HIPAA Security Rule Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 HIPAA Security Rule flashcards as text
Under the HIPAA Security Rule, which of the following scenarios would trigger the requirement for a formal Security Rule risk analysis?
Answer: A covered entity implements a new EHR system that stores ePHI
Any new system that creates, receives, maintains, or transmits ePHI triggers the need to update or conduct a risk analysis to identify new vulnerabilities.
A HIPAA Security Officer at a covered entity is drafting workforce sanction policies. What must these policies include to meet HIPAA requirements?
Answer: Consequences for workforce members who fail to comply with security policies
HIPAA requires covered entities to apply appropriate sanctions against workforce members who fail to comply with security policies, with the specific consequences determined by the entity.
A covered entity's Security Rule risk management process must prioritize addressing risks based on:
Answer: The likelihood and impact of potential ePHI compromise
Risk management under HIPAA requires implementing security measures sufficient to reduce risks to reasonable and appropriate levels based on likelihood and impact of threats.
Which of the following best describes the relationship between the HIPAA Privacy Rule and the HIPAA Security Rule?
Answer: The Privacy Rule covers all PHI while the Security Rule covers only ePHI
The Privacy Rule applies to all forms of PHI (paper, oral, electronic), while the Security Rule specifically addresses protections for ePHI in electronic form.
A covered entity's HIPAA Security Officer wants to verify that technical controls are functioning as intended. Which activity best fulfills this objective?
Answer: Reviewing and testing audit logs from EHR systems
Reviewing and testing audit logs allows the Security Officer to verify that access controls, audit controls, and other technical safeguards are operating as designed.
Under HIPAA, which of the following small covered entity configurations may use an 'alternative measure' instead of fully implementing an addressable specification?
Answer: Any covered entity that documents why the alternative provides equivalent protection
Any covered entity may implement a reasonable alternative to an addressable specification as long as it documents the rationale and how the alternative achieves equivalent protection.
An IT vendor with access to a covered entity's ePHI systems notifies the covered entity of a potential security incident affecting ePHI. Under HIPAA, the vendor must report this within:
Answer: Without unreasonable delay as specified in the BAA
Business associates must report security incidents to covered entities without unreasonable delay, with the specific timeframe typically defined in the Business Associate Agreement.