โ† All AHIC Flashcard Decks

Privacy and Security Flashcards

7 cards from real AHIC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Privacy and Security flashcards as text
  1. Under HIPAA, which of the following is considered a 'business associate' requiring a formal agreement?

    Answer: A billing company that processes PHI on behalf of a covered entity

    A business associate is any entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity, such as a billing company.

  2. Which authentication control best mitigates the risk of credential theft in a health informatics environment?

    Answer: Multi-factor authentication (MFA)

    MFA requires multiple verification factors, significantly reducing the risk of unauthorized access even if credentials are stolen.

  3. A covered entity discovers a breach affecting 600 individuals. What is the HIPAA notification deadline to the Secretary of HHS?

    Answer: 60 days after the end of the calendar year

    Breaches affecting fewer than 500 individuals must be reported to HHS within 60 days after the end of the calendar year in which the breach was discovered.

  4. What does the concept of 'minimum necessary' require under the HIPAA Privacy Rule?

    Answer: Access to PHI must be limited to the least amount needed to accomplish the purpose

    The minimum necessary standard requires that PHI be used, disclosed, or requested only to the extent needed to accomplish the intended purpose.

  5. Which security framework is most widely referenced for establishing information security controls in U.S. healthcare organizations?

    Answer: NIST Cybersecurity Framework

    The NIST Cybersecurity Framework is widely adopted in U.S. healthcare for structuring security programs around Identify, Protect, Detect, Respond, and Recover functions.

  6. A ransomware attack encrypts a hospital's EHR system. Under HIPAA, this event is presumed to be:

    Answer: A breach unless the covered entity can demonstrate low probability of PHI compromise

    Per HHS guidance, ransomware attacks are presumed breaches unless the entity can demonstrate a low probability that PHI was compromised under the four-factor risk assessment.

  7. Which of the following best describes role-based access control (RBAC) in a clinical setting?

    Answer: Access rights are assigned based on predefined organizational roles such as nurse or pharmacist

    RBAC grants permissions based on a user's role within the organization, ensuring staff only access data relevant to their function.