โ† All CSC Flashcard Decks

HIPAA Security Rule Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 HIPAA Security Rule flashcards as text
  1. Under the HIPAA Security Rule, which type of safeguard specifically addresses workforce training and security awareness programs?

    Answer: Administrative safeguards

    Administrative safeguards include workforce training, security awareness, and policies governing the management of ePHI.

  2. A covered entity discovers a workforce member has been accessing patient records outside their job role for three months. Which HIPAA Security Rule standard is most directly implicated?

    Answer: Information Access Management

    Information Access Management requires implementing policies that authorize access to ePHI based on job role, preventing unauthorized access.

  3. What does the HIPAA Security Rule require regarding the transmission of ePHI over open networks?

    Answer: Encryption or equivalent measures must protect ePHI in transit

    The Security Rule requires covered entities to implement technical security measures to guard against unauthorized access to ePHI transmitted over open networks.

  4. Which of the following is an example of a physical safeguard under the HIPAA Security Rule?

    Answer: Facility access controls with badge readers

    Physical safeguards include facility access controls such as badge readers, locks, and security cameras that limit physical access to systems containing ePHI.

  5. The HIPAA Security Rule's 'minimum necessary' concept most directly applies to which safeguard category?

    Answer: Administrative safeguards via access management

    Administrative safeguards including Information Access Management implement the minimum necessary standard by granting role-based access to ePHI.

  6. A hospital's contingency plan fails during a ransomware attack because backups were also encrypted. Which required implementation specification was inadequately addressed?

    Answer: Data Backup Plan

    The Data Backup Plan specification requires creating and maintaining retrievable exact copies of ePHI, which must be protected and stored separately.

  7. Under HIPAA Security Rule, how often must covered entities review and modify their security policies and procedures?

    Answer: Periodically, in response to environmental or operational changes

    The Security Rule requires covered entities to review and update policies and procedures in response to environmental or operational changes affecting ePHI security.