โ† All CHI Flashcard Decks

Risk Management & Mitigation Flashcards

7 cards from real CHI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Management & Mitigation flashcards as text
  1. A hospital's EHR vendor experiences a ransomware attack that disrupts patient record access. Which risk category best describes this event?

    Answer: Third-party / supply chain risk

    When a vendor's security failure causes disruption to a covered entity, it represents third-party or supply chain risk, highlighting the importance of Business Associate Agreements.

  2. In health informatics, what is the purpose of a Data Flow Diagram (DFD) during a risk assessment?

    Answer: To map how PHI moves between systems, processes, and external entities

    DFDs identify all points where PHI is created, stored, transmitted, or destroyed, enabling risk assessors to uncover exposure points across data flows.

  3. Which security concept ensures that PHI cannot be altered or destroyed in an unauthorized manner?

    Answer: Integrity

    Integrity, one of the three HIPAA Security Rule principles, ensures that electronic PHI is not improperly modified or deleted.

  4. An organization decides to discontinue a high-risk legacy system with no feasible control options. Which risk strategy is being employed?

    Answer: Risk avoidance

    Risk avoidance eliminates the risk entirely by discontinuing the activity, system, or process that creates the exposure.

  5. Which role is primarily responsible for ensuring a risk management program aligns with organizational strategy and approving risk tolerance levels?

    Answer: Board of Directors or Senior Leadership

    Risk tolerance and enterprise-wide risk appetite decisions must be set and approved by senior leadership or the board, as they reflect organizational strategy.

  6. What is the main advantage of using quantitative risk analysis over qualitative analysis?

    Answer: It produces numeric financial estimates enabling cost-benefit comparisons for controls

    Quantitative analysis produces monetary values (e.g., Annual Loss Expectancy) that allow organizations to compare control costs against expected losses.

  7. A covered entity implements automatic session timeouts on all EHR workstations. This is an example of which type of safeguard under the HIPAA Security Rule?

    Answer: Technical safeguard

    Automatic logoff is explicitly listed as a technical safeguard implementation specification under the HIPAA Security Rule's Access Control standard.

Risk Management & Mitigation Flashcards โ€” CHI Study Cards with Answers