โ† All CHP Flashcard Decks

Risk Management & Compliance Audits Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Management & Compliance Audits flashcards as text
  1. During a HIPAA compliance audit, what is the PRIMARY purpose of reviewing an organization's Notice of Privacy Practices (NPP)?

    Answer: To verify patients receive required disclosures about PHI use

    The NPP must inform patients how their PHI may be used and disclosed, and auditors verify it meets all required content elements under the Privacy Rule.

  2. Which of the following BEST describes a 'gap analysis' in the context of HIPAA risk management?

    Answer: A comparison of current compliance posture against required standards to identify deficiencies

    A gap analysis identifies where an organization's current controls fall short of HIPAA requirements, forming the foundation for a remediation plan.

  3. Under HIPAA, which type of risk assessment methodology involves assigning numerical probability and impact scores to identified threats?

    Answer: Quantitative risk assessment

    Quantitative risk assessment uses numerical values to calculate risk levels, enabling organizations to prioritize remediation based on measurable scores.

  4. A covered entity discovers that a workforce member has been accessing patient records without a legitimate work reason for six months. What HIPAA violation does this most directly represent?

    Answer: Breach of the Minimum Necessary standard

    HIPAA's Minimum Necessary standard requires workforce members to access only the PHI needed to perform their job functions.

  5. When conducting an internal HIPAA audit, which document serves as the authoritative baseline for evaluating administrative safeguard compliance?

    Answer: The HIPAA Security Rule (45 CFR Part 164, Subpart C)

    The HIPAA Security Rule codified at 45 CFR Part 164, Subpart C, establishes the required and addressable administrative safeguard standards.

  6. Which corrective action plan (CAP) component is MOST critical following an OCR investigation finding of non-compliance?

    Answer: Specific milestones and timelines for achieving compliance

    OCR requires CAPs to include specific, measurable milestones and deadlines so that progress toward full compliance can be monitored and verified.

  7. A business associate fails to report a security incident to the covered entity within a reasonable timeframe. What is the covered entity's BEST immediate response?

    Answer: Assess whether the incident constitutes a reportable breach and document the BA's notification failure

    The covered entity must first determine if a breach occurred and document the BA's failure, as both the breach assessment and the BA's non-compliance require separate remediation.