HIPAA The HIPAA Security Rule 2 — Questions and Answers
Question 1: Which of the following is an example of a physical safeguard under the HIPAA Security Rule?
- Automatic logoff after inactivity
- Facility access controls (Correct answer)
- Audit logs of ePHI access
- Encryption of data in transit
Correct answer: Facility access controls
Physical safeguards include facility access controls, workstation use policies, and device and media controls to protect physical access to ePHI.
Question 2: What is the primary purpose of a Risk Analysis under the HIPAA Security Rule?
- To create a disaster recovery plan
- To identify and assess vulnerabilities to ePHI confidentiality, integrity, and availability (Correct answer)
- To train employees on HIPAA policies
- To document all system users with ePHI access
Correct answer: To identify and assess vulnerabilities to ePHI confidentiality, integrity, and availability
A Risk Analysis identifies potential threats and vulnerabilities to ePHI so covered entities can implement appropriate safeguards.
Question 3: Under the HIPAA Security Rule, which standard requires covered entities to have policies for responding to a security incident?
- Contingency Plan
- Security Incident Procedures (Correct answer)
- Audit Controls
- Workforce Security
Correct answer: Security Incident Procedures
The Security Incident Procedures standard requires covered entities to identify, respond to, mitigate, and document security incidents involving ePHI.
Question 4: A hospital uses an automatic logoff feature that locks workstations after 10 minutes of inactivity. This is an example of which type of safeguard?
- Physical safeguard
- Administrative safeguard
- Technical safeguard (Correct answer)
- Organizational safeguard
Correct answer: Technical safeguard
Automatic logoff is a technical safeguard that prevents unauthorized access to ePHI on idle workstations.
Question 5: Which of the following best describes an 'addressable' implementation specification under the Security Rule?
- It must be implemented exactly as written with no flexibility
- It is optional and can be skipped without justification
- It must be implemented, or a documented alternative must be adopted if reasonable and appropriate (Correct answer)
- It applies only to business associates, not covered entities
Correct answer: It must be implemented, or a documented alternative must be adopted if reasonable and appropriate
Addressable specifications require covered entities to assess whether implementation is reasonable and appropriate, and to document their decision either way.
Question 6: What type of safeguard includes policies and procedures for creating and maintaining retrievable exact copies of ePHI?
- Technical safeguard — Integrity
- Physical safeguard — Device and Media Controls
- Technical safeguard — Data Backup Plan
- Administrative safeguard — Contingency Plan (Correct answer)
Correct answer: Administrative safeguard — Contingency Plan
The Contingency Plan standard under Administrative Safeguards includes the required Data Backup Plan, which ensures retrievable copies of ePHI.
Question 7: Which entity is directly required to comply with the HIPAA Security Rule?
- Any vendor that sells software to hospitals
- Covered entities and their business associates (Correct answer)
- Patients who access their own ePHI
- Health IT developers funded by CMS
Correct answer: Covered entities and their business associates
The Security Rule applies directly to covered entities (health plans, providers, clearinghouses) and their business associates.
Which of the following is an example of a physical safeguard under the HIPAA Security Rule?