โ† All HIPAA Flashcard Decks

Electronic Health Records (EHR) Compliance Flashcards

36 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 20 Electronic Health Records (EHR) Compliance flashcards as text
  1. Under HIPAA, which of the following is a primary requirement for electronic health record systems handling Protected Health Information (PHI)?

    Answer: Implementing access controls that limit PHI access to authorized users

    HIPAA's Security Rule requires covered entities to implement technical access controls ensuring only authorized individuals can access PHI in electronic form.

  2. A hospital migrates to a new EHR system. What HIPAA requirement applies to PHI stored in the old system?

    Answer: It must be retained according to applicable retention laws and securely disposed of when no longer needed

    HIPAA requires that PHI be retained per applicable state and federal retention laws, and disposed of securely when retention periods expire.

  3. Which HIPAA Security Rule standard directly addresses the integrity of electronic PHI in EHR systems?

    Answer: Integrity Controls

    Integrity controls are required under the Technical Safeguards section of the Security Rule to ensure ePHI is not improperly altered or destroyed.

  4. A physician practice uses a cloud-based EHR platform. Under HIPAA, what document is required between the practice and the EHR vendor?

    Answer: A Business Associate Agreement (BAA)

    When a vendor creates, receives, maintains, or transmits PHI on behalf of a covered entity, a Business Associate Agreement is legally required.

  5. Under HIPAA, an EHR system's audit log must capture which of the following?

    Answer: User activity including access, modifications, and disclosures of PHI

    HIPAA requires audit controls that record and examine activity in systems containing ePHI, including who accessed, modified, or disclosed information.

  6. A covered entity discovers that their EHR vendor experienced a data breach. Under HIPAA, when must the covered entity notify affected patients?

    Answer: Within 60 days of discovery of the breach

    HIPAA's Breach Notification Rule requires individual notice to affected patients within 60 days of discovering a breach of unsecured PHI.

  7. Which of the following best describes the 'minimum necessary' standard as applied to EHR access?

    Answer: Access to PHI should be limited to the minimum needed to perform a job function

    HIPAA's minimum necessary standard requires that access to PHI be restricted to only what is needed for the specific task or role.

  8. What is the purpose of automatic logoff in an EHR system under HIPAA?

    Answer: To terminate sessions and prevent unauthorized access after a period of inactivity

    Automatic logoff is an addressable implementation specification under HIPAA that terminates sessions after inactivity to prevent unauthorized access to ePHI.

  9. An EHR system must transmit patient data to a referring specialist. Which HIPAA requirement applies to this transmission?

    Answer: Encryption must be used to protect ePHI during transmission over open networks

    HIPAA's Security Rule requires that ePHI transmitted over open networks be encrypted to protect it from unauthorized interception.

  10. Which federal law expanded HIPAA's requirements and directly increased compliance obligations for EHR systems?

    Answer: The HITECH Act of 2009

    The Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 strengthened HIPAA enforcement and extended requirements to business associates including EHR vendors.

  11. A covered entity implements a new EHR system. What risk analysis requirement does HIPAA impose before go-live?

    Answer: A thorough assessment of potential risks and vulnerabilities to ePHI must be conducted

    HIPAA requires covered entities to conduct a thorough risk analysis to identify threats and vulnerabilities to ePHI before and throughout system operation.

  12. Under HIPAA, which of the following represents appropriate de-identification of patient data in an EHR export?

    Answer: Removing all 18 HIPAA-defined identifiers or applying statistical methods to achieve de-identification

    HIPAA provides two methods for de-identification: removal of all 18 specified identifiers (Safe Harbor) or expert statistical determination that re-identification risk is very small.

  13. What does HIPAA require regarding contingency planning for EHR systems?

    Answer: Covered entities must have data backup, disaster recovery, and emergency mode operation plans

    HIPAA's Security Rule requires organizations to develop contingency plans including data backup, disaster recovery, and emergency mode operation procedures.

  14. A patient requests access to their EHR records. Under HIPAA, what is the covered entity's obligation?

    Answer: The covered entity must provide access within 30 days, with a possible 30-day extension

    HIPAA's Privacy Rule gives patients the right to access their PHI, including electronic records, within 30 days with a permitted 30-day extension.

  15. Which of the following is NOT a required element of a HIPAA Security Rule risk management implementation?

    Answer: Eliminating all identified risks completely

    HIPAA requires reducing risks to a reasonable and appropriate level, not eliminating all risks โ€” complete risk elimination is not feasible or required.

  16. An EHR vendor uses a subcontractor to provide data storage. Under HIPAA, what is required?

    Answer: The business associate (EHR vendor) must obtain a BAA from the subcontractor

    Under HITECH and HIPAA, business associates must obtain BAAs from their subcontractors who create, receive, maintain, or transmit PHI on their behalf.

  17. What is the significance of 'meaningful use' as it relates to HIPAA and EHR compliance?

    Answer: It is a Medicare/Medicaid incentive program promoting certified EHR adoption with specific security criteria

    Meaningful use (now 'Promoting Interoperability') was a CMS incentive program under HITECH that required use of certified EHR technology meeting specific security and interoperability criteria.

  18. Under HIPAA, which practice regarding EHR passwords is explicitly prohibited?

    Answer: Sharing login credentials among colleagues to allow coverage during absences

    Sharing login credentials violates HIPAA's requirement for unique user identification, which is essential for accountability and audit trail integrity.

  19. A covered entity wants to interface their EHR with a health information exchange (HIE). What HIPAA consideration applies?

    Answer: A BAA must be executed with the HIE, and the interface must maintain ePHI security

    HIEs that handle PHI on behalf of covered entities are business associates requiring BAAs, and all ePHI transmitted to/from the HIE must be secured.

  20. What is the HIPAA requirement for workforce training on EHR security?

    Answer: All workforce members with access to EHR systems must receive security awareness training

    HIPAA's Security Rule requires security awareness and training for all workforce members, including periodic updates and reminders.

Electronic Health Records (EHR) Compliance Flashcards โ€” HIPAA Study Cards with Answers