← All HIPAA Flashcard Decks

Technical & Physical Safeguards Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Technical & Physical Safeguards flashcards as text
  1. HIPAA's Transmission Security standard requires covered entities to guard against unauthorized access to ePHI during transmission. Which implementation specification is addressable under this standard?

    Answer: Encryption of data in transit

    Encryption of ePHI in transit is an addressable implementation specification under the Transmission Security standard; covered entities must implement it or document why it is not reasonable.

  2. Under the Device and Media Controls standard, the 'accountability' implementation specification requires covered entities to maintain records of:

    Answer: The movements of hardware and electronic media

    The accountability specification requires a record of the movements of hardware and electronic media and the person responsible for those movements.

  3. What does the 'unique user identification' implementation specification under HIPAA's Access Control standard require?

    Answer: Each user must use a unique name or number to identify themselves

    Unique user identification requires assigning each user a unique name or number so system activity can be traced to that specific individual.

  4. A covered entity experiences a power outage affecting its data center. Which Physical Safeguard implementation specification addresses restoring access to ePHI during emergencies?

    Answer: Contingency Operations

    Contingency Operations procedures establish how to restore access to data protected by access controls in the event of a disaster or emergency.

  5. Under HIPAA technical safeguards, which standard specifically addresses ensuring that ePHI transmitted over an electronic network has not been improperly modified?

    Answer: Integrity

    The Integrity standard requires policies and procedures to protect ePHI from improper alteration or destruction, including during transmission.

  6. A practice's policy requires that all laptops used off-site must have full-disk encryption enabled. This addresses which category of HIPAA safeguard?

    Answer: Physical Safeguards — Device and Media Controls

    Full-disk encryption on portable devices is a control under Device and Media Controls, which governs hardware and media that house ePHI.

  7. What is the primary goal of the 'Person or Entity Authentication' standard under HIPAA's Technical Safeguards?

    Answer: To verify that a person or entity seeking access is who they claim to be

    Person or Entity Authentication requires implementing procedures to verify the identity of anyone seeking access to ePHI.