โ† All CEHRS Flashcard Decks

CEHRS Data Security and Access Control Flashcards

7 cards from real CEHRS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CEHRS Data Security and Access Control flashcards as text
  1. A patient requests that their EHR not be shared with their insurance company. Under HIPAA, the provider MUST honor this request if:

    Answer: The patient pays out of pocket in full for the service

    Under the HITECH Act amendment to HIPAA, providers must honor a patient's request to restrict disclosure to a health plan if the patient pays for the service entirely out of pocket.

  2. Which of the following BEST describes a 'minimum necessary' standard in the context of EHR access?

    Answer: Employees should access only the ePHI required to perform their job duties

    The minimum necessary standard requires that access to PHI be limited to what is needed to accomplish the intended purpose or job function.

  3. An EHR system automatically logs out a user after 15 minutes of inactivity. This is an example of which HIPAA technical safeguard?

    Answer: Automatic logoff

    Automatic logoff is a HIPAA technical safeguard that terminates an electronic session after a predetermined period of inactivity to prevent unauthorized access.

  4. Which of the following is a physical safeguard required under the HIPAA Security Rule?

    Answer: Facility access controls

    Facility access controls are a physical safeguard that limits physical access to electronic information systems and the buildings where they are housed.

  5. A ransomware attack encrypts patient records in an EHR system and demands payment for decryption. Under HIPAA, this event is presumed to be:

    Answer: A breach unless a risk assessment demonstrates low probability of PHI compromise

    Per 2016 HHS guidance, ransomware attacks are presumed to be HIPAA breaches unless a risk assessment shows low probability that PHI was compromised.

  6. Which term describes the process of verifying that data has not been altered or destroyed in an unauthorized manner?

    Answer: Data integrity

    Data integrity refers to ensuring that ePHI is not improperly altered or destroyed, which is a core requirement of the HIPAA Security Rule.

  7. A business associate agreement (BAA) is REQUIRED when a covered entity shares ePHI with a vendor that:

    Answer: Performs functions involving PHI on behalf of the covered entity

    A BAA is required whenever a covered entity engages a business associate to perform services that involve creating, receiving, maintaining, or transmitting PHI.