HIPAA Administrative Safeguards 4 โ Questions and Answers
Question 1: What is the required minimum content of a HIPAA Security Risk Analysis?
- A list of all known breaches in the past three years
- An accurate and thorough assessment of potential risks and vulnerabilities to ePHI confidentiality, integrity, and availability (Correct answer)
- A penetration test of all ePHI systems conducted by an external auditor
- A comparison of current security controls against NIST SP 800-53
Correct answer: An accurate and thorough assessment of potential risks and vulnerabilities to ePHI confidentiality, integrity, and availability
The risk analysis must be an accurate and thorough assessment of potential risks and vulnerabilities to all ePHI that an organization creates, receives, maintains, or transmits.
Question 2: Under HIPAA Administrative Safeguards, 'log-in monitoring' is classified as:
- A required standard
- An addressable implementation specification under security awareness and training (Correct answer)
- A required implementation specification under access control
- An addressable standard under security management process
Correct answer: An addressable implementation specification under security awareness and training
Log-in monitoring is an addressable implementation specification under the security awareness and training standard, focusing on training staff to monitor login attempts.
Question 3: A covered entity conducts a risk assessment and identifies that unencrypted laptops pose a significant risk to ePHI. The entity decides not to encrypt them due to cost. This decision is:
- Acceptable if documented with a cost justification
- Acceptable if the entity notifies HHS within 60 days
- Not acceptable because risk management must address identified risks (Correct answer)
- Acceptable because encryption is only an addressable specification
Correct answer: Not acceptable because risk management must address identified risks
Risk management requires implementing security measures sufficient to reduce identified risks to a reasonable and appropriate level; simply accepting a significant risk without mitigation violates this requirement.
Question 4: Which HIPAA standard requires covered entities to document the rationale for security policy decisions?
- Security management process
- Documentation standard (Correct answer)
- Assigned security responsibility
- Evaluation standard
Correct answer: Documentation standard
The documentation standard (ยง164.316) requires covered entities to maintain written policies and procedures and to document decisions, including reasons for implementing or not implementing certain controls.
Question 5: An evaluation under HIPAA's Administrative Safeguards must be performed:
- Annually by a certified third-party auditor
- Periodically and in response to environmental or operational changes (Correct answer)
- Only after a reported security incident
- Every two years as mandated by the HITECH Act
Correct answer: Periodically and in response to environmental or operational changes
Covered entities must perform a periodic technical and nontechnical evaluation based on standards and in response to environmental or operational changes affecting ePHI security.
Question 6: A cloud vendor stores ePHI on behalf of a hospital. Under Administrative Safeguards, this vendor must be treated as:
- A covered entity subject to all HIPAA rules
- A business associate requiring a signed BAA (Correct answer)
- A workforce member subject to sanction policies
- An exempt third party if data is encrypted in transit
Correct answer: A business associate requiring a signed BAA
Any third party that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate and must have a BAA in place.
Question 7: Which of the following is NOT a required implementation specification under the Contingency Plan standard?
- Data backup plan
- Disaster recovery plan
- Emergency mode operation plan
- Intrusion detection procedure (Correct answer)
Correct answer: Intrusion detection procedure
Intrusion detection is not part of the contingency plan standard; the required specifications are data backup, disaster recovery, emergency mode operation, testing/revision, and applications/data criticality analysis.
What is the required minimum content of a HIPAA Security Risk Analysis?