The HIPAA Security Rule Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 The HIPAA Security Rule flashcards as text
Under the HIPAA Security Rule, which safeguard category includes the requirement for 'device and media controls'?
Answer: Physical Safeguards
Device and Media Controls is a standard under Physical Safeguards governing the receipt, removal, and disposal of hardware and media containing ePHI.
A practice must reassign a user's ePHI access rights when that user changes roles. Which specification addresses this?
Answer: Access Establishment and Modification
Access Establishment and Modification is an addressable specification requiring policies to grant, change, and revoke access rights based on an employee's role.
What is the difference between a 'threat' and a 'vulnerability' in the context of a HIPAA Security Rule risk analysis?
Answer: A threat is a potential danger to ePHI; a vulnerability is a weakness that could be exploited by a threat
In risk analysis, a threat is a potential occurrence that could negatively impact ePHI, while a vulnerability is a flaw or weakness that increases the likelihood of that threat causing harm.
A clinic stores backup tapes of ePHI in an unlocked supply closet. Which Security Rule standard is most directly violated?
Answer: Device and Media Controls
Device and Media Controls requires covered entities to implement policies for the secure storage and handling of media containing ePHI.
Which of the following must be documented and retained for at least six years under the HIPAA Security Rule?
Answer: Security Rule policies, procedures, and actions
The Security Rule requires covered entities to retain documentation of their policies, procedures, and required actions for a minimum of six years from creation or last effective date.
An organization assigns each workforce member a unique username to track ePHI access. This satisfies which Security Rule requirement?
Answer: Unique User Identification
Unique User Identification is a required implementation specification under Access Control that assigns each user a unique name or number to track individual activity.
Under the Security Rule, which standard specifically requires mechanisms to record and examine activity in information systems containing ePHI?
Answer: Audit Controls
Audit Controls is a required standard under Technical Safeguards that mandates hardware, software, or procedural mechanisms to record and examine access to ePHI systems.