Administrative, Physical & Technical Safeguards Flashcards
7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Administrative, Physical & Technical Safeguards flashcards as text
Under HIPAA technical safeguards, which control ensures that ePHI is not improperly altered or destroyed?
Answer: Integrity controls
Integrity controls are technical safeguards designed to protect ePHI from unauthorized alteration or destruction, such as checksums and hash validation.
Which HIPAA technical safeguard standard requires covered entities to implement hardware, software, or procedural mechanisms to record and examine ePHI access activity?
Answer: Audit controls
Audit controls require the implementation of mechanisms to record and examine activity in information systems that contain or use ePHI.
A covered entity transmits ePHI over an unencrypted public Wi-Fi network. Which HIPAA technical safeguard is violated?
Answer: Transmission security
Transmission security requires covered entities to implement technical security measures to guard against unauthorized access to ePHI during electronic transmission.
What is the purpose of the 'automatic logoff' implementation specification under HIPAA technical safeguards?
Answer: To prevent unauthorized users from accessing ePHI on unattended sessions
Automatic logoff terminates electronic sessions after a predetermined period of inactivity to prevent unauthorized access to ePHI on unattended workstations.
Under the HIPAA Security Rule, 'encryption and decryption' is classified as which type of implementation specification?
Answer: Addressable under transmission security
Encryption and decryption is an addressable implementation specification under the transmission security standard, meaning covered entities must implement it if reasonable and appropriate.
A physician uses the same login credentials as her nurse to access the EHR system. Which HIPAA technical safeguard is most directly violated?
Answer: Person or entity authentication
Person or entity authentication requires verifying that the person seeking access is who they claim to be — shared credentials prevent individual accountability.
Which of the following is an example of an emergency access procedure under HIPAA technical access controls?
Answer: A break-glass protocol allowing temporary elevated ePHI access during emergencies
Emergency access procedures (break-glass protocols) allow authorized personnel to access ePHI in emergency situations while maintaining accountability through logging.