Security Principles and Practices Flashcards
7 cards from real CCS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Principles and Practices flashcards as text
Which of the following best describes 'role-based access control' (RBAC) in a healthcare setting?
Answer: Access permissions are assigned based on each employee's job function and duties
RBAC restricts system access so that employees can only view or modify data relevant to their specific job role, supporting the minimum necessary standard.
The HITECH Act strengthened HIPAA primarily by:
Answer: Extending HIPAA's privacy and security requirements to business associates and increasing penalties
HITECH expanded HIPAA enforcement by making business associates directly liable for HIPAA compliance and significantly increasing civil and criminal penalties for violations.
A healthcare worker notices a colleague looking up records of a celebrity patient without a clinical reason. The worker should:
Answer: Report the activity to the Privacy Officer or compliance department
Accessing records without a legitimate clinical purpose is a HIPAA violation, and employees are obligated to report such suspicious activity through proper channels.
Which of the following is a valid 'safe harbor' method for de-identifying patient data under HIPAA?
Answer: Removing all 18 specific identifiers listed by HIPAA and having no knowledge of residual identification risk
HIPAA's safe harbor method requires removal of all 18 designated identifiers and a reasonable belief that the remaining data cannot identify an individual.
What does 'need-to-know' mean in the context of healthcare information security?
Answer: Staff should only access PHI required to perform their specific assigned duties
The need-to-know principle restricts information access to individuals who require it to accomplish a specific, legitimate job function.
A phishing email tricks a coding employee into entering her EHR credentials on a fake website. This attack primarily exploits:
Answer: Human error and lack of security awareness training
Phishing attacks exploit human psychology and lack of awareness rather than technical system vulnerabilities, making security training a critical countermeasure.
Which of the following actions would best protect ePHI stored on a laptop used by a remote coder?
Answer: Using full-disk encryption and requiring a strong password at startup
Full-disk encryption ensures that even if a laptop is lost or stolen, the ePHI stored on it cannot be accessed without the decryption credentials.