Technical & Physical Safeguards Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Technical & Physical Safeguards flashcards as text
Under HIPAA, which of the following best distinguishes 'required' from 'addressable' implementation specifications?
Answer: Required specs must be implemented; addressable specs must be assessed and either implemented or documented as to why they are not reasonable
Required specifications must be implemented as stated; addressable specifications require a risk-based assessment and either implementation or documented justification for an alternative measure.
A covered entity's access control policy assigns each employee a role (e.g., nurse, biller) and grants ePHI access based on that role. This implements which type of access control model?
Answer: Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) restricts system access based on a user's organizational role, which aligns with HIPAA's minimum necessary principle.
A health system's security officer discovers that a former employee's access credentials were not disabled after termination. Which HIPAA technical safeguard was violated?
Answer: Access Control — Unique User Identification
Unique User Identification requires that access credentials are managed per individual, including timely revocation when employment ends.
A covered entity needs to move a server containing ePHI to a new facility. Which physical safeguard specification is most relevant to documenting this move?
Answer: Device and Media Controls — Accountability
The Accountability specification under Device and Media Controls requires documenting the movement of hardware and electronic media and the individuals responsible.
Which of the following is NOT a technical safeguard standard under the HIPAA Security Rule?
Answer: Workstation Security
Workstation Security is a Physical Safeguard standard, not a Technical Safeguard; the Technical Safeguard standards are Access Control, Audit Controls, Integrity, Person or Entity Authentication, and Transmission Security.
After a risk analysis, a small clinic determines that encrypting ePHI transmissions over its internal network is not reasonable given its current infrastructure. What must the clinic do?
Answer: Document the rationale and implement an equivalent alternative measure
Because transmission encryption is an addressable specification, the clinic must document its reasoning and implement a reasonable alternative that achieves the same protection.
A covered entity implements biometric fingerprint scanners to verify the identity of users accessing ePHI. This satisfies which HIPAA Technical Safeguard standard?
Answer: Person or Entity Authentication
Person or Entity Authentication requires procedures to verify identity before granting access to ePHI; biometric scanners are an accepted authentication mechanism.