โ† All CHP Flashcard Decks

Documentation & Record Keeping Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Documentation & Record Keeping flashcards as text
  1. Under the HIPAA Security Rule, how long must covered entities retain security-related documentation?

    Answer: 6 years from creation or last effective date

    The HIPAA Security Rule requires that security policies, procedures, and related documentation be retained for 6 years from the date of creation or the date it was last in effect.

  2. What must be included in a covered entity's documentation of its risk analysis?

    Answer: The scope, identified threats and vulnerabilities, current controls, likelihood, and impact assessments

    A thorough risk analysis must document the scope of the analysis, potential threats and vulnerabilities, existing security controls, and the likelihood and impact of potential risks to ePHI.

  3. An organization updates its password policy. What documentation action is required under HIPAA?

    Answer: The new policy must be documented and the prior version retained for 6 years

    Any changes to HIPAA-required policies must be documented, and prior versions must also be retained for the required 6-year period from when they were last in effect.

  4. Which of the following is an example of required Security Rule documentation?

    Answer: Facility access logs and audit trails for ePHI systems

    The Security Rule requires documentation of audit logs, access controls, and other safeguards implemented to protect ePHI from unauthorized access.

  5. A small physician practice stores its HIPAA documentation on paper. Is this compliant?

    Answer: Yes, HIPAA documentation may be maintained in written or electronic form

    HIPAA does not mandate a specific format for documentation and permits covered entities to maintain required records in either written or electronic form.

  6. What is the purpose of documenting a covered entity's contingency plan?

    Answer: To demonstrate preparedness for ePHI access during system emergencies and ensure continuity

    Documenting the contingency plan under the Security Rule ensures the organization has a tested, retrievable plan for maintaining access to ePHI during system failures, disasters, or emergencies.

  7. If a business associate agreement (BAA) is amended, what must the covered entity do with the original BAA?

    Answer: Retain the original BAA for 6 years from when it was last in effect

    Superseded BAAs must be retained for 6 years from the date they were last in effect, consistent with HIPAA's general documentation retention requirements.