โ† All Epic Skills Assessment Flashcard Decks

Information Security & HIPAA Compliance Flashcards

7 cards from real Epic Skills Assessment practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Security & HIPAA Compliance flashcards as text
  1. Which of the following is an administrative safeguard under the HIPAA Security Rule?

    Answer: Conducting regular workforce security training and awareness programs

    Workforce security training is an administrative safeguard, as it involves policies, procedures, and workforce management rather than physical or technical controls.

  2. A patient requests that their doctor not share their mental health records with their employer. Under HIPAA, the covered entity must:

    Answer: Honor the restriction request for disclosures the patient pays for out of pocket

    Under HIPAA, covered entities must honor a patient's request to restrict disclosure of PHI to a health plan for services paid entirely out of pocket.

  3. When a user logs into Epic, the system requires both a password and a one-time code sent to their mobile device. This security mechanism is called:

    Answer: Multi-factor authentication (MFA)

    Multi-factor authentication requires two or more verification factors (something you know + something you have), significantly reducing the risk of unauthorized access.

  4. De-identification of PHI under HIPAA's Safe Harbor method requires removing how many specific identifiers?

    Answer: 18

    HIPAA's Safe Harbor de-identification method requires removing 18 specific types of identifiers (such as name, dates, ZIP codes, and device identifiers) to render data non-identifiable.

  5. An employee notices a colleague printing large volumes of patient records and taking them home. The MOST appropriate first action is to:

    Answer: Report the suspicious activity to the privacy or compliance officer

    Suspicious activity involving PHI should be reported immediately to the privacy or compliance officer, who has the authority and tools to investigate properly.

  6. Which of the following represents the principle of 'data integrity' in the context of ePHI?

    Answer: Ensuring ePHI has not been altered or destroyed in an unauthorized manner

    Data integrity means that ePHI remains accurate and unaltered except through authorized processes, protecting it from unauthorized modification or destruction.

  7. A healthcare organization's workforce member accidentally emails PHI to the wrong patient. Under HIPAA, this event is BEST classified as:

    Answer: A potential breach requiring risk assessment to determine notification obligations

    Accidental disclosures trigger a four-factor risk assessment to determine if a breach occurred and whether notification is required under the Breach Notification Rule.