โ† All CCS Flashcard Decks

Security Principles and Practices Flashcards

7 cards from real CCS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Principles and Practices flashcards as text
  1. A coding specialist working remotely accesses patient records over public Wi-Fi without a VPN. This violates which HIPAA Security Rule requirement?

    Answer: Transmission security safeguards for ePHI

    HIPAA transmission security standards require encryption or equivalent measures when ePHI is transmitted over open networks to prevent unauthorized interception.

  2. Which of the following represents a physical safeguard under the HIPAA Security Rule?

    Answer: Locked server rooms with key card access

    Physical safeguards control physical access to facilities and equipment where ePHI is stored or accessed, such as locked rooms with controlled entry.

  3. A patient requests an amendment to their medical record because they believe it contains an error. Under HIPAA, the covered entity must:

    Answer: Accept or deny the request within 60 days, with a possible 30-day extension

    HIPAA gives covered entities 60 days to respond to amendment requests, with the option to extend by 30 days if they provide written notice.

  4. Which type of malware specifically encrypts an organization's files and demands payment for the decryption key?

    Answer: Ransomware

    Ransomware encrypts victim files or systems and demands a ransom payment, often in cryptocurrency, for the decryption key.

  5. A coder realizes she has been documenting under a colleague's login credentials for two weeks. This situation violates which core security principle?

    Answer: Non-repudiation and individual accountability

    Sharing login credentials undermines non-repudiation and individual accountability, making it impossible to attribute specific actions to the correct user.

  6. Under the HIPAA Minimum Necessary Rule, which scenario is most appropriate?

    Answer: A biller accesses only the claim-related diagnosis and procedure codes needed for billing

    The minimum necessary standard requires that access to PHI be limited to the specific information required to complete the task at hand.

  7. Which federal law specifically addresses the electronic exchange of health information and established nationwide standards for health data security?

    Answer: HIPAA of 1996

    HIPAA of 1996 established the foundational national standards for protecting health information privacy and security in electronic transactions.