Medical Device Cybersecurity and Information Security Flashcards
7 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Medical Device Cybersecurity and Information Security flashcards as text
What is the HITRUST CSF (Common Security Framework) primarily used for in healthcare organizations?
Answer: Providing a certifiable, comprehensive information risk management and compliance framework for healthcare
HITRUST CSF provides a comprehensive, certifiable framework that consolidates healthcare information security and compliance requirements from HIPAA, NIST, ISO, and other standards.
Which component of HIPAA specifically establishes standards for protecting electronic protected health information (ePHI)?
Answer: HIPAA Security Rule establishing administrative, physical, and technical safeguards for ePHI
The HIPAA Security Rule establishes national standards for protecting ePHI through required and addressable administrative, physical, and technical safeguards.
What primary cybersecurity benefit does network segmentation provide for medical devices in a hospital environment?
Answer: Limits the lateral spread of cyberattacks by containing compromised devices within network segments
Network segmentation contains compromised devices within their segment, preventing attackers from moving laterally to other clinical systems or stealing data from other network areas.
What is the primary purpose of penetration testing conducted on medical devices?
Answer: To simulate real cyberattacks to proactively identify security vulnerabilities before malicious actors exploit them
Penetration testing simulates real-world cyberattacks in a controlled manner to identify and remediate security vulnerabilities before they can be exploited by malicious actors in the field.
What is the primary role of a patch management policy in medical device cybersecurity?
Answer: To establish systematic processes for evaluating, testing, and applying security updates to medical devices
A patch management policy establishes systematic processes for evaluating, testing, and applying security updates while ensuring device functionality, patient safety, and regulatory compliance are maintained.
What does 'authentication' specifically ensure within a medical device access control system?
Answer: That users or systems are verified to be who they claim to be before access is granted
Authentication verifies the identity of users or systems attempting to access a medical device, ensuring only authorized individuals or systems can interact with the device.
Which of the following best describes a 'supply chain attack' in the context of medical device security?
Answer: A cyberattack that compromises medical device software or hardware during manufacturing or distribution before reaching the healthcare facility
A supply chain attack compromises devices during manufacturing or distribution by inserting malicious code or hardware, making the device a threat before it is ever deployed in a clinical setting.