โ† All AHIC Flashcard Decks

Privacy and Security Flashcards

7 cards from real AHIC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Privacy and Security flashcards as text
  1. Which of the following describes 'data integrity' in the context of healthcare information security?

    Answer: Ensuring that data is not altered or destroyed in an unauthorized manner

    Data integrity means protecting information from unauthorized modification or destruction, ensuring accuracy and completeness of health records.

  2. A hospital uses a cloud-based EHR vendor. To comply with HIPAA, the hospital must:

    Answer: Execute a Business Associate Agreement (BAA) with the cloud vendor

    Any cloud vendor handling PHI on behalf of a covered entity is a business associate and must sign a BAA before PHI is processed or stored.

  3. Which activity would be classified as 'healthcare operations' under HIPAA, permitting use of PHI without patient authorization?

    Answer: Conducting quality assessment and improvement activities

    Quality assessment, auditing, training, and similar administrative activities qualify as healthcare operations, permitting PHI use without patient authorization.

  4. What is the primary risk associated with using unsecured personal mobile devices to access ePHI (BYOD)?

    Answer: Increased risk of data breach through lost, stolen, or compromised personal devices

    BYOD introduces significant breach risk because personal devices may lack organizational security controls and can be lost or stolen.

  5. A social engineering attack in which an attacker impersonates an IT support technician to obtain login credentials is called:

    Answer: Pretexting

    Pretexting involves fabricating a scenario (pretext) to manipulate an individual into revealing sensitive information or granting access.

  6. Under the HIPAA Breach Notification Rule, what four factors must be assessed to determine if there is a low probability of PHI compromise?

    Answer: Nature and extent of PHI, unauthorized person involved, whether PHI was actually acquired, and extent of risk mitigation

    The four-factor risk assessment considers the nature/extent of PHI, the unauthorized person, whether PHI was acquired/viewed, and the extent to which risk has been mitigated.

  7. Which term describes the legal and ethical obligation of healthcare professionals to protect patient information from unauthorized disclosure?

    Answer: Confidentiality

    Confidentiality is the professional and legal duty to keep patient health information private and disclose it only with proper authorization.