Privacy and Security Flashcards
7 cards from real AHIC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Privacy and Security flashcards as text
Which of the following is an example of a physical safeguard under the HIPAA Security Rule?
Answer: Badge-controlled access to server rooms
Physical safeguards control physical access to facilities and equipment where ePHI is stored, such as badge-controlled entry to server rooms.
An organization receives a subpoena for a patient's medical records. Which HIPAA provision is most relevant?
Answer: The Privacy Rule's required disclosures for law enforcement with proper process
HIPAA permits disclosures in response to a court order or subpoena under specific conditions outlined in the Privacy Rule's law enforcement provisions.
De-identification of PHI under HIPAA can be achieved through which two official methods?
Answer: Expert determination and the Safe Harbor method
HIPAA recognizes Expert Determination (statistical certification) and Safe Harbor (removal of 18 specific identifiers) as the two official de-identification methods.
Which federal law grants patients the right to access their electronic health information and requires covered entities to provide it in a machine-readable format?
Answer: 21st Century Cures Act
The 21st Century Cures Act strengthened information blocking rules and mandated that patients receive electronic access to their health data via standardized APIs.
A healthcare organization's disaster recovery plan should prioritize restoring which systems first after a cyberattack?
Answer: Clinical systems that directly affect patient safety and care delivery
Clinical systems affecting patient safety must be restored first to minimize harm, reflecting the healthcare industry's patient-first recovery prioritization.
What is 'tailgating' in the context of healthcare facility security?
Answer: An unauthorized person following an authorized person through a secured entry point
Tailgating is a physical security breach where an unauthorized individual gains access to a restricted area by following an authorized person.
Under HIPAA, a covered entity's Notice of Privacy Practices (NPP) must be provided:
Answer: At the first service delivery and upon request thereafter
Covered entities must provide the NPP no later than the date of first service delivery and must make it available upon request at all times.