Administrative Safeguards Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Administrative Safeguards flashcards as text
Under HIPAA, how long must covered entities retain documentation of their security policies and procedures?
Answer: 6 years from the date of creation or last effective date
HIPAA requires that documentation of security policies and procedures be retained for 6 years from the date of creation or the date it was last in effect, whichever is later.
A covered entity's risk management plan must reduce risks to ePHI to:
Answer: A reasonable and appropriate level
Risk management requires implementing security measures to reduce risks and vulnerabilities to a reasonable and appropriate level, not to eliminate all risk.
Which scenario represents proper use of the 'applications and data criticality analysis' specification within the contingency plan?
Answer: Ranking ePHI applications by their business importance to prioritize recovery order
Applications and data criticality analysis involves assessing the relative criticality of specific applications and data to prioritize recovery efforts during a disaster.
Security awareness training under HIPAA must be provided to workforce members:
Answer: Periodically and with updates as environmental changes warrant
Training must be provided to all workforce members periodically and updated as needed when environmental or operational changes affect ePHI security.
A clinic's IT administrator implements automatic logoff on workstations after 15 minutes of inactivity. Which standard does this support?
Answer: Access control (Technical Safeguards)
Automatic logoff is a Technical Safeguard under access control, not an Administrative Safeguard, though administrative policies may require it.
Under the Information Access Management standard, which implementation specification controls who can access ePHI based on job function?
Answer: Access establishment and modification
Access establishment and modification requires documented policies for granting, changing, and revoking ePHI access based on the workforce member's role.
A covered entity that is also a health care clearinghouse must, under Administrative Safeguards:
Answer: Implement policies to protect ePHI from unauthorized access by the rest of the organization
If a covered entity performs clearinghouse functions, it must implement policies to protect clearinghouse ePHI from unauthorized access by the larger organization.