its own risk analysis regardless of software used
Every covered entity, regardless of size or software used, must conduct its own risk analysis as a required implementation specification under HIPAA.
Question 6: Which scenario best illustrates a violation of the HIPAA Security Rule's Workstation Use standard?
- A nurse accesses ePHI from a hospital-issued laptop at home via VPN
- A receptionist uses a shared workstation to browse social media while logged into the EHR (Correct answer)
- A physician prints patient records for a care team meeting
- An IT admin performs system maintenance after hours
Correct answer: A receptionist uses a shared workstation to browse social media while logged into the EHR
The Workstation Use standard requires policies specifying the proper functions and manner of use for workstations that access ePHI, prohibiting unauthorized uses.
Question 7: What is the primary purpose of 'audit controls' as a technical safeguard under the HIPAA Security Rule?
- To encrypt ePHI stored on servers
- To record and examine activity in systems containing ePHI (Correct answer)
- To automatically terminate sessions after inactivity
- To authenticate users before granting access
Correct answer: To record and examine activity in systems containing ePHI
Audit controls require hardware, software, and procedural mechanisms that record and examine activity in information systems containing ePHI for accountability and forensics.
Which HIPAA Security Rule implementation specification requires a covered entity to obtain satisfactory assurances from business associates before sharing ePHI?