โ† All CCS Flashcard Decks

Security Principles and Practices Flashcards

7 cards from real CCS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Principles and Practices flashcards as text
  1. Under HIPAA, which of the following is NOT considered protected health information (PHI)?

    Answer: De-identified patient data with all 18 identifiers removed

    Data that has had all 18 HIPAA identifiers removed through proper de-identification is no longer considered PHI.

  2. A coding specialist receives a request for medical records from a patient's employer. Under HIPAA, the coder should:

    Answer: Require a valid patient authorization before releasing any records

    Employers are not covered entities, so a valid signed patient authorization is required before releasing PHI to them.

  3. Which security measure ensures that electronic PHI has not been altered or destroyed in an unauthorized manner?

    Answer: Integrity control

    Integrity controls protect ePHI from unauthorized alteration or destruction, ensuring data accuracy and completeness.

  4. A hospital's coding department stores patient files on shared drives. Which access control approach best aligns with the minimum necessary standard?

    Answer: Access is limited to only the data needed to perform each job function

    The minimum necessary standard requires limiting access to only the PHI needed for each employee to perform their specific job duties.

  5. What is the primary purpose of a Business Associate Agreement (BAA) under HIPAA?

    Answer: To ensure vendors who handle PHI comply with HIPAA privacy and security rules

    A BAA is a contract requiring business associates who access PHI on behalf of a covered entity to safeguard that information per HIPAA requirements.

  6. An audit log in a health information system primarily serves which security purpose?

    Answer: Tracking and reviewing who accessed or modified patient records

    Audit logs record access and changes to ePHI, enabling detection of unauthorized or suspicious activity in health information systems.

  7. When a covered entity discovers a breach of unsecured PHI affecting 600 patients, HIPAA requires notification to:

    Answer: Affected individuals, HHS, and prominent local media outlets

    For breaches affecting 500 or more individuals in a state, HIPAA requires notifying affected individuals, HHS, and prominent media in that state.