CEHRS CEHRS Data Security and Access Control 4 — Questions and Answers
Question 1: Which federal regulation specifically governs the security of electronic protected health information (ePHI) in the United States?
- HITECH Act
- HIPAA Security Rule (Correct answer)
- HIPAA Privacy Rule
- Meaningful Use Rule
Correct answer: HIPAA Security Rule
The HIPAA Security Rule specifically establishes national standards for protecting ePHI that is created, received, used, or maintained by covered entities.
Question 2: A clinic employee shares their EHR login credentials with a coworker to cover for them during break. This violates which security principle?
- Data minimization
- Individual accountability (Correct answer)
- Need-to-know access
- Data integrity
Correct answer: Individual accountability
Sharing credentials violates individual accountability, which requires that each user be uniquely identified so their actions in the system can be traced.
Question 3: Which type of access control assigns permissions based on job function rather than individual identity?
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Role-Based Access Control (RBAC) (Correct answer)
- Attribute-Based Access Control (ABAC)
Correct answer: Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) grants permissions according to the user's role or job function within the organization.
Question 4: A breach notification must be sent to HHS and affected individuals within how many days of discovering a HIPAA breach affecting 500 or more individuals?
- 30 days
- 45 days
- 60 days (Correct answer)
- 60 days for HHS and 45 days for individuals
Correct answer: 60 days
HIPAA requires breach notification to affected individuals and HHS within 60 days of discovery of a breach affecting 500 or more individuals.
Question 5: Which encryption standard is currently recommended by NIST for protecting ePHI at rest?
- DES (Data Encryption Standard)
- AES-128 or higher (Correct answer)
- MD5 hashing
- RSA-512
Correct answer: AES-128 or higher
NIST recommends AES (Advanced Encryption Standard) with a key length of 128 bits or higher for encrypting data at rest.
Question 6: When a user's employment is terminated, the MOST immediate action an EHR administrator should take is:
- Archive the user's records
- Disable or revoke the user's system access (Correct answer)
- Transfer the user's files to their supervisor
- Generate an audit report of the user's activity
Correct answer: Disable or revoke the user's system access
Revoking access immediately upon termination prevents unauthorized access to ePHI by former employees.
Question 7: Which HIPAA administrative safeguard requires organizations to regularly review records of information system activity?
- Contingency Plan
- Audit Controls (Correct answer)
- Information Access Management
- Security Awareness Training
Correct answer: Audit Controls
The Audit Controls standard under HIPAA requires covered entities to implement hardware, software, and procedural mechanisms to record and examine system activity.
Which federal regulation specifically governs the security of electronic protected health information (ePHI) in the United States?