โ† All HIPAA Flashcard Decks

Administrative Safeguards Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Administrative Safeguards flashcards as text
  1. Which of the following is an ADDRESSABLE implementation specification under the Security Management Process standard?

    Answer: Information system activity review

    Information system activity review is an addressable specification, meaning entities must assess whether it is reasonable and appropriate given their environment.

  2. A small medical practice decides not to implement an addressable specification. What must they do?

    Answer: Document the reason and implement an equivalent alternative if reasonable

    If an addressable specification is not implemented, the entity must document why it is not reasonable and appropriate and whether an equivalent alternative measure has been implemented.

  3. What is the scope of HIPAA's workforce training requirement under Administrative Safeguards?

    Answer: All workforce members, including volunteers and trainees

    Security awareness training must be provided to all workforce members, including management, regardless of whether they directly handle ePHI.

  4. Under the Security Management Process, what is the purpose of 'information system activity review'?

    Answer: To audit logs, access reports, and security incident tracking reports

    Information system activity review involves regularly reviewing records of activity such as audit logs and access reports to detect security incidents.

  5. A covered entity undergoes a merger. Which Administrative Safeguard process must be updated to reflect the new organizational structure?

    Answer: Security policies and procedures, including risk analysis

    A merger constitutes a significant operational change that triggers a review and update of security policies and procedures, including a new or updated risk analysis.

  6. Which of the following best describes the 'termination procedures' implementation specification under workforce security?

    Answer: Procedures for revoking access to ePHI when employment ends

    Termination procedures ensure that when a workforce member's employment ends, their access to ePHI systems is promptly revoked.

  7. A HIPAA-covered entity's security training includes reminders about malicious software. This training element maps to which implementation specification?

    Answer: Protection from malicious software

    Training on malicious software falls under the 'protection from malicious software' addressable specification within the security awareness and training standard.