Mixed Deck — All CHISSP Topics Flashcards
100 cards from real CHISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CHISSP Topics flashcards as text
In Certified Healthcare Information Systems Security Practitioner, which factor MOST influences the selection of appropriate research methods & evidence-based practice?
Answer: The specific requirements and constraints of the situation
The specific requirements and constraints of each situation should drive technique selection to ensure the most effective and appropriate approach.
What factor MOST affects the validity of diagnostic procedures & interpretation outcomes in Certified Healthcare Information Systems Security Practitioner?
Answer: The consistency and appropriateness of assessment methods used
Validity depends primarily on using consistent, appropriate methods that actually measure what they are intended to measure.
Which risk management framework is most commonly adopted by US healthcare organizations to align information security with regulatory requirements?
Answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework is widely adopted by US healthcare organizations because it aligns with HIPAA Security Rule requirements and provides a flexible, risk-based approach.
What is the PRIMARY objective of anatomy & physiology fundamentals within the Certified Healthcare Information Systems Security Practitioner profession?
Answer: To ensure quality outcomes through standardized practices and continuous improvement
The primary objective is ensuring quality outcomes through established standards while continuously improving practices and processes.
Under HITECH's breach notification provisions, what threshold triggers the requirement for media notification in addition to individual notification?
Answer: Breaches affecting 500 or more residents of a state or jurisdiction
When a breach affects 500 or more residents of a state or jurisdiction, HIPAA requires prominent media notification (e.g., press release) in addition to individual and HHS notification.
A ransomware attack encrypts ePHI on a hospital's servers. Under HIPAA Breach Notification Rule guidance, how should this be treated?
Answer: Presumed a reportable breach unless the entity can demonstrate low probability of PHI compromise
HHS OCR guidance states ransomware attacks presumptively constitute breaches because unauthorized access occurred; the covered entity must conduct a four-factor risk assessment to rebut this presumption.
Which HITECH provision extended direct HIPAA Security Rule obligations to business associates?
Answer: Section 13401 of HITECH, which made Security Rule provisions directly applicable to business associates
HITECH §13401 made business associates directly liable for compliance with the HIPAA Security Rule's administrative, physical, and technical safeguards, enforceable by HHS OCR.
What is the MOST effective way to stay current with developments in anatomy & physiology fundamentals for Certified Healthcare Information Systems Security Practitioner?
Answer: Participating in professional development, industry events, and peer collaboration
A multi-faceted approach including formal development, industry events, and peer collaboration provides the broadest perspective on current developments.
In Certified Healthcare Information Systems Security Practitioner, what is the PRIMARY purpose of conducting regular quality improvement & patient safety assessments?
Answer: To identify potential hazards before incidents occur
Regular safety assessments are primarily conducted to proactively identify and mitigate potential hazards before they lead to incidents or injuries.
A hospital's security team wants to detect lateral movement by an attacker who has already compromised an internal workstation. Which tool is MOST effective for this purpose?
Answer: Security Information and Event Management (SIEM) system with behavioral analytics
A SIEM with behavioral analytics correlates logs across the network to detect anomalous internal traffic patterns indicative of lateral movement, which perimeter tools cannot see.
Which factor BEST indicates mastery of anatomy & physiology fundamentals in Certified Healthcare Information Systems Security Practitioner?
Answer: The ability to adapt knowledge and skills to varying contexts while maintaining standards
True mastery is demonstrated by the ability to apply knowledge flexibly across different contexts while consistently maintaining quality standards.
How many of the 18 HIPAA-defined identifiers must be removed from patient data for it to qualify as 'de-identified' under the Safe Harbor method?
Answer: All 18 identifiers must be removed
The Safe Harbor de-identification method under §164.514(b) requires removal of all 18 specified identifiers and verification that no residual information could identify the individual.
In healthcare IT security, what does 'defense in depth' primarily refer to?
Answer: Layering multiple independent security controls so a failure in one does not compromise the entire system
Defense in depth layers multiple independent controls (firewalls, IDS, access control, encryption, monitoring) so that an attacker must defeat every layer, reducing the likelihood of a successful breach.
Which documentation & health records practice is MOST critical for maintaining data integrity in Certified Healthcare Information Systems Security Practitioner?
Answer: Standardized input procedures with validation checks and regular audits
Standardized procedures with validation and audits ensure data remains accurate, consistent, and trustworthy.
What is the FIRST step in conducting a thorough clinical assessment & patient care in Certified Healthcare Information Systems Security Practitioner?
Answer: Defining clear assessment criteria and objectives
Defining clear criteria and objectives ensures the assessment is focused, consistent, and produces actionable results.
What is the PRIMARY objective of pharmacology & treatment protocols within the Certified Healthcare Information Systems Security Practitioner profession?
Answer: To ensure quality outcomes through standardized practices and continuous improvement
The primary objective is ensuring quality outcomes through established standards while continuously improving practices and processes.
Under NIST guidelines, what is the primary purpose of implementing 802.1X port-based authentication on a healthcare network?
Answer: To ensure only authenticated devices connect to network segments
802.1X port-based authentication prevents unauthorized devices from connecting to the network by requiring successful authentication before granting network access.
Which factor BEST indicates mastery of infection control & prevention in Certified Healthcare Information Systems Security Practitioner?
Answer: The ability to adapt knowledge and skills to varying contexts while maintaining standards
True mastery is demonstrated by the ability to apply knowledge flexibly across different contexts while consistently maintaining quality standards.
Which barrier MOST commonly hinders effective patient education & health promotion in Certified Healthcare Information Systems Security Practitioner?
Answer: Lack of active listening and assumptions about understanding
Failure to actively listen and making assumptions about understanding are the most common barriers to effective communication.
What is the primary purpose of a Healthcare Risk Analysis (HRA) under the HIPAA Security Rule?
Answer: To identify and evaluate risks to the confidentiality, integrity, and availability of ePHI
HIPAA's Security Rule §164.308(a)(1) requires covered entities to conduct an accurate and thorough assessment of potential risks to ePHI as the foundation of their security program.