The HIPAA Security Rule Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 The HIPAA Security Rule flashcards as text
A cloud storage vendor holds ePHI on behalf of a covered hospital. Under the HIPAA Security Rule, this vendor is best classified as a:
Answer: Business associate
A vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate subject to the Security Rule.
Under the Security Rule's Integrity standard, what must covered entities implement to ensure ePHI has not been improperly altered or destroyed?
Answer: Mechanisms to authenticate ePHI
The Integrity standard requires technical security mechanisms, such as checksums or hashing, to confirm that ePHI has not been improperly altered or destroyed.
Which of the following is a required implementation specification under the Security Rule's Contingency Plan standard?
Answer: Emergency mode operation plan
Emergency Mode Operation Plan is one of five required specifications under the Contingency Plan, ensuring critical business processes continue during a disaster.
The HIPAA Security Rule requires covered entities to conduct a Risk Analysis. How often must this analysis be performed?
Answer: Periodically and when environmental or operational changes occur
The Security Rule requires periodic risk analyses and reassessment whenever significant changes to operations or the environment occur.
Which Security Rule standard requires covered entities to implement policies ensuring only authorized personnel have access to ePHI?
Answer: Access Control
The Access Control standard under Technical Safeguards requires unique user identification, emergency access procedures, and role-based access to ePHI systems.
A security officer discovers that ePHI is being sent via unencrypted email to external providers. What Security Rule standard is most directly implicated?
Answer: Technical Safeguards — Transmission Security
The Transmission Security standard requires technical measures to guard against unauthorized access to ePHI transmitted over electronic networks.
Which of the following Security Rule requirements addresses what happens when an employee is terminated?
Answer: Termination Procedures
Termination Procedures is an addressable implementation specification under Workforce Security that requires revoking system access for terminated employees.