HIPAA Administrative Safeguards 2 — Questions and Answers
Question 1: Under HIPAA's Administrative Safeguards, what is the primary purpose of a contingency plan?
- To prevent unauthorized access to ePHI systems
- To respond to emergencies that damage systems containing ePHI (Correct answer)
- To train workforce members on PHI handling
- To document business associate agreements
Correct answer: To respond to emergencies that damage systems containing ePHI
The contingency plan standard requires covered entities to establish policies for responding to emergencies or disasters that damage systems containing ePHI.
Question 2: Which component of the contingency plan addresses how a covered entity will continue operating in the event of a system failure?
- Disaster recovery plan
- Emergency mode operation plan (Correct answer)
- Data backup plan
- Testing and revision procedure
Correct answer: Emergency mode operation plan
The emergency mode operation plan is required to enable continuation of critical business processes for protection of the security of ePHI during system failure.
Question 3: A hospital's security officer discovers that a workforce member accessed patient records without authorization. Under Administrative Safeguards, what must occur?
- The hospital must immediately notify HHS
- The hospital must apply appropriate sanctions against the workforce member (Correct answer)
- The hospital must terminate the workforce member
- The hospital must file a police report
Correct answer: The hospital must apply appropriate sanctions against the workforce member
The sanction policy standard requires covered entities to apply appropriate sanctions against workforce members who fail to comply with security policies.
Question 4: What does the 'assigned security responsibility' standard under Administrative Safeguards require?
- Every workforce member must have a unique security role
- One individual must be identified as responsible for security policies and procedures (Correct answer)
- Security responsibilities must be outsourced to a third party
- A security committee must be established
Correct answer: One individual must be identified as responsible for security policies and procedures
Covered entities must identify one person — often called the Security Officer — who is responsible for developing and implementing security policies.
Question 5: Under HIPAA, an authorization and/or supervision implementation specification requires covered entities to:
- Require dual authorization for all ePHI access
- Supervise workforce members who work with ePHI (Correct answer)
- Obtain written authorization from patients before access
- Have all PHI access approved by a privacy officer
Correct answer: Supervise workforce members who work with ePHI
Workforce members who work with ePHI must be supervised as appropriate, especially those working in locations with physical access to facilities with ePHI.
Question 6: How often must covered entities review and modify their security policies under HIPAA's Administrative Safeguards?
- Annually, as required by statute
- Every three years, per HHS guidance
- Periodically, based on environmental or operational changes (Correct answer)
- Only when a breach occurs
Correct answer: Periodically, based on environmental or operational changes
HIPAA requires periodic review of security policies when environmental or operational changes affect the security of ePHI, not on a fixed schedule.
Question 7: A covered entity uses a clearinghouse to process claims. Under the workforce clearance procedure, what must be done before granting this clearinghouse access to ePHI?
- Execute a business associate agreement only
- Implement procedures to verify authorization of access is appropriate (Correct answer)
- Obtain patient consent for third-party processing
- Require the clearinghouse to carry malpractice insurance
Correct answer: Implement procedures to verify authorization of access is appropriate
Workforce clearance procedures require implementing processes to determine whether access to ePHI by a workforce member is appropriate before granting such access.
Under HIPAA's Administrative Safeguards, what is the primary purpose of a contingency plan?