HIPAA Technical & Physical Safeguards 2 — Questions and Answers
Question 1: Under HIPAA's Physical Safeguard standards, what does 'workstation use' specification require covered entities to document?
- The hardware specifications of each workstation
- Proper functions and physical attributes of workstations that can access ePHI (Correct answer)
- The software installed on each workstation
- The network connections used by each workstation
Correct answer: Proper functions and physical attributes of workstations that can access ePHI
The workstation use specification requires policies defining the proper functions, manner, and physical setting of workstations that access ePHI.
Question 2: Which HIPAA technical safeguard standard requires covered entities to implement controls ensuring only authorized users can access ePHI systems?
- Audit Controls
- Access Control (Correct answer)
- Integrity Controls
- Transmission Security
Correct answer: Access Control
The Access Control standard requires technical policies and procedures allowing only authorized persons or software programs to access ePHI.
Question 3: A hospital uses key cards to restrict access to server rooms containing ePHI. This is an example of which HIPAA physical safeguard?
- Facility Access Controls (Correct answer)
- Workstation Security
- Device and Media Controls
- Contingency Operations
Correct answer: Facility Access Controls
Facility Access Controls include physical measures like key cards that limit and validate access to facilities housing ePHI systems.
Question 4: What is the purpose of the 'automatic logoff' implementation specification under HIPAA's Access Control standard?
- To enforce password complexity rules
- To terminate an electronic session after a predetermined period of inactivity (Correct answer)
- To log all user access attempts
- To encrypt data when a session ends
Correct answer: To terminate an electronic session after a predetermined period of inactivity
Automatic logoff terminates idle sessions to prevent unauthorized access when a workstation is left unattended.
Question 5: Under HIPAA Device and Media Controls, what must covered entities do before reusing electronic media that previously stored ePHI?
- Obtain patient consent for reuse
- Physically destroy the media
- Clear or purge the media so ePHI cannot be retrieved (Correct answer)
- Archive the data to a backup server
Correct answer: Clear or purge the media so ePHI cannot be retrieved
Before reuse, covered entities must clear (overwrite) or purge (degauss) media to ensure ePHI cannot be recovered.
Question 6: Which technical safeguard implementation specification is specifically designed to detect unauthorized alterations of ePHI?
- Encryption and Decryption
- Automatic Logoff
- Integrity Controls (Correct answer)
- Unique User Identification
Correct answer: Integrity Controls
Integrity Controls use electronic mechanisms such as checksums or digital signatures to confirm that ePHI has not been altered or destroyed without authorization.
Question 7: A clinic trains staff never to leave workstations displaying patient records unattended and to position screens away from public view. Which physical safeguard does this policy fulfill?
- Contingency Operations
- Workstation Use (Correct answer)
- Facility Access Controls
- Accountability
Correct answer: Workstation Use
The Workstation Use specification requires policies covering the physical setting of workstations, including screen positioning and unattended-session procedures.
Under HIPAA's Physical Safeguard standards, what does 'workstation use' specification require covered entities to document?