CEHRS CEHRS Data Security and Access Control 1 — Questions and Answers
Question 1: Which HIPAA rule specifically addresses the safeguarding of electronic protected health information (ePHI)?
- HIPAA Security Rule (Correct answer)
- HIPAA Privacy Rule
- HIPAA Breach Notification Rule
- HIPAA Enforcement Rule
Correct answer: HIPAA Security Rule
The HIPAA Security Rule establishes national standards to protect electronic protected health information (ePHI) created, received, maintained, or transmitted by covered entities.
Question 2: What is the principle of 'minimum necessary' access in EHR security?
- Users should only access the minimum amount of PHI needed to perform their job functions (Correct answer)
- Passwords must meet a minimum length of 8 characters
- EHR systems must use the minimum required encryption standards
- Audit logs must capture the minimum data elements required by HIPAA
Correct answer: Users should only access the minimum amount of PHI needed to perform their job functions
The minimum necessary principle requires that access to PHI be limited to only what is needed for an employee to perform their specific job duties.
Question 3: Which type of EHR access control assigns permissions based on a user's job role or title?
- Role-Based Access Control (RBAC) (Correct answer)
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Attribute-Based Access Control (ABAC)
Correct answer: Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) assigns system permissions to users based on their organizational role, such as nurse, physician, or billing staff.
Question 4: What is the purpose of an EHR audit log?
- To record who accessed patient records, what was viewed, and when (Correct answer)
- To document system downtime and maintenance windows
- To track billing codes entered by medical coders
- To log network traffic for IT infrastructure management
Correct answer: To record who accessed patient records, what was viewed, and when
EHR audit logs create a chronological record of all user access to patient records, including who accessed information, what was viewed or changed, and the timestamp.
Question 5: Which authentication method requires users to verify identity using something they know AND something they have?
- Multi-factor authentication (MFA) (Correct answer)
- Single sign-on (SSO)
- Biometric authentication
- Certificate-based authentication
Correct answer: Multi-factor authentication (MFA)
Multi-factor authentication requires at least two verification factors — typically a password (something you know) plus a code sent to a device (something you have).
Question 6: What action should an EHR specialist take when they suspect unauthorized access to patient records?
- Report the incident to the privacy/security officer immediately (Correct answer)
- Reset the affected user's password and monitor the account
- Delete the audit log entries related to the incident
- Notify the affected patient directly before reporting internally
Correct answer: Report the incident to the privacy/security officer immediately
Suspected unauthorized access must be reported immediately to the organization's privacy or security officer, who will investigate and determine if a breach notification is required.
Which HIPAA rule specifically addresses the safeguarding of electronic protected health information (ePHI)?