The HIPAA Security Rule Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 The HIPAA Security Rule flashcards as text
A hospital's Security Officer wants to verify that ePHI received from a partner has not been corrupted in transit. Which Security Rule standard applies?
Answer: Integrity Controls within Transmission Security
Transmission Security includes an addressable implementation specification for integrity controls to ensure ePHI is not improperly modified during transmission.
Which of the following is NOT a standard under the Administrative Safeguards of the HIPAA Security Rule?
Answer: Workstation Use
Workstation Use is a standard under Physical Safeguards, not Administrative Safeguards.
A covered entity contracts with a software vendor to process claims containing ePHI. What must be in place before sharing ePHI with the vendor?
Answer: A Business Associate Agreement (BAA)
Before sharing ePHI with a business associate, the covered entity must have a signed Business Associate Agreement specifying permitted uses and security obligations.
Under the HIPAA Security Rule, which of the following best describes 'ePHI'?
Answer: Individually identifiable health information created, received, maintained, or transmitted in electronic form
ePHI is individually identifiable health information that is created, received, maintained, or transmitted in any electronic format by a covered entity or business associate.
Which Security Rule standard requires training programs to educate workforce members about potential threats to ePHI security?
Answer: Security Awareness and Training
Security Awareness and Training is an Administrative Safeguards standard requiring covered entities to train all workforce members on security policies and procedures.
A covered entity periodically reviews whether its security measures are still sufficient against evolving threats. This activity corresponds to which Administrative Safeguard standard?
Answer: Evaluation
The Evaluation standard requires covered entities to perform periodic technical and nontechnical assessments of whether security policies and procedures meet Security Rule requirements.
Which of the following scenarios would most likely constitute a violation of the HIPAA Security Rule's Workforce Security standard?
Answer: A new employee is given broad ePHI system access without any role-based authorization review
Granting ePHI access without assessing whether access is appropriate for the employee's role violates the Workforce Security standard's clearance procedures.