Safety & Infection Control Flashcards
7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Safety & Infection Control flashcards as text
Under HIPAA, which entity is primarily responsible for establishing physical safeguards to prevent unauthorized access to areas where PHI is stored or processed?
Answer: The covered entity or business associate
HIPAA's Security Rule requires covered entities and business associates to implement physical safeguards to protect electronic PHI from unauthorized access.
A healthcare worker suspects a colleague is not following proper hand hygiene protocols before accessing workstations containing ePHI. What is the BEST first step?
Answer: Document the behavior and report it to the Privacy or Security Officer
Workforce members should report potential policy violations to the Privacy or Security Officer, who can investigate and address the issue appropriately.
Which type of facility control helps prevent contamination of PHI-containing systems in a clinical environment by limiting access to clean versus dirty zones?
Answer: Physical separation or zoning protocols
Physical separation of clean and dirty zones is an infection control and safety measure that also supports HIPAA physical safeguard requirements by limiting unauthorized access.
A hospital is implementing a new HIPAA-compliant workstation policy in isolation rooms used for infectious patients. Which measure BEST addresses both infection control and HIPAA security?
Answer: Use dedicated, easily disinfectable workstations with automatic screen lock and session timeout
Dedicated, disinfectable workstations with automatic screen lock and session timeout address both infection control (cleanable surfaces) and HIPAA security (access controls).
Which HIPAA Security Rule standard specifically requires covered entities to protect against unauthorized physical access to systems storing ePHI?
Answer: Physical Safeguards — Facility Access Controls
The Physical Safeguards — Facility Access Controls standard requires covered entities to implement policies to limit physical access to electronic information systems while ensuring authorized access.
In a healthcare setting, shared keyboards and touchscreens used to access ePHI are routinely disinfected. From a HIPAA perspective, why is this practice also relevant?
Answer: Contaminated surfaces can harbor pathogens that spread between users, potentially exposing PHI through unclean hands
Infection control practices like disinfecting shared input devices reduce cross-contamination risks and support the integrity of access controls by promoting safe, clean system use.
A business associate agreement (BAA) is being negotiated with a medical waste disposal company that handles documents containing PHI. Which element is MOST critical to include regarding infection and safety controls?
Answer: Provisions ensuring PHI is destroyed in a manner that is both sanitary and renders it unreadable and unrecoverable
The BAA must ensure PHI destruction methods are both safe (sanitary) and compliant with HIPAA's requirement that PHI be rendered unreadable and unrecoverable.