← All CSC Flashcard Decks

HIPAA Security Rule Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 HIPAA Security Rule flashcards as text
  1. Which HIPAA Security Rule implementation specification requires a covered entity to obtain satisfactory assurances from business associates before sharing ePHI?

    Answer: Business Associate Contracts

    Business Associate Contracts (or other arrangements) are an addressable implementation specification requiring documented assurances that business associates will protect ePHI.

  2. A healthcare organization uses a cloud storage provider to store patient imaging files. Under HIPAA, the cloud provider is best classified as:

    Answer: A business associate requiring a signed BAA

    Cloud service providers handling ePHI on behalf of covered entities are business associates and must sign a Business Associate Agreement (BAA).

  3. The HIPAA Security Rule's 'integrity' controls are designed to protect ePHI from which specific threat?

    Answer: Unauthorized alteration or destruction

    Integrity controls ensure that ePHI is not improperly altered or destroyed, protecting the accuracy and completeness of health information.

  4. Under the Security Rule, which standard governs the processes for creating, changing, and safeguarding passwords?

    Answer: Access Control — Password Management

    Password management is an addressable implementation specification under the Access Control standard of HIPAA Technical Safeguards.

  5. A small medical practice claims it does not need to conduct a formal risk analysis because it uses a certified EHR system. This claim is:

    Answer: Invalid, because every covered entity must conduct its own risk analysis regardless of software used

    Every covered entity, regardless of size or software used, must conduct its own risk analysis as a required implementation specification under HIPAA.

  6. Which scenario best illustrates a violation of the HIPAA Security Rule's Workstation Use standard?

    Answer: A receptionist uses a shared workstation to browse social media while logged into the EHR

    The Workstation Use standard requires policies specifying the proper functions and manner of use for workstations that access ePHI, prohibiting unauthorized uses.

  7. What is the primary purpose of 'audit controls' as a technical safeguard under the HIPAA Security Rule?

    Answer: To record and examine activity in systems containing ePHI

    Audit controls require hardware, software, and procedural mechanisms that record and examine activity in information systems containing ePHI for accountability and forensics.