← All HIPAA Flashcard Decks

Technical & Physical Safeguards Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Technical & Physical Safeguards flashcards as text
  1. Under HIPAA, which of the following best distinguishes 'required' from 'addressable' implementation specifications?

    Answer: Required specs must be implemented; addressable specs must be assessed and either implemented or documented as to why they are not reasonable

    Required specifications must be implemented as stated; addressable specifications require a risk-based assessment and either implementation or documented justification for an alternative measure.

  2. A covered entity's access control policy assigns each employee a role (e.g., nurse, biller) and grants ePHI access based on that role. This implements which type of access control model?

    Answer: Role-Based Access Control (RBAC)

    Role-Based Access Control (RBAC) restricts system access based on a user's organizational role, which aligns with HIPAA's minimum necessary principle.

  3. A health system's security officer discovers that a former employee's access credentials were not disabled after termination. Which HIPAA technical safeguard was violated?

    Answer: Access Control — Unique User Identification

    Unique User Identification requires that access credentials are managed per individual, including timely revocation when employment ends.

  4. A covered entity needs to move a server containing ePHI to a new facility. Which physical safeguard specification is most relevant to documenting this move?

    Answer: Device and Media Controls — Accountability

    The Accountability specification under Device and Media Controls requires documenting the movement of hardware and electronic media and the individuals responsible.

  5. Which of the following is NOT a technical safeguard standard under the HIPAA Security Rule?

    Answer: Workstation Security

    Workstation Security is a Physical Safeguard standard, not a Technical Safeguard; the Technical Safeguard standards are Access Control, Audit Controls, Integrity, Person or Entity Authentication, and Transmission Security.

  6. After a risk analysis, a small clinic determines that encrypting ePHI transmissions over its internal network is not reasonable given its current infrastructure. What must the clinic do?

    Answer: Document the rationale and implement an equivalent alternative measure

    Because transmission encryption is an addressable specification, the clinic must document its reasoning and implement a reasonable alternative that achieves the same protection.

  7. A covered entity implements biometric fingerprint scanners to verify the identity of users accessing ePHI. This satisfies which HIPAA Technical Safeguard standard?

    Answer: Person or Entity Authentication

    Person or Entity Authentication requires procedures to verify identity before granting access to ePHI; biometric scanners are an accepted authentication mechanism.