CEHRS CEHRS Data Security and Access Control 2 — Questions and Answers
Question 1: What does 'encryption at rest' protect in an EHR system?
- Data stored on hard drives, servers, or portable devices from unauthorized access (Correct answer)
- Data being transmitted between healthcare organizations over networks
- Data displayed on screen from being viewed by unauthorized individuals
- Data backups stored in cloud environments from deletion
Correct answer: Data stored on hard drives, servers, or portable devices from unauthorized access
Encryption at rest protects stored data — on hard drives, servers, USB drives, or laptops — by rendering it unreadable without the proper decryption key.
Question 2: Which HIPAA Security Rule safeguard category includes policies and procedures for managing workforce access to ePHI?
- Administrative safeguards (Correct answer)
- Physical safeguards
- Technical safeguards
- Organizational safeguards
Correct answer: Administrative safeguards
Administrative safeguards include policies and procedures such as workforce training, access management, and security awareness that govern how ePHI is managed.
Question 3: What is the purpose of an automatic session timeout in an EHR system?
- To log out inactive users and prevent unauthorized access to an unattended workstation (Correct answer)
- To update patient records automatically after a set period
- To generate billing reports at scheduled intervals
- To sync data with the HIE after each clinical session
Correct answer: To log out inactive users and prevent unauthorized access to an unattended workstation
Automatic session timeout logs users out after a period of inactivity to prevent unauthorized access if a workstation is left unattended.
Question 4: Which type of malware encrypts EHR data and demands payment for the decryption key?
- Ransomware (Correct answer)
- Spyware
- Adware
- Rootkit
Correct answer: Ransomware
Ransomware is malicious software that encrypts a victim's data and demands a ransom payment in exchange for the decryption key needed to restore access.
Question 5: Under HIPAA, how long must covered entities retain documentation of their security policies and procedures?
- 6 years from creation or last effective date (Correct answer)
- 3 years from creation
- 10 years from creation
- Indefinitely, with no defined retention limit
Correct answer: 6 years from creation or last effective date
HIPAA requires covered entities to retain security rule documentation for 6 years from the date of its creation or the date it was last in effect, whichever is later.
Question 6: What is a business associate agreement (BAA) in the context of EHR data security?
- A contract requiring vendors who handle ePHI to comply with HIPAA security requirements (Correct answer)
- An agreement between two hospitals to share patient records
- A document authorizing a patient to access their own health records
- A billing contract between a provider and an insurance company
Correct answer: A contract requiring vendors who handle ePHI to comply with HIPAA security requirements
A BAA is a legally required contract between a covered entity and a business associate that establishes HIPAA compliance responsibilities for vendors handling ePHI.
What does 'encryption at rest' protect in an EHR system?