CEHRS Data Security and Access Control Flashcards
7 cards from real CEHRS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CEHRS Data Security and Access Control flashcards as text
Which federal regulation specifically governs the security of electronic protected health information (ePHI) in the United States?
Answer: HIPAA Security Rule
The HIPAA Security Rule specifically establishes national standards for protecting ePHI that is created, received, used, or maintained by covered entities.
A clinic employee shares their EHR login credentials with a coworker to cover for them during break. This violates which security principle?
Answer: Individual accountability
Sharing credentials violates individual accountability, which requires that each user be uniquely identified so their actions in the system can be traced.
Which type of access control assigns permissions based on job function rather than individual identity?
Answer: Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) grants permissions according to the user's role or job function within the organization.
A breach notification must be sent to HHS and affected individuals within how many days of discovering a HIPAA breach affecting 500 or more individuals?
Answer: 60 days
HIPAA requires breach notification to affected individuals and HHS within 60 days of discovery of a breach affecting 500 or more individuals.
Which encryption standard is currently recommended by NIST for protecting ePHI at rest?
Answer: AES-128 or higher
NIST recommends AES (Advanced Encryption Standard) with a key length of 128 bits or higher for encrypting data at rest.
When a user's employment is terminated, the MOST immediate action an EHR administrator should take is:
Answer: Disable or revoke the user's system access
Revoking access immediately upon termination prevents unauthorized access to ePHI by former employees.
Which HIPAA administrative safeguard requires organizations to regularly review records of information system activity?
Answer: Audit Controls
The Audit Controls standard under HIPAA requires covered entities to implement hardware, software, and procedural mechanisms to record and examine system activity.