HIPAA Administrative Safeguards 3 — Questions and Answers
Question 1: Which of the following is an ADDRESSABLE implementation specification under the Security Management Process standard?
- Risk analysis
- Risk management
- Sanction policy
- Information system activity review (Correct answer)
Correct answer: Information system activity review
Information system activity review is an addressable specification, meaning entities must assess whether it is reasonable and appropriate given their environment.
Question 2: A small medical practice decides not to implement an addressable specification. What must they do?
- Notify HHS of the decision within 30 days
- Document the reason and implement an equivalent alternative if reasonable (Correct answer)
- Obtain a waiver from their regional HHS office
- Have the decision approved by their privacy officer
Correct answer: Document the reason and implement an equivalent alternative if reasonable
If an addressable specification is not implemented, the entity must document why it is not reasonable and appropriate and whether an equivalent alternative measure has been implemented.
Question 3: What is the scope of HIPAA's workforce training requirement under Administrative Safeguards?
- Only workforce members who directly handle ePHI
- All workforce members, including volunteers and trainees (Correct answer)
- Only IT staff responsible for ePHI systems
- Workforce members hired after the compliance date
Correct answer: All workforce members, including volunteers and trainees
Security awareness training must be provided to all workforce members, including management, regardless of whether they directly handle ePHI.
Question 4: Under the Security Management Process, what is the purpose of 'information system activity review'?
- To certify that all ePHI systems meet NIST standards
- To audit logs, access reports, and security incident tracking reports (Correct answer)
- To review system uptime and performance metrics
- To assess vendor compliance with BAAs
Correct answer: To audit logs, access reports, and security incident tracking reports
Information system activity review involves regularly reviewing records of activity such as audit logs and access reports to detect security incidents.
Question 5: A covered entity undergoes a merger. Which Administrative Safeguard process must be updated to reflect the new organizational structure?
- Only the contingency plan
- Only workforce training
- Security policies and procedures, including risk analysis (Correct answer)
- Only the assigned security responsibility designation
Correct answer: Security policies and procedures, including risk analysis
A merger constitutes a significant operational change that triggers a review and update of security policies and procedures, including a new or updated risk analysis.
Question 6: Which of the following best describes the 'termination procedures' implementation specification under workforce security?
- Steps to fire noncompliant workforce members
- Procedures for revoking access to ePHI when employment ends (Correct answer)
- Guidelines for employee exit interviews about PHI
- Policies for reassigning ePHI access after termination
Correct answer: Procedures for revoking access to ePHI when employment ends
Termination procedures ensure that when a workforce member's employment ends, their access to ePHI systems is promptly revoked.
Question 7: A HIPAA-covered entity's security training includes reminders about malicious software. This training element maps to which implementation specification?
- Log-in monitoring
- Password management
- Protection from malicious software (Correct answer)
- Security reminders
Correct answer: Protection from malicious software
Training on malicious software falls under the 'protection from malicious software' addressable specification within the security awareness and training standard.
Which of the following is an ADDRESSABLE implementation specification under the Security Management Process standard?