AHIC Privacy and Security 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a 'business associate' requiring a formal agreement?
- A billing company that processes PHI on behalf of a covered entity (Correct answer)
- A patient's family member who helps manage medical records
- A hospital employee who accesses EHR for treatment purposes
- A state health department receiving data for public health reporting
Correct answer: A billing company that processes PHI on behalf of a covered entity
A business associate is any entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity, such as a billing company.
Question 2: Which authentication control best mitigates the risk of credential theft in a health informatics environment?
- Single-factor password authentication
- Multi-factor authentication (MFA) (Correct answer)
- Shared group logins for clinical staff
- Security questions as a backup method
Correct answer: Multi-factor authentication (MFA)
MFA requires multiple verification factors, significantly reducing the risk of unauthorized access even if credentials are stolen.
Question 3: A covered entity discovers a breach affecting 600 individuals. What is the HIPAA notification deadline to the Secretary of HHS?
- 30 days after discovery
- 60 days after discovery
- 60 days after the end of the calendar year (Correct answer)
- Within 30 days of the calendar year end
Correct answer: 60 days after the end of the calendar year
Breaches affecting fewer than 500 individuals must be reported to HHS within 60 days after the end of the calendar year in which the breach was discovered.
Question 4: What does the concept of 'minimum necessary' require under the HIPAA Privacy Rule?
- Covered entities must encrypt all PHI at all times
- Access to PHI must be limited to the least amount needed to accomplish the purpose (Correct answer)
- Patients must sign a minimum of two consent forms before receiving care
- Healthcare providers must minimize the number of staff with system access
Correct answer: Access to PHI must be limited to the least amount needed to accomplish the purpose
The minimum necessary standard requires that PHI be used, disclosed, or requested only to the extent needed to accomplish the intended purpose.
Question 5: Which security framework is most widely referenced for establishing information security controls in U.S. healthcare organizations?
- ISO 27001
- NIST Cybersecurity Framework (Correct answer)
- SOC 2 Type II
- PCI DSS
Correct answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework is widely adopted in U.S. healthcare for structuring security programs around Identify, Protect, Detect, Respond, and Recover functions.
Question 6: A ransomware attack encrypts a hospital's EHR system. Under HIPAA, this event is presumed to be:
- A security incident but not a breach unless data was exfiltrated
- A breach unless the covered entity can demonstrate low probability of PHI compromise (Correct answer)
- Not a breach because ransomware does not access or view data
- A breach only if more than 500 patients are affected
Correct answer: A breach unless the covered entity can demonstrate low probability of PHI compromise
Per HHS guidance, ransomware attacks are presumed breaches unless the entity can demonstrate a low probability that PHI was compromised under the four-factor risk assessment.
Question 7: Which of the following best describes role-based access control (RBAC) in a clinical setting?
- Each user sets their own access permissions based on job needs
- Access rights are assigned based on predefined organizational roles such as nurse or pharmacist (Correct answer)
- All clinical staff receive identical system access to ensure care continuity
- Access is granted individually by a system administrator for every resource
Correct answer: Access rights are assigned based on predefined organizational roles such as nurse or pharmacist
RBAC grants permissions based on a user's role within the organization, ensuring staff only access data relevant to their function.
Under HIPAA, which of the following is considered a 'business associate' requiring a formal agreement?