CEHRS CEHRS Data Security and Access Control 5 — Questions and Answers
Question 1: A patient requests that their EHR not be shared with their insurance company. Under HIPAA, the provider MUST honor this request if:
- The patient pays out of pocket in full for the service (Correct answer)
- The provider agrees in writing
- The information is more than 12 months old
- The patient submits the request in writing
Correct answer: The patient pays out of pocket in full for the service
Under the HITECH Act amendment to HIPAA, providers must honor a patient's request to restrict disclosure to a health plan if the patient pays for the service entirely out of pocket.
Question 2: Which of the following BEST describes a 'minimum necessary' standard in the context of EHR access?
- Employees should access only the ePHI required to perform their job duties (Correct answer)
- Only minimum-wage staff need restricted access
- Patients should receive the minimum amount of their own data
- PHI must be stored in the smallest file format possible
Correct answer: Employees should access only the ePHI required to perform their job duties
The minimum necessary standard requires that access to PHI be limited to what is needed to accomplish the intended purpose or job function.
Question 3: An EHR system automatically logs out a user after 15 minutes of inactivity. This is an example of which HIPAA technical safeguard?
- Encryption
- Automatic logoff (Correct answer)
- Integrity controls
- Transmission security
Correct answer: Automatic logoff
Automatic logoff is a HIPAA technical safeguard that terminates an electronic session after a predetermined period of inactivity to prevent unauthorized access.
Question 4: Which of the following is a physical safeguard required under the HIPAA Security Rule?
- Data encryption in transit
- Unique user identification
- Facility access controls (Correct answer)
- Automatic logoff
Correct answer: Facility access controls
Facility access controls are a physical safeguard that limits physical access to electronic information systems and the buildings where they are housed.
Question 5: A ransomware attack encrypts patient records in an EHR system and demands payment for decryption. Under HIPAA, this event is presumed to be:
- A security incident only, not a breach
- A breach unless a risk assessment demonstrates low probability of PHI compromise (Correct answer)
- Automatically exempt if backups exist
- A breach only if the attacker is located outside the US
Correct answer: A breach unless a risk assessment demonstrates low probability of PHI compromise
Per 2016 HHS guidance, ransomware attacks are presumed to be HIPAA breaches unless a risk assessment shows low probability that PHI was compromised.
Question 6: Which term describes the process of verifying that data has not been altered or destroyed in an unauthorized manner?
- Authentication
- Authorization
- Data integrity (Correct answer)
- Non-repudiation
Correct answer: Data integrity
Data integrity refers to ensuring that ePHI is not improperly altered or destroyed, which is a core requirement of the HIPAA Security Rule.
Question 7: A business associate agreement (BAA) is REQUIRED when a covered entity shares ePHI with a vendor that:
- Only stores de-identified data
- Performs functions involving PHI on behalf of the covered entity (Correct answer)
- Is another covered entity
- Accesses aggregate statistical data only
Correct answer: Performs functions involving PHI on behalf of the covered entity
A BAA is required whenever a covered entity engages a business associate to perform services that involve creating, receiving, maintaining, or transmitting PHI.
A patient requests that their EHR not be shared with their insurance company.
Under HIPAA, the provider MUST honor this request if: