HIPAA Security Rule Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 HIPAA Security Rule flashcards as text
A covered entity is evaluating whether to implement a specific HIPAA Security Rule safeguard. The entity determines the cost outweighs the risk reduction benefit. Under HIPAA, this analysis is valid when the specification is:
Answer: Addressable, because addressable specifications allow risk-based alternatives
Addressable implementation specifications allow covered entities to assess whether the specification is reasonable and appropriate based on their risk analysis, and to implement alternatives if not.
Which of the following is NOT included in the HIPAA Security Rule's definition of electronic protected health information (ePHI)?
Answer: De-identified patient data in an analytics database
De-identified health information that meets HIPAA's de-identification standards is not considered PHI and is therefore not subject to HIPAA Security Rule protections.
Under the HIPAA Security Rule, which entity is primarily responsible for ensuring that a business associate complies with applicable Security Rule requirements?
Answer: The business associate itself, with no covered entity oversight required
Business associates are directly liable for their own Security Rule compliance under the HITECH Act; covered entities fulfill their obligation by executing a compliant BAA.
A healthcare provider's risk analysis identifies a high-risk vulnerability in a legacy system. The provider decides to accept the risk without implementing additional controls. Under HIPAA, this decision:
Answer: May be permissible if documented with rationale, but increases breach liability
While HIPAA does not prohibit risk acceptance, the decision must be documented, and accepting high risks can increase regulatory and breach liability exposure.
The HIPAA Security Rule requires covered entities to implement a 'unique user identification' control primarily to:
Answer: Enable tracking and monitoring of individual user activity in ePHI systems
Unique user IDs enable covered entities to track and audit which specific individuals accessed or modified ePHI, supporting accountability and incident investigation.
A hospital workforce member reports a stolen laptop containing unencrypted ePHI. Under HIPAA, the hospital's first obligation is to:
Answer: Conduct a breach risk assessment to determine if notification is required
The HIPAA Breach Notification Rule requires a four-factor risk assessment to determine if the incident constitutes a reportable breach before notification obligations are triggered.
Which HIPAA Security Rule standard most directly requires covered entities to have a plan for restoring access to ePHI during a system outage?
Answer: Emergency Mode Operation Plan
The Emergency Mode Operation Plan specification requires procedures to enable the continuation of critical business processes for the protection of ePHI during system emergencies.