Security Principles and Practices Flashcards
7 cards from real CCS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Principles and Practices flashcards as text
A healthcare organization must ensure patient data remains accessible during a system outage. Which element of the CIA triad does this address?
Answer: Availability
Availability ensures that authorized users can access information and systems when needed, including during outages or disasters.
What is the role of a Privacy Officer in a healthcare organization?
Answer: Developing and implementing HIPAA privacy policies and handling complaints
The Privacy Officer is responsible for developing and enforcing HIPAA privacy policies, training staff, and serving as the point of contact for privacy complaints.
Which of the following is an example of a 'technical safeguard' under the HIPAA Security Rule?
Answer: Implementing multi-factor authentication for EHR access
Technical safeguards are technology-based controls like MFA, encryption, and automatic logoff that protect ePHI from unauthorized access.
A patient asks a hospital not to disclose their mental health treatment to their adult children. Under HIPAA, the hospital should:
Answer: Honor the restriction request as long as the patient pays out of pocket for that service
Under HIPAA, if a patient pays out of pocket in full for a service, they may request that the provider not disclose that information to their health plan, and the provider must comply.
Social engineering in the context of healthcare information security refers to:
Answer: Manipulating people into revealing confidential information or granting unauthorized access
Social engineering involves psychologically manipulating individuals into divulging confidential information or performing actions that compromise security.
Which HIPAA rule requires covered entities to notify patients when their unsecured PHI has been improperly disclosed?
Answer: The Breach Notification Rule
The HIPAA Breach Notification Rule requires covered entities and business associates to notify affected individuals, HHS, and sometimes the media following a breach of unsecured PHI.
A coding specialist accidentally sends a fax containing patient information to the wrong number. This is best categorized as:
Answer: An impermissible disclosure that must be assessed as a potential breach
Accidental misdirected faxes are impermissible disclosures that must undergo a four-factor risk assessment to determine if they constitute a reportable breach.