Certified in Healthcare Privacy and Security (CHPS) โ Questions and Answers
Question 1: A healthcare organization implements a policy requiring all portable media containing PHI to be encrypted. Which HIPAA safeguard category does this policy primarily address?
- Administrative safeguards
- Physical safeguards
- Organizational safeguards
- Technical safeguards (Correct answer)
Correct answer: Technical safeguards
Encryption of data on portable media is a technical safeguard, falling under the HIPAA Security Rule's technical safeguards standard for transmission and storage security.
Question 2: An organization implements full-disk encryption on all laptops. Under HIPAA's Breach Notification Rule, if an encrypted laptop is stolen, the organization should:
- Not report it as a breach if the encryption meets HHS guidance (Correct answer)
- Notify affected individuals within 30 days
- Conduct a full risk analysis and report to law enforcement
- Report it to HHS within 60 days regardless
Correct answer: Not report it as a breach if the encryption meets HHS guidance
Data encrypted in accordance with HHS guidance is considered 'unusable, unreadable, or indecipherable' and therefore its loss does not constitute a reportable breach.
Question 3: Which HIPAA-required document informs patients about how their PHI may be used and their privacy rights, and must be provided at first service delivery?
- Authorization Form
- Notice of Privacy Practices (NPP) (Correct answer)
- Business Associate Agreement (BAA)
- Accounting of Disclosures
Correct answer: Notice of Privacy Practices (NPP)
The Notice of Privacy Practices must describe how PHI may be used and disclosed, individual rights, and covered entity duties, and must be provided to patients at first point of service.
Question 4: An organization implements automatic session timeouts for workstations accessing ePHI. This is an example of which HIPAA Security Rule safeguard category?
- Technical safeguard (Correct answer)
- Physical safeguard
- Organizational requirement
- Administrative safeguard
Correct answer: Technical safeguard
Automatic logoff is explicitly listed as an addressable implementation specification under the Access Control technical safeguard in the HIPAA Security Rule.
Question 5: A covered entity discovers that a workforce member has been snooping on celebrity patient records over the past year. How many breaches does this represent?
- One breach per patient record impermissibly accessed (Correct answer)
- One breach per year
- A single breach because it involves one workforce member
- No breach if the workforce member did not disclose the information to anyone
Correct answer: One breach per patient record impermissibly accessed
Each patient's record that was impermissibly accessed represents a separate potential breach requiring individual analysis under the four-factor risk assessment.
Question 6: Under HIPAA, what is the retention period for a covered entity's privacy policies and procedures documentation?
- 7 years from creation or last effective date
- 6 years from creation or last effective date (Correct answer)
- 10 years from creation or last effective date
- 3 years from creation or last effective date
Correct answer: 6 years from creation or last effective date
The HIPAA Privacy Rule at 45 CFR ยง164.530(j) requires policies, procedures, and related documentation to be retained for 6 years from creation or last effective date, whichever is later.
Question 7: A hospital's backup tapes containing unencrypted ePHI are discovered missing after a vendor picks them up for off-site storage. Under HIPAA, the hospital should FIRST:
- Submit a report to local law enforcement before notifying HHS
- Conduct a risk assessment to determine the probability that PHI was compromised (Correct answer)
- Wait 60 days before taking action to see if the tapes reappear
- Immediately send individual notifications to all affected patients
Correct answer: Conduct a risk assessment to determine the probability that PHI was compromised
Before triggering breach notification, the covered entity must conduct the four-factor risk assessment to determine whether there is a low probability of PHI compromise.
Question 8: An audit log system records who accessed ePHI, when, and what actions were taken. Under the HIPAA Security Rule, this is classified as which type of safeguard?
- Organizational requirement โ business associate contracts
- Administrative safeguard โ information access management
- Technical safeguard โ audit controls (Correct answer)
- Physical safeguard โ workstation security
Correct answer: Technical safeguard โ audit controls
Audit controls are a required technical safeguard under the HIPAA Security Rule, mandating mechanisms to record and examine activity in systems that contain ePHI.
Question 9: Under the HIPAA Breach Notification Rule, what is the presumption when an impermissible use or disclosure of PHI occurs?
- The event is presumed to be a security incident requiring criminal referral
- The event is presumed to be a breach unless the covered entity demonstrates low probability of PHI compromise (Correct answer)
- The event requires immediate notification to all affected individuals
- The event is presumed harmless unless the patient files a complaint
Correct answer: The event is presumed to be a breach unless the covered entity demonstrates low probability of PHI compromise
Under the 2013 Omnibus Rule, an impermissible use or disclosure is presumed to be a breach unless a covered entity can demonstrate through a four-factor risk assessment that there is a low probability the PHI was compromised.
Question 10: The four-factor risk assessment under the HIPAA Breach Notification Rule includes all of the following EXCEPT:
- The unauthorized person who used or received PHI
- Likelihood that PHI was actually acquired or viewed
- Whether the affected individual has experienced actual identity theft (Correct answer)
- Nature and extent of PHI involved including types of identifiers
Correct answer: Whether the affected individual has experienced actual identity theft
Actual identity theft is not one of the four factors โ the assessment focuses on probability of compromise, not actual harm after the fact.
Question 11: Under HIPAA, which of the following is an acceptable substitute for individual breach notification when the covered entity has insufficient contact information?
- Filing a report with the state insurance commissioner
- Posting conspicuous notice on the covered entity's website for 90 days and notifying major print/broadcast media (Correct answer)
- Posting notice on the HHS website
- Calling local community organizations to distribute information
Correct answer: Posting conspicuous notice on the covered entity's website for 90 days and notifying major print/broadcast media
When direct contact information is unavailable, substitute notice may be provided by posting on the covered entity's website for 90 days or in major print or broadcast media serving the affected area.
Question 12: What is the term for a risk management strategy where a covered entity accepts the potential cost of a risk rather than implementing controls to mitigate it?
- Risk avoidance
- Risk mitigation
- Risk acceptance (Correct answer)
- Risk transference
Correct answer: Risk acceptance
Risk acceptance is the deliberate decision to accept a risk's potential impact without additional controls, typically documented when the cost of controls exceeds the expected loss.
Question 13: Under the HIPAA Breach Notification Rule, what is the maximum number of days a covered entity has to notify affected individuals of a breach?
- 45 days
- 60 days (Correct answer)
- 90 days
- 30 days
Correct answer: 60 days
Covered entities must notify affected individuals of a breach without unreasonable delay and no later than 60 calendar days after discovery.
Question 14: Role-based access use is an illustration of
- Notification
- Symmetric key
- Access authorization
- Access control (Correct answer)
Correct answer: Access control
The use of role-based access is an example of "access control." <br> <br> Access control refers to the set of mechanisms and processes that govern the management of user access to resources within a system or organization. It involves defining and enforcing policies and procedures to determine who can access what resources, under what circumstances, and with what privileges.
Question 15: After a new control is put in place, risk is still deemed to exist if an organization.
- Incidental
- Periradicular
- Dentigerous
- Residual (Correct answer)
Correct answer: Residual
If an organization still has risk after implementing a new control, that risk is considered to be "residual risk." <br> <br> Residual risk refers to the level of risk that remains after implementing controls or risk mitigation measures. It represents the amount of risk that remains even with the presence of controls designed to reduce or mitigate the initial risk.
Question 16: Under HIPAA, what is the maximum civil monetary penalty per identical violation category per calendar year?
- $500,000
- $1,919,173 (Correct answer)
- $100,000
- $1,000,000
Correct answer: $1,919,173
The HHS annually adjusts the annual cap for identical violations, which as of recent adjustments exceeds $1.9 million per violation category per year.
Question 17: Which NIST publication provides a framework for improving critical infrastructure cybersecurity and is widely referenced in healthcare security programs?
- NIST SP 800-53
- NIST SP 800-30
- NIST Cybersecurity Framework (CSF) (Correct answer)
- NIST SP 800-66
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) organizes security activities into Identify, Protect, Detect, Respond, and Recover functions and is widely adopted in healthcare as a voluntary risk management framework.
Question 18: The organization must take action if a health insurance provider contacts a member to advertise a car insurance plan provided by the same provider.
- Authorization for disclosure for marketing purposes (Correct answer)
- All electronic systems
- After 6 years
- Risk avoidance
Correct answer: Authorization for disclosure for marketing purposes
Under the Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule, covered entities are generally required to provide timely notification to individuals whose protected health information (PHI) has been breached. The notification should be made without unreasonable delay and no later than 60 days from the discovery of the breach.
Question 19: A hospital's Security Officer discovers that a workforce member accessed patient records without a valid treatment, payment, or operations reason. This is BEST described as:
- A required disclosure under HIPAA
- A security incident requiring breach notification
- A business associate agreement breach
- A workforce sanction policy violation (Correct answer)
Correct answer: A workforce sanction policy violation
Inappropriate access by workforce members without authorization violates the workforce sanction policy, which covered entities must have in place under the HIPAA Security Rule.
Question 20: Which of the following access control models is most commonly recommended for healthcare environments to enforce least privilege?
- Role-Based Access Control (RBAC) (Correct answer)
- Mandatory Access Control (MAC)
- Discretionary Access Control (DAC)
- Rule-Based Access Control
Correct answer: Role-Based Access Control (RBAC)
RBAC grants access based on a user's job role, which aligns well with the least-privilege principle in healthcare settings.
Question 21: What is 'shoulder surfing' in the context of healthcare information security?
- Redirecting email communications to an unauthorized inbox
- Observing someone's screen or keyboard to steal credentials or PHI (Correct answer)
- Impersonating a clinician to gain system access
- Intercepting wireless network traffic in a clinical setting
Correct answer: Observing someone's screen or keyboard to steal credentials or PHI
Shoulder surfing is a social engineering technique where an attacker physically observes a user's screen or keystrokes to obtain sensitive information.
Question 22: An employee emails unencrypted PHI to a personal email account 'just to work from home.' Under HIPAA, this is BEST characterized as:
- A permitted disclosure for healthcare operations
- A minor violation with no reporting requirement
- An acceptable workforce accommodation
- A potential security incident requiring evaluation (Correct answer)
Correct answer: A potential security incident requiring evaluation
Sending unencrypted PHI to an unauthorized external account constitutes a potential security incident that must be evaluated to determine whether a reportable breach occurred.
Question 23: What is 'workforce' as defined under HIPAA, and does it include volunteers and trainees?
- Employees only; volunteers and trainees are excluded
- Anyone who handles PHI regardless of relationship
- Employees and contractors; volunteers are excluded
- Employees, volunteers, trainees, and other persons under the entity's direct control (Correct answer)
Correct answer: Employees, volunteers, trainees, and other persons under the entity's direct control
HIPAA defines workforce as employees, volunteers, trainees, and other persons whose conduct is under the direct control of the covered entity, whether or not they are paid.
Question 24: A healthcare organization uses a firewall, intrusion detection system, and antivirus software as layers of protection. This approach is known as:
- Defense in depth (Correct answer)
- Zero-trust architecture
- Security through obscurity
- Least privilege principle
Correct answer: Defense in depth
Defense in depth uses multiple, overlapping security controls so that if one layer fails, additional layers continue to protect ePHI from compromise.
Question 25: Under the HIPAA minimum necessary standard, which of the following disclosures is exempt?
- Disclosures to the individual who is the subject of the PHI (Correct answer)
- Disclosures for payment purposes
- Disclosures for health care operations
- Disclosures to business associates
Correct answer: Disclosures to the individual who is the subject of the PHI
The minimum necessary standard does not apply to disclosures made to the individual who is the subject of the PHI.
Question 26: Which HIPAA enforcement tier applies when a covered entity did not know and could not have reasonably known of a violation?
- Tier 1 โ Reasonable cause
- Tier 3 โ Willful neglect, corrected
- Tier 4 โ Willful neglect, not corrected
- Tier 1 โ Did not know (Correct answer)
Correct answer: Tier 1 โ Did not know
Tier 1 of HIPAA's civil penalty structure applies to violations where the entity did not know and with reasonable diligence would not have known of the violation, carrying the lowest penalty range.
Question 27: Which HIPAA provision requires covered entities to provide patients with an accounting of certain disclosures of their PHI?
- Right of Access
- Right to an Accounting of Disclosures (Correct answer)
- Right to Request Restrictions
- Right to Amend
Correct answer: Right to an Accounting of Disclosures
The Right to an Accounting of Disclosures (45 CFR ยง164.528) requires covered entities to provide a list of disclosures made for purposes other than treatment, payment, and operations.
Question 28: Which HIPAA Privacy Rule standard allows covered entities to use or disclose PHI for their own treatment, payment, and healthcare operations without patient authorization?
- Individual access rights
- Minimum necessary standard
- Permitted uses and disclosures (Correct answer)
- Notice of Privacy Practices
Correct answer: Permitted uses and disclosures
The permitted uses and disclosures provision allows covered entities to use or disclose PHI for TPO (treatment, payment, healthcare operations) without individual authorization.
Question 29: Under the HIPAA Privacy Rule, what is the maximum period a covered entity may retain a patient's authorization for use or disclosure of PHI?
- One year from the date of signing
- Six years from the date of creation
- Five years from the date of creation
- Until the patient revokes it in writing (Correct answer)
Correct answer: Until the patient revokes it in writing
An authorization remains valid until the patient revokes it in writing or the expiration date stated in the authorization is reached.
Question 30: Which HIPAA penalty tier applies when a covered entity knew of a violation and failed to correct it within 30 days?
- No financial penalty โ only corrective action plans are required
- $1,000โ$50,000 per violation with a $100,000 annual cap
- $10,000โ$50,000 per violation with a $1.5 million annual cap (Tier 3/4 range) (Correct answer)
- $100โ$50,000 per violation with a $25,000 annual cap
Correct answer: $10,000โ$50,000 per violation with a $1.5 million annual cap (Tier 3/4 range)
Willful neglect violations that are not corrected fall in the highest penalty tiers, ranging from $10,000 to $50,000 per violation with an annual cap of $1.5 million.
Question 31: Which NIST publication provides the primary framework for federal information security programs and is widely used in healthcare security?
- NIST SP 800-53 (Correct answer)
- NIST SP 800-171
- NIST SP 800-37
- NIST CSF
Correct answer: NIST SP 800-53
NIST SP 800-53 provides a catalog of security and privacy controls for federal information systems and is a key reference for healthcare security programs.
Question 32: Under HIPAA, which of the following is a permitted disclosure of PHI to family members WITHOUT patient authorization?
- Disclosing mental health notes to a sibling upon request
- Providing test results to a parent of an adult patient
- Sharing a full medical history with an adult patient's spouse
- Sharing information directly relevant to a family member's involvement in care when the patient has not objected (Correct answer)
Correct answer: Sharing information directly relevant to a family member's involvement in care when the patient has not objected
Under 45 CFR ยง164.510(b), a covered entity may share PHI with family members involved in care if the patient has not objected and the information is directly relevant to that involvement.
Question 33: How frequently must a covered entity review and update its security policies and procedures under the HIPAA Security Rule?
- Periodically, and in response to environmental or operational changes that affect ePHI security (Correct answer)
- Annually on a fixed calendar schedule
- Every three years as part of a formal certification cycle
- Only when a breach or security incident occurs
Correct answer: Periodically, and in response to environmental or operational changes that affect ePHI security
The Security Rule requires covered entities to review and update policies periodically and whenever environmental or operational changes affect the security of ePHI, rather than on a fixed schedule.
Question 34: Which NIST framework publication provides guidance specifically for protecting health information in cybersecurity programs?
- NIST SP 800-37
- NIST SP 800-171
- NIST SP 800-66 (Correct answer)
- NIST SP 800-53
Correct answer: NIST SP 800-66
NIST SP 800-66 is the resource guide for implementing the HIPAA Security Rule and provides practical guidance for healthcare organizations.
Question 35: How much time is allotted for a covered company to reply to an accounting of disclosure request?
- Facility security plan
- 30 days with one 30 day extension (Correct answer)
- Security update
- Acts of man
Correct answer: 30 days with one 30 day extension
A covered entity under the Health Insurance Portability and Accountability Act (HIPAA) has a maximum of 30 days to respond to an accounting of disclosure request from an individual. However, if the covered entity is unable to meet the deadline within the initial 30-day period, they can request a one-time 30-day extension to provide a response.
Question 36: A covered entity discloses PHI to a public health authority to prevent the spread of disease. This is an example of:
- A required disclosure mandated by HIPAA
- A breach requiring notification
- A permitted disclosure without patient authorization (Correct answer)
- A violation of the minimum necessary standard
Correct answer: A permitted disclosure without patient authorization
HIPAA permits disclosures of PHI to public health authorities for activities such as disease surveillance, investigation, and intervention without requiring patient authorization.
Question 37: A Notice of Privacy Practices (NPP) must include which of the following elements?
- The names of all business associates
- Annual audit results of privacy program compliance
- A description of the types of uses and disclosures a covered entity may make (Correct answer)
- A list of all workforce members who may access PHI
Correct answer: A description of the types of uses and disclosures a covered entity may make
The NPP must describe the types of uses and disclosures the covered entity is permitted or required to make, as required by 45 CFR ยง164.520.
Question 38: An organization has just implemented a new policy that spells out how it would physically safeguard the five clinics it owns. This is an illustration of a (n)
- Burden of proof
- Security update
- Facility security plan (Correct answer)
- Exclusion
Correct answer: Facility security plan
The implementation of a new policy that outlines how an organization protects the physical space of its clinics is an example of a Facility Security Plan. <br> <br> A Facility Security Plan is a comprehensive set of policies, procedures, and protocols designed to safeguard the physical security of an organization's facilities. It covers various aspects such as access control, surveillance systems, visitor management, emergency response, incident reporting, and other security measures.
Question 39: Which HIPAA Security Rule safeguard category includes the requirement for workforce training on security policies and procedures?
- Organizational Safeguards
- Administrative Safeguards (Correct answer)
- Physical Safeguards
- Technical Safeguards
Correct answer: Administrative Safeguards
Security Awareness and Training is an Administrative Safeguard (45 CFR ยง164.308(a)(5)) requiring periodic security training for all workforce members.
Question 40: Under HIPAA, breach discovery is defined as the date on which which party first knows or reasonably should have known of the breach?
- The individual whose PHI was breached
- The covered entity, regardless of when the business associate discovered it
- The HHS Office for Civil Rights (OCR)
- The covered entity or business associate, whichever is the data holder (Correct answer)
Correct answer: The covered entity or business associate, whichever is the data holder
Discovery date is when the covered entity or business associate (whichever holds the data) first knew or should have known about the breach through reasonable diligence.
Question 41: Which ISO standard is specifically designed for information security management systems and is used as a benchmark in healthcare security programs?
- ISO 27001 (Correct answer)
- ISO 31000
- ISO 9001
- ISO 13485
Correct answer: ISO 27001
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS) and is widely adopted in healthcare.
Question 42: Which cryptographic control renders ePHI unusable, unreadable, or indecipherable to unauthorized individuals and can exempt a breach from notification requirements?
- NIST-compliant encryption (Correct answer)
- Tokenization
- Steganography
- Hashing
Correct answer: NIST-compliant encryption
NIST-compliant encryption (following HHS guidance referencing NIST SP 800-111 for data at rest) renders PHI unreadable and qualifies as a safe harbor under the Breach Notification Rule.
Question 43: Which healthcare interoperability standard defines the format for electronic exchange of clinical data including medications, allergies, and diagnoses?
- DICOM
- X12 EDI
- HL7 FHIR (Correct answer)
- SNOMED CT
Correct answer: HL7 FHIR
HL7 FHIR (Fast Healthcare Interoperability Resources) is the current standard for healthcare data exchange, enabling structured clinical data sharing between systems.
Question 44: Under the HIPAA Security Rule, what is the purpose of the 'Assigned Security Responsibility' standard?
- Determining which workforce members require security awareness training
- Designating a person responsible for developing and implementing security policies and procedures (Correct answer)
- Assigning unique IDs to all workforce members accessing ePHI
- Classifying ePHI data by sensitivity level for access control
Correct answer: Designating a person responsible for developing and implementing security policies and procedures
The Assigned Security Responsibility standard (45 CFR ยง164.308(a)(2)) requires covered entities to identify a Security Officer responsible for security policies and procedures.
Question 45: What is the primary purpose of a healthcare organization's sanctions policy under HIPAA?
- To create a framework for denying patient access requests
- To document procedures for reporting breaches to HHS
- To define consequences for workforce members who violate privacy and security policies (Correct answer)
- To establish financial penalties for patients who misuse the patient portal
Correct answer: To define consequences for workforce members who violate privacy and security policies
The sanctions policy (required by 45 CFR ยง164.530(e)) defines appropriate disciplinary actions for workforce members who fail to comply with privacy and security policies.
Question 46: Under the Physical Safeguards of the HIPAA Security Rule, Facility Access Controls are designed to:
- Limit physical access to electronic information systems and the facilities in which they are housed to authorized users (Correct answer)
- Monitor network traffic entering and leaving the facility
- Control logical user access to ePHI applications
- Prevent unauthorized software from being installed on facility computers
Correct answer: Limit physical access to electronic information systems and the facilities in which they are housed to authorized users
Facility Access Controls require policies and procedures to limit physical access to electronic information systems and their housing facilities to those with authorized access.
Question 47: In a healthcare EHR environment, which access control model most effectively enforces the Minimum Necessary standard?
- Role-Based Access Control (RBAC) (Correct answer)
- Mandatory Access Control (MAC)
- Discretionary Access Control (DAC)
- Attribute-Based Access Control (ABAC)
Correct answer: Role-Based Access Control (RBAC)
RBAC restricts ePHI access based on defined job roles, naturally enforcing the Minimum Necessary standard by limiting access to what each role requires.
Question 48: When a patient obtains a treatment, pays out of pocket, and wishes that information not be forwarded to his or her personal account, a healthcare institution must abide by a limitation.
- The board of directors or trustees
- Treatment
- Health insurance company (Correct answer)
- The individual seeking the care
Correct answer: Health insurance company
A healthcare organization must comply with a restriction when a patient receives a service, pays out of pocket, and requests that information is not sent to his/her health insurance company. <br> <br> Under the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule, the disclosure of protected health information (PHI) for marketing purposes generally requires the individual's authorization. PHI includes any individually identifiable health information held or transmitted by a covered entity or its business associates.
Question 49: Under HIPAA's right to request restrictions, when is a covered entity REQUIRED to agree to a patient's restriction request?
- When the restriction involves disclosures to a family member
- When the patient requests restriction on disclosure to a health plan for services the patient paid out-of-pocket in full (Correct answer)
- When the treating physician supports the restriction
- Covered entities are never required to agree to restriction requests
Correct answer: When the patient requests restriction on disclosure to a health plan for services the patient paid out-of-pocket in full
Under the HITECH-amended HIPAA rules, covered entities must honor restrictions when the patient has paid out-of-pocket in full and requests the restriction to a health plan.
Question 50: Which network segmentation strategy BEST protects a healthcare organization's clinical systems from a ransomware attack originating on the administrative network?
- Using the same VLAN for all devices to simplify management
- Requiring all devices to use VPN for internal access
- Segmenting clinical systems into a separate VLAN with strict firewall rules controlling inter-segment traffic (Correct answer)
- Blocking all internet access from the entire organization
Correct answer: Segmenting clinical systems into a separate VLAN with strict firewall rules controlling inter-segment traffic
Network segmentation isolates clinical systems from administrative networks, containing ransomware spread and protecting patient-facing systems from attacks originating elsewhere.
Question 51: Which security control is MOST effective at detecting unauthorized internal access to ePHI by snooping employees?
- Data Loss Prevention (DLP) system
- Web application firewall (WAF)
- Firewall with intrusion prevention system
- User and Entity Behavior Analytics (UEBA) (Correct answer)
Correct answer: User and Entity Behavior Analytics (UEBA)
UEBA establishes behavioral baselines for each user and alerts on anomalous access patterns, making it highly effective at detecting insider threats like snooping.
Question 52: Data is sent between computers in encrypted form. Which of the following best represents the date following the use of the encryption algorithm?
- Agent installations
- Residual
- Device controls (Correct answer)
- Endpoint groups
Correct answer: Device controls
The term that describes the data after the encryption algorithm has been applied is "encrypted data." <br> <br> Encryption is a process of encoding data to make it unreadable or unintelligible to unauthorized individuals. It involves using an encryption algorithm and a key to transform the original data into encrypted form, also known as ciphertext.
Question 53: A healthcare organization discovers that an employee's workstation has been accessed by an unauthorized user. According to the HIPAA Security Rule, this should be documented under which process?
- Information Access Management
- Contingency Plan
- Workforce Clearance Procedure
- Security Incident Procedures (Correct answer)
Correct answer: Security Incident Procedures
Security Incident Procedures require covered entities to document and respond to suspected or known security incidents, including unauthorized access events.
Question 54: Under HIPAA's Right of Access, what is the maximum fee a covered entity may charge for electronic copies of PHI maintained electronically?
- A fee not exceeding $6.50 per request under the safe harbor (Correct answer)
- A flat fee of $25
- A reasonable cost-based fee for labor, supplies, and postage
- No fee may be charged for electronic records
Correct answer: A fee not exceeding $6.50 per request under the safe harbor
The OCR established a $6.50 safe harbor fee for providing individuals with electronic copies of their PHI when maintained electronically.
Question 55: A covered entity wishes to use patient PHI for a research study. Under HIPAA, which of the following is NOT a valid pathway to use PHI for research?
- Purchasing de-identified data from a vendor and re-linking it to patient records (Correct answer)
- Obtaining a valid patient authorization
- Obtaining a waiver of authorization from an IRB or Privacy Board
- Using a Limited Data Set with a Data Use Agreement
Correct answer: Purchasing de-identified data from a vendor and re-linking it to patient records
Re-linking de-identified data to patient records defeats the purpose of de-identification and is not a permissible research pathway under HIPAA.
Question 56: Under HIPAA, when may a covered entity use PHI for fundraising purposes?
- Only when the patient has opted in to fundraising communications
- When demographic information and dates of service are used and the patient is given an opportunity to opt out (Correct answer)
- Never โ fundraising requires explicit written authorization
- Only with de-identified data
Correct answer: When demographic information and dates of service are used and the patient is given an opportunity to opt out
Covered entities may use limited PHI (demographics and dates of service) for fundraising if the NPP discloses this and patients are given a clear opportunity to opt out.
Question 57: Under the HIPAA Security Rule, 'audit controls' are best described as:
- Hardware, software, or procedural mechanisms that record and examine activity in systems containing ePHI (Correct answer)
- Policies governing who may access ePHI workstations
- Encryption standards applied to ePHI in transit
- Physical locks and badges controlling server room entry
Correct answer: Hardware, software, or procedural mechanisms that record and examine activity in systems containing ePHI
Audit controls (45 CFR ยง164.312(b)) require mechanisms to record and examine access and activity in information systems that contain or use ePHI.
Question 58: Under the HIPAA Breach Notification Rule, which of the following is NOT a required element of individual breach notification?
- A brief description of what happened and the date of breach and discovery
- A description of the covered entity's security vulnerabilities that caused the breach (Correct answer)
- The types of PHI involved in the breach
- Steps individuals should take to protect themselves from potential harm
Correct answer: A description of the covered entity's security vulnerabilities that caused the breach
While entities must provide breach details and mitigation guidance, disclosing the specific internal security vulnerabilities that caused the breach is not a required element of individual notification.
Question 59: A patient requests an amendment to their medical record because they believe information is incorrect. Under HIPAA, the covered entity may deny the request if:
- The information is stored in an EHR system
- The record was not created by the covered entity (Correct answer)
- The record is older than seven years
- The patient has previously requested amendments
Correct answer: The record was not created by the covered entity
A covered entity may deny an amendment request if the PHI was not created by that entity, among other permissible reasons.
Question 60: Under the HIPAA Security Rule's Physical Safeguards, what does the Workstation Use standard require?
- Encryption of all data stored on workstations
- A formal check-in process for all users accessing workstations
- Automatic screen locks after a period of inactivity
- Policies and procedures specifying proper functions performed at workstations and the physical attributes of the surroundings of workstations with access to ePHI (Correct answer)
Correct answer: Policies and procedures specifying proper functions performed at workstations and the physical attributes of the surroundings of workstations with access to ePHI
The Workstation Use standard requires policies defining proper workstation functions and the physical environment of workstations that access ePHI, such as positioning screens away from unauthorized viewers.
Question 61: What is 'de-identification' of PHI under HIPAA, and what are the two accepted methods?
- Aggregating records; methods are averaging and suppression
- Encrypting data; methods are symmetric and asymmetric encryption
- Removing the patient's name; methods are redaction and pseudonymization
- Removing 18 specific identifiers (Safe Harbor) or statistical expert determination (Correct answer)
Correct answer: Removing 18 specific identifiers (Safe Harbor) or statistical expert determination
HIPAA recognizes two de-identification methods: Safe Harbor (removing all 18 specified identifiers) and Expert Determination (statistical certification that re-identification risk is very small).
Question 62: A covered entity implements a policy requiring all portable devices containing ePHI to use full-disk encryption. This control PRIMARILY addresses which security objective?
- Availability
- Confidentiality (Correct answer)
- Non-repudiation
- Integrity
Correct answer: Confidentiality
Full-disk encryption on portable devices primarily protects confidentiality by ensuring that ePHI cannot be read by unauthorized individuals if a device is lost or stolen.
Question 63: A hospital's Security Officer is conducting a risk analysis. Which NIST document provides the most comprehensive guidance for conducting a risk assessment?
- NIST SP 800-53
- NIST SP 800-122
- NIST SP 800-66
- NIST SP 800-30 (Correct answer)
Correct answer: NIST SP 800-30
NIST SP 800-30 is the Guide for Conducting Risk Assessments and provides a structured framework for identifying and evaluating information security risks.
Question 64: In a healthcare privacy program, which document formally authorizes the Privacy Officer's role and defines the scope of the privacy program?
- Privacy Notice
- Risk Management Plan
- Business Associate Agreement
- Privacy Policy Charter or Program Charter (Correct answer)
Correct answer: Privacy Policy Charter or Program Charter
A Privacy Program Charter formally establishes the privacy program, defines its scope, and grants authority to the Privacy Officer to develop and enforce privacy policies.
Question 65: What is the primary purpose of conducting a Security Risk Analysis (SRA) under the HIPAA Security Rule?
- To identify and assess potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI (Correct answer)
- To train workforce members on security policies
- To document all breaches that have occurred in the past year
- To certify that all technical safeguards are functioning properly
Correct answer: To identify and assess potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI
The Security Risk Analysis is required to identify potential threats and vulnerabilities to ePHI so that the organization can implement appropriate security measures to reduce those risks.
Question 66: Which of the following HIPAA Security Rule requirements addresses the need for a covered entity to restore ePHI data after a disaster?
- Testing and Revision Procedures
- Data Backup Plan
- Disaster Recovery Plan (Correct answer)
- Emergency Mode Operation Plan
Correct answer: Disaster Recovery Plan
The Disaster Recovery Plan implementation specification (45 CFR ยง164.308(a)(7)(ii)(B)) requires procedures to restore lost data in the event of an emergency or disaster.
Question 67: Under the Administrative Safeguards of the HIPAA Security Rule, which standard requires covered entities to implement policies and procedures to prevent, detect, contain, and correct security violations?
- Information Access Management
- Security Awareness and Training
- Security Incident Procedures (Correct answer)
- Workforce Security
Correct answer: Security Incident Procedures
The Security Incident Procedures standard requires covered entities to address the identification and response to security incidents, including policies to prevent, detect, contain, and correct violations.
Question 68: Which of the following best describes the purpose of a Business Associate Agreement (BAA) under the HIPAA Security Rule?
- To transfer legal liability for breaches from the covered entity to the business associate
- To contractually require business associates to implement appropriate safeguards to protect ePHI they create, receive, maintain, or transmit on behalf of a covered entity (Correct answer)
- To authorize a business associate to disclose ePHI to other third parties
- To certify that a vendor has passed a HIPAA compliance audit
Correct answer: To contractually require business associates to implement appropriate safeguards to protect ePHI they create, receive, maintain, or transmit on behalf of a covered entity
A BAA is a required contract that establishes the permitted uses and disclosures of ePHI by a business associate and obligates the associate to implement appropriate security safeguards.
Question 69: Which HIPAA Security Rule standard requires covered entities to implement policies to prevent, detect, contain, and correct security violations?
- Security Management Process (Correct answer)
- Security Incident Procedures
- Evaluation
- Workforce Training and Awareness
Correct answer: Security Management Process
The Security Management Process standard (45 CFR ยง164.308(a)(1)) is the overarching standard requiring risk analysis, risk management, sanction policy, and activity review.
Question 70: When a breach affects 500 or more residents of a state or jurisdiction, a covered entity must notify which additional party?
- The local police department
- The state Attorney General only
- Prominent media outlets serving the state or jurisdiction (Correct answer)
- The Federal Trade Commission (FTC)
Correct answer: Prominent media outlets serving the state or jurisdiction
When a breach affects 500 or more residents of a state, the covered entity must provide notice to prominent media outlets in addition to individual and HHS notification.
Question 71: What term describes the HIPAA requirement that covered entities use only the minimum amount of PHI necessary to accomplish a task?
- Minimum necessary standard (Correct answer)
- Need-to-know principle
- Data minimization directive
- Least privilege rule
Correct answer: Minimum necessary standard
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to the minimum needed for the intended purpose.
Question 72: When designing a privacy compliance monitoring program, which approach provides the strongest ongoing assurance?
- Relying solely on patient complaints as a proxy for compliance failures
- Annual self-attestation by department heads
- Conducting a comprehensive audit only when OCR requests one
- Periodic random audits combined with automated access log monitoring and incident trend analysis (Correct answer)
Correct answer: Periodic random audits combined with automated access log monitoring and incident trend analysis
Combining periodic random audits with automated log monitoring and trend analysis provides multi-layered, continuous assurance across the privacy program.
Question 73: A hospital's EHR system sends a patient summary to a referring physician via unsecured email. Under the HIPAA Security Rule, which standard is most directly violated?
- Integrity Controls
- Access Control
- Transmission Security (Correct answer)
- Audit Controls
Correct answer: Transmission Security
Transmission Security (45 CFR ยง164.312(e)) requires covered entities to guard against unauthorized access to ePHI transmitted over electronic communications networks.
Question 74: What is a 'break-the-glass' procedure in the context of healthcare IT?
- A procedure for destroying PHI media in emergencies
- An emergency protocol for physical access to server rooms during fires
- An audit-logged override mechanism allowing emergency access to restricted PHI when needed for patient care (Correct answer)
- A policy for escalating cybersecurity incidents to senior management
Correct answer: An audit-logged override mechanism allowing emergency access to restricted PHI when needed for patient care
Break-the-glass is an emergency access override that allows authorized users to access restricted PHI in urgent clinical situations, with all access fully audit-logged.
Question 75: Under a comprehensive privacy program, which document maps the flow of PHI through an organization to identify privacy risks?
- Risk Assessment Report
- Business Associate Agreement
- Notice of Privacy Practices
- Data Flow Diagram or Data Map (Correct answer)
Correct answer: Data Flow Diagram or Data Map
A data flow diagram or data map visually represents how PHI moves through an organization, helping identify where it is collected, used, stored, and disclosed.
Question 76: Under HIPAA, which of the following entities is classified as a 'hybrid entity'?
- A hospital that also provides long-term care
- An organization that performs both covered and non-covered functions and designates its healthcare components (Correct answer)
- A business associate that also provides clinical services
- A health plan that covers both dental and medical services
Correct answer: An organization that performs both covered and non-covered functions and designates its healthcare components
A hybrid entity is a single legal entity that performs both covered and non-covered functions and officially designates its healthcare components subject to HIPAA.
Question 77: Under the HIPAA Breach Notification Rule, what is the deadline for notifying HHS of a breach affecting fewer than 500 individuals?
- Within 60 days of year-end (Correct answer)
- By March 1 of the following year
- Within 60 days of discovery
- Within 30 days of discovery
Correct answer: Within 60 days of year-end
For breaches affecting fewer than 500 individuals, covered entities may log them and report to HHS within 60 days after the end of the calendar year in which the breach occurred.
Question 78: A covered company has been asked in writing to postpone notifying the public of a data breach because it would complicate an investigation. How long may the covered entity delay sending the notice?
- Who is accessing information for business needs within the organization
- By the amount time specified in the request. (Correct answer)
- Designated record set
- Implement based on organizational assessment
Correct answer: By the amount time specified in the request.
Under the HIPAA Breach Notification Rule, if law enforcement provides a written statement that notification would impede an investigation, the covered entity must delay only for the specific time period stated in that request. The other options describe access-control or record-set concepts unrelated to a notification delay.
Question 79: Which federal law enacted in 2009 extended HIPAA privacy and security obligations directly to Business Associates?
- ACA
- GINA
- HITECH Act (Correct answer)
- ARRA
Correct answer: HITECH Act
The Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 made Business Associates directly liable for HIPAA compliance.
Question 80: Which of the following is under HIPAA and involves giving a primary care provider a copy of an emergency department visit report?
- Fair underwriting practices
- Disclosure of protected health information (Correct answer)
- Fair claims practices
- Coordination of benefits
Correct answer: Disclosure of protected health information
Providing a copy of an emergency room visit report to a primary care provider is an example of a "disclosure of protected health information" under HIPAA. <br> <br> HIPAA, the Health Insurance Portability and Accountability Act, establishes rules and regulations to protect the privacy and security of individuals' protected health information (PHI). PHI refers to any individually identifiable health information held or transmitted by a covered entity or its business associates.
Question 81: Under HIPAA, which of the following is NOT one of the 18 identifiers that must be removed to achieve Safe Harbor de-identification?
- Vehicle identifiers and serial numbers
- Patient's blood type (Correct answer)
- Full-face photographs
- ZIP codes (first 3 digits retained if population > 20,000)
Correct answer: Patient's blood type
Blood type is not among the 18 HIPAA Safe Harbor identifiers because it is not individually identifying; the 18 identifiers focus on names, dates, geographic data, contact information, and unique ID numbers.
Question 82: Which of the following organizations maintains the 'Wall of Shame' โ the public list of healthcare breaches affecting 500 or more individuals?
- NIST National Cybersecurity Center
- HHS Office for Civil Rights (OCR) (Correct answer)
- The American Health Information Management Association (AHIMA)
- The Joint Commission
Correct answer: HHS Office for Civil Rights (OCR)
OCR maintains the public breach portal (colloquially called the 'Wall of Shame') listing breaches affecting 500 or more individuals as required by HITECH.
Question 83: The HIPAA Security Rule's Transmission Security standard is designed to protect ePHI when it is:
- Stored on portable devices such as laptops
- Accessed by workforce members at workstations
- Transmitted over electronic communications networks (Correct answer)
- Transferred between departments within the same facility
Correct answer: Transmitted over electronic communications networks
The Transmission Security standard requires covered entities to implement technical security measures to guard against unauthorized access to ePHI transmitted over electronic communications networks.
Question 84: Under the HIPAA Minimum Necessary standard, which of the following disclosures is EXEMPT from the requirement?
- Disclosures for treatment purposes to treating providers (Correct answer)
- Disclosures to health plan auditors
- Disclosures for payment reconciliation
- Disclosures to business associates
Correct answer: Disclosures for treatment purposes to treating providers
The Minimum Necessary standard does not apply to disclosures to or requests by a healthcare provider for treatment purposes.
Question 85: Under the HIPAA Security Rule, what is the significance of documenting security decisions and policies even when a covered entity is small?
- Documentation is required to demonstrate compliance during HHS audits and investigations, and scalability of safeguards depends on documented risk analysis findings (Correct answer)
- Documentation is optional if the covered entity has never experienced a breach
- Documentation is only required for covered entities with more than 50 employees
- Small covered entities are exempt from documentation requirements if they use a certified EHR
Correct answer: Documentation is required to demonstrate compliance during HHS audits and investigations, and scalability of safeguards depends on documented risk analysis findings
The Security Rule requires all covered entities, regardless of size, to document policies, procedures, and risk analysis findings because documentation is the evidence of compliance reviewed during audits and breach investigations.
Question 86: What is the key difference between the HIPAA Privacy Rule and the HIPAA Security Rule?
- The Privacy Rule is enforced by ONC; the Security Rule is enforced by OCR
- The Privacy Rule is voluntary; the Security Rule is mandatory
- The Privacy Rule applies only to hospitals; the Security Rule applies to all covered entities
- The Privacy Rule covers all PHI in any form; the Security Rule covers only electronic PHI (ePHI) (Correct answer)
Correct answer: The Privacy Rule covers all PHI in any form; the Security Rule covers only electronic PHI (ePHI)
The Privacy Rule applies to protected health information in all forms (oral, paper, electronic), while the Security Rule specifically addresses electronic PHI (ePHI).
Question 87: A hospital discovers a breach on March 15. Under HIPAA, individual breach notifications must be sent no later than:
- June 14 (90 days after discovery)
- April 14 (30 days after discovery)
- May 14 (60 days after discovery) (Correct answer)
- March 30 (15 days after discovery)
Correct answer: May 14 (60 days after discovery)
Individual notifications must be provided without unreasonable delay and no later than 60 days following discovery of the breach.
Question 88: Under NIST guidelines adopted for HIPAA compliance, what does the acronym 'FIPS' stand for?
- Functional Information Protection Schema
- Federal Information Processing Standards (Correct answer)
- Federal Information Privacy Standards
- Federated Identity and Privacy System
Correct answer: Federal Information Processing Standards
FIPS stands for Federal Information Processing Standards, which are NIST-issued standards often referenced in HIPAA security guidance, particularly for encryption.
Question 89: Which of the following is an example of a technical safeguard under the HIPAA Security Rule?
- Role-based access control limiting ePHI access by job function (Correct answer)
- Policies governing workstation placement in patient areas
- Workforce security awareness training
- Visitor sign-in logs at a data center
Correct answer: Role-based access control limiting ePHI access by job function
Role-based access control is a technical safeguard โ it uses technology to ensure workforce members access only the ePHI necessary for their job functions.
Question 90: An example of a policy that details the tasks that may be carried out on computers and laptops inside an organization
- Security update
- Risk avoidance
- Workstation use (Correct answer)
- Exclusion
Correct answer: Workstation use
Workstation Use is the HIPAA Security Rule physical safeguard standard that requires policies specifying the proper functions, manner of performance, and physical environment for devices that access ePHI. Risk avoidance is a risk-management strategy, not a usage policy, and exclusion and security update do not define what tasks may be performed on workstations.
Question 91: Which of the following best describes the HIPAA concept of 'treatment, payment, and health care operations' (TPO)?
- Administrative safeguards required by the Security Rule
- Three categories requiring written patient authorization before PHI disclosure
- Permitted purposes for PHI use and disclosure that generally do not require patient authorization (Correct answer)
- Breach categories under the Breach Notification Rule
Correct answer: Permitted purposes for PHI use and disclosure that generally do not require patient authorization
TPO represents the core permitted purposes under the Privacy Rule where covered entities can use and disclose PHI without patient authorization.
Question 92: Which HIPAA standard requires covered entities to have written contracts with business associates before sharing PHI?
- Data Sharing Protocol (DSP)
- Business Associate Agreement (BAA) (Correct answer)
- Privacy Impact Assessment (PIA)
- Memorandum of Understanding (MOU)
Correct answer: Business Associate Agreement (BAA)
A Business Associate Agreement (BAA) is the HIPAA-required written contract that establishes the permitted uses and disclosures of PHI by a business associate.
Question 93: The Contingency Plan standard under the HIPAA Security Rule's Administrative Safeguards requires which of the following implementation specifications as 'required' (not addressable)?
- Applications and data criticality analysis
- Data backup plan and disaster recovery plan
- Emergency mode operation plan and testing and revision procedures
- Both A and B (Correct answer)
Correct answer: Both A and B
The required contingency plan implementation specifications are the data backup plan, disaster recovery plan, and emergency mode operation plan; testing/revision procedures and criticality analysis are addressable.
Question 94: Under the HIPAA Security Rule, which of the following best describes the purpose of 'entity authentication'?
- Authenticating the integrity of ePHI data during transmission
- Verifying that a business associate is HIPAA-compliant before signing a BAA
- Verifying that a person or entity seeking access to ePHI is who they claim to be before granting access (Correct answer)
- Verifying the identity of hardware devices connecting to a network
Correct answer: Verifying that a person or entity seeking access to ePHI is who they claim to be before granting access
Entity authentication (45 CFR ยง164.312(d)) requires covered entities to verify the identity of any person or entity seeking access to ePHI before granting access.
Question 95: An employee repeatedly accesses the medical records of a celebrity patient out of curiosity without a treatment, payment, or operations need. This is best described as:
- A permissible use for health care operations
- Snooping โ an internal privacy violation (Correct answer)
- An authorized disclosure under the Privacy Rule
- An incidental disclosure
Correct answer: Snooping โ an internal privacy violation
Accessing PHI without a permissible purpose (such as treatment, payment, or operations) constitutes a privacy violation commonly called snooping or workforce misconduct.
Question 96: A hacker encrypts a hospital's ePHI and demands ransom. Under HIPAA's Breach Notification Rule, this event is presumed to be what?
- A security incident only, not a breach
- Automatically exempt if the ransom is paid
- A breach unless the entity can demonstrate low probability of PHI compromise (Correct answer)
- Not covered because it involves external actors
Correct answer: A breach unless the entity can demonstrate low probability of PHI compromise
A ransomware attack on ePHI is presumed to be a reportable breach unless the covered entity can demonstrate through a four-factor risk assessment that there is a low probability the PHI was compromised.
Question 97: Which of the following is an example of a physical safeguard required by the HIPAA Security Rule?
- Encryption and decryption mechanisms
- Audit controls and automatic logoff
- User authentication and unique user identification
- Workstation use policies and physical access controls to facilities (Correct answer)
Correct answer: Workstation use policies and physical access controls to facilities
Physical safeguards include facility access controls, workstation use policies, and device and media controls to protect electronic PHI from physical threats.
Question 98: The HIPAA Security Rule specifically protects which type of protected health information (PHI)?
- Electronic protected health information (ePHI) only (Correct answer)
- All forms of PHI including oral, paper, and electronic
- Verbal and electronic protected health information
- Paper and electronic protected health information
Correct answer: Electronic protected health information (ePHI) only
The HIPAA Security Rule applies exclusively to electronic protected health information (ePHI) โ PHI that is created, received, maintained, or transmitted in electronic form.
Question 99: Under the HIPAA Security Rule, what is the primary responsibility of the designated Security Official (Security Officer)?
- To conduct all security risk analyses personally each year
- To be responsible for the development and implementation of policies and procedures required by the Security Rule (Correct answer)
- To approve every request for access to ePHI
- To serve as the organization's liaison with the Department of Health and Human Services
Correct answer: To be responsible for the development and implementation of policies and procedures required by the Security Rule
The Security Official is responsible for developing and implementing the security policies and procedures required by the HIPAA Security Rule for the covered entity.
Question 100: Under HIPAA, which of the following statements about the Right of Access is TRUE?
- Access may be permanently denied if the record is voluminous
- Psychotherapy notes must be provided upon request
- Covered entities must provide access within 15 days
- Covered entities may charge a reasonable cost-based fee for copies (Correct answer)
Correct answer: Covered entities may charge a reasonable cost-based fee for copies
Covered entities may charge a reasonable, cost-based fee for providing copies of PHI, covering labor, supplies, and postage, but may not profit from access requests.
Question 101: What is the goal of 'de-identification' of PHI under HIPAA?
- To remove identifiers so the information cannot reasonably identify an individual (Correct answer)
- To convert PHI into a limited data set for research
- To encrypt PHI so only authorized users can read it
- To anonymize only the patient's name and date of birth
Correct answer: To remove identifiers so the information cannot reasonably identify an individual
De-identification removes or obscures the 18 HIPAA-specified identifiers so that the remaining data cannot reasonably be used to identify an individual.
Question 102: Under HIPAA, what is the 'right of access' that patients have regarding their PHI?
- The right to demand deletion of all their PHI immediately
- The right to access any provider's network system at any time
- The right to inspect and obtain a copy of their PHI held in a designated record set (Correct answer)
- The right to view real-time system audit logs containing their data
Correct answer: The right to inspect and obtain a copy of their PHI held in a designated record set
The HIPAA right of access gives individuals the right to inspect and receive a copy of their PHI maintained in a covered entity's designated record set.
Question 103: The HIPAA Security Rule organizes its standards into three categories of safeguards. Which of the following correctly lists all three?
- Organizational, Physical, and Logical
- Administrative, Physical, and Technical (Correct answer)
- Policy, Physical, and Procedural
- Administrative, Operational, and Technical
Correct answer: Administrative, Physical, and Technical
The HIPAA Security Rule requires covered entities to implement Administrative, Physical, and Technical safeguards to protect electronic protected health information (ePHI).
Question 104: Under the HIPAA Security Rule, which safeguard category includes workstation use policies and facility access controls?
- Organizational Safeguards
- Technical Safeguards
- Physical Safeguards (Correct answer)
- Administrative Safeguards
Correct answer: Physical Safeguards
Physical Safeguards govern physical access to facilities and workstations, including facility access controls, workstation use policies, and device and media controls.
Question 105: Which of the following HIPAA standards would contain the policies and procedures that specify the process for authorizing access to PHI?
- General authorization
- Access control
- Data privacy
- Access authorization (Correct answer)
Correct answer: Access authorization
Policies and procedures that define the process for granting access to protected health information (PHI) are typically addressed in the "Access Authorization" standard of the Health Insurance Portability and Accountability Act (HIPAA). Access authorization refers to the controls and mechanisms put in place to ensure that only authorized individuals can access PHI. <br> <br> The Access Authorization standard under HIPAA includes requirements for covered entities (such as healthcare providers, health plans, and healthcare clearinghouses) to implement policies and procedures that govern the granting and revoking of access to PHI. These policies and procedures should specify who can access PHI, under what circumstances, and for what purposes. They also typically outline the processes for reviewing and approving access requests, ensuring appropriate user authentication and authorization, and maintaining audit trails to track access to PHI.
Question 106: Which access control mechanism grants permissions based on an individual's role within an organization rather than their specific identity?
- Role-Based Access Control (RBAC) (Correct answer)
- Mandatory Access Control (MAC)
- Attribute-Based Access Control (ABAC)
- Discretionary Access Control (DAC)
Correct answer: Role-Based Access Control (RBAC)
RBAC assigns permissions according to job roles (e.g., nurse, billing clerk), simplifying administration and supporting the minimum necessary principle required by HIPAA.
Question 107: Which of the following is the strongest authentication method for protecting access to an EHR system?
- Biometric fingerprint scan alone
- A complex alphanumeric password changed every 90 days
- Security questions plus a PIN
- Multi-factor authentication combining a password and a hardware token (Correct answer)
Correct answer: Multi-factor authentication combining a password and a hardware token
Multi-factor authentication (MFA) combining something you know (password) and something you have (hardware token) provides the strongest protection against unauthorized access.
Question 108: What type of PHI is specifically excluded from the HIPAA Breach Notification Rule's definition of PHI for breach purposes?
- PHI in a Limited Data Set (Correct answer)
- PHI in paper form
- PHI in oral form
- PHI maintained in EHR systems
Correct answer: PHI in a Limited Data Set
Limited Data Sets (which remove direct identifiers but retain some indirect identifiers like dates and geographic data) are excluded from the Breach Notification Rule's definition of PHI for breach purposes when covered by a DUA.
Question 109: Which federal agency is primarily responsible for enforcing the HIPAA Privacy and Security Rules?
- HHS Office for Civil Rights (OCR) (Correct answer)
- Office of the National Coordinator for Health Information Technology (ONC)
- Federal Trade Commission (FTC)
- Centers for Medicare & Medicaid Services (CMS)
Correct answer: HHS Office for Civil Rights (OCR)
The HHS Office for Civil Rights (OCR) is the primary federal agency responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules.
Question 110: A risk analysis under the HIPAA Security Rule must identify threats to the confidentiality, integrity, and availability of ePHI. Which document type formally captures this assessment?
- Business Associate Agreement
- Risk Assessment Report (Correct answer)
- Notice of Privacy Practices
- Workforce Training Record
Correct answer: Risk Assessment Report
The Risk Assessment Report documents identified threats, vulnerabilities, likelihood, and impact, fulfilling the Security Rule's requirement for a formal, documented risk analysis.
Question 111: A covered entity's risk management plan should achieve which primary goal per the HIPAA Security Rule?
- Eliminate all identified risks to ePHI
- Transfer all residual risk to business associates
- Document every potential vulnerability in detail
- Reduce risks to ePHI to a reasonable and appropriate level (Correct answer)
Correct answer: Reduce risks to ePHI to a reasonable and appropriate level
Risk management under the Security Rule aims to reduce risks and vulnerabilities to ePHI to a reasonable and appropriate level โ not necessarily eliminate them entirely.
Question 112: A hospital's privacy program is undergoing an external assessment. Which standard would be MOST appropriate for benchmarking privacy program maturity in a US healthcare context?
- PCI DSS controls
- SOC 2 Type II criteria
- NIST Privacy Framework (PF) (Correct answer)
- GDPR compliance checklist
Correct answer: NIST Privacy Framework (PF)
The NIST Privacy Framework (PF) provides a voluntary, risk-based framework for managing privacy risks that aligns well with US healthcare privacy requirements including HIPAA.
Question 113: Which of the following is a required implementation specification under the HIPAA Security Rule's Administrative Safeguards?
- Encryption of data at rest
- Facility access controls
- Workforce training and management (Correct answer)
- Workstation security
Correct answer: Workforce training and management
Workforce training and management, including security awareness training, is a required implementation specification within the Administrative Safeguards of the HIPAA Security Rule.
Question 114: Under the HIPAA Security Rule, what is an 'audit control' and why is it required?
- A process to approve user access; required to prevent unauthorized logins
- Hardware, software, or procedural mechanisms to record and examine activity in systems containing ePHI; required to detect and investigate security incidents (Correct answer)
- Encryption of audit logs; required to prevent tampering
- An annual review of security policies; required for compliance documentation
Correct answer: Hardware, software, or procedural mechanisms to record and examine activity in systems containing ePHI; required to detect and investigate security incidents
Audit controls are mechanisms that record and examine activity in systems containing ePHI, enabling organizations to detect, investigate, and respond to security incidents and policy violations.
Question 115: A healthcare organization wants to share a patient's case study in a medical journal. Which is the MOST appropriate privacy approach?
- Obtain verbal consent from the patient prior to submission
- De-identify the information to Safe Harbor standards before publication (Correct answer)
- File an IRB waiver of authorization for research purposes
- Share the case study since medical education is a permitted TPO purpose
Correct answer: De-identify the information to Safe Harbor standards before publication
Publishing de-identified case studies that meet the Safe Harbor standard removes HIPAA applicability entirely and is the most appropriate approach for journal publication.
Question 116: The Workforce Security standard under the HIPAA Security Rule's Administrative Safeguards requires covered entities to:
- Restrict ePHI access to clinical staff only
- Implement policies and procedures to ensure that workforce members have appropriate access to ePHI and to prevent those who do not have access from obtaining it (Correct answer)
- Provide annual HIPAA security training to all workforce members
- Conduct background checks on all employees who handle ePHI
Correct answer: Implement policies and procedures to ensure that workforce members have appropriate access to ePHI and to prevent those who do not have access from obtaining it
Workforce Security requires policies ensuring appropriate ePHI access for those who need it while preventing unauthorized access by those who do not, covering authorization, supervision, and termination procedures.
Question 117: Under HIPAA, what must a covered entity do if it maintains PHI about deceased individuals?
- Immediately destroy all PHI upon a patient's death
- Maintain HIPAA protections for PHI of deceased individuals for 50 years after death (Correct answer)
- PHI of deceased individuals loses HIPAA protection immediately upon death
- Disclose PHI of deceased individuals freely since privacy rights end at death
Correct answer: Maintain HIPAA protections for PHI of deceased individuals for 50 years after death
HIPAA protections extend to PHI of deceased individuals for 50 years following death, after which the information is no longer subject to HIPAA.
Question 118: Which governance framework is MOST commonly used in healthcare to align IT security controls with business objectives and regulatory requirements?
- COBIT (Correct answer)
- Six Sigma
- ISO 9001
- COSO ERM
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is widely used in healthcare IT governance to align security controls with organizational objectives and compliance requirements.
Question 119: Under the HIPAA Security Rule, what must a covered entity do when it terminates a workforce member's employment?
- Archive the employee's ePHI access logs for 6 years
- Implement a termination procedure that includes removal of system access (Correct answer)
- Submit a workforce change notification to HHS
- Only notify the Privacy Officer of the termination
Correct answer: Implement a termination procedure that includes removal of system access
Workforce Security standards require covered entities to implement termination procedures including removing system access to prevent unauthorized use of ePHI post-employment.
Question 120: Which of the following is a key privacy consideration when implementing a Health Information Exchange (HIE)?
- Establishing governance agreements that address consent models, data use limitations, and break-the-glass procedures (Correct answer)
- Restricting HIE access to only primary care providers
- Ensuring all participating organizations use the same EHR system
- Requiring all patients to opt in to all HIE data sharing by default
Correct answer: Establishing governance agreements that address consent models, data use limitations, and break-the-glass procedures
HIE governance agreements must address how participant organizations handle consent, limit data use to appropriate purposes, and manage emergency access (break-the-glass) scenarios.
Question 121: A patient requests an amendment to their medical record because they believe it contains an error. The covered entity denies the request. What must the covered entity provide?
- Notice to HHS of the denial
- Verbal explanation within 30 days
- Written denial and the right to submit a statement of disagreement (Correct answer)
- A corrected record regardless of the denial
Correct answer: Written denial and the right to submit a statement of disagreement
When a covered entity denies an amendment request, it must provide a written denial and inform the individual of the right to submit a statement of disagreement to be included in the record.
Question 122: A new business partner was employed by a covered organization. The business associate asked the covered entity to sign the contract provided by the vendor during the assessment of the business associates agreement. Is this a proper procedure?
- Access establishment and modifications
- Device controls
- All electronic systems
- Yes, the covered entity must review the documentation in the business associate agreement and agree to it (Correct answer)
Correct answer: Yes, the covered entity must review the documentation in the business associate agreement and agree to it
Yes โ the covered entity is responsible for reviewing the terms of a Business Associate Agreement and agreeing to them before signing, so reviewing the vendor-provided contract is proper procedure. The other options reference Security Rule administrative controls, not the BAA review process.
Question 123: In healthcare security, what does the acronym 'CIA' stand for in the context of information security?
- Compliance, Integration, Assurance
- Central Intelligence Agency
- Confidentiality, Integrity, Availability (Correct answer)
- Control, Identify, Authenticate
Correct answer: Confidentiality, Integrity, Availability
The CIA triad โ Confidentiality, Integrity, and Availability โ represents the three core principles of information security that HIPAA's Security Rule is designed to protect.
Question 124: Which of the following best describes the concept of 'integrity' in the context of the HIPAA Security Rule?
- Encrypting ePHI during transmission over open networks
- Restricting ePHI access to only authorized workforce members
- Protecting ePHI from improper alteration or destruction (Correct answer)
- Ensuring ePHI is accessible to authorized users when needed
Correct answer: Protecting ePHI from improper alteration or destruction
Integrity under HIPAA Security Rule means that ePHI has not been altered or destroyed in an unauthorized manner, preserving its accuracy and completeness.
Question 125: What is the maximum civil monetary penalty under HIPAA for violations due to willful neglect that are not corrected?
- $50,000 per violation up to $1.5 million per year (Correct answer)
- $250,000 per violation with no annual cap
- $100,000 per violation up to $1.5 million per year
- $10,000 per violation up to $250,000 per year
Correct answer: $50,000 per violation up to $1.5 million per year
Willful neglect violations not corrected carry penalties of $50,000 per violation up to a maximum of $1.5 million per calendar year for identical violations.
Question 126: A healthcare organization implements a 'Privacy by Design' approach. Which principle best describes this concept?
- Publishing a comprehensive privacy policy annually
- Retroactively reviewing systems for privacy risks after deployment
- Designating a privacy champion in each department
- Integrating privacy protections into the design and architecture of systems from the outset (Correct answer)
Correct answer: Integrating privacy protections into the design and architecture of systems from the outset
Privacy by Design embeds privacy protections into systems and processes from the beginning of development rather than as an afterthought.
Question 127: A healthcare organization uses a cloud-based EHR. Under HIPAA, which type of agreement must be in place with the cloud provider?
- Service Level Agreement (SLA)
- Business Associate Agreement (BAA) (Correct answer)
- Non-Disclosure Agreement (NDA)
- Data Governance Agreement (DGA)
Correct answer: Business Associate Agreement (BAA)
Cloud providers that create, receive, maintain, or transmit ePHI on behalf of a covered entity are business associates and must have a BAA in place.
Question 128: Which entities are directly required to comply with the HIPAA Security Rule?
- Covered entities only
- All entities that handle any patient data
- Business associates only
- Covered entities and business associates (Correct answer)
Correct answer: Covered entities and business associates
Both covered entities (health plans, healthcare clearinghouses, and certain healthcare providers) and their business associates are required to comply with the HIPAA Security Rule.
Question 129: Under the Technical Safeguards of the HIPAA Security Rule, which implementation specification for Access Control is designated as 'required'?
- Automatic logoff
- Unique user identification (Correct answer)
- Emergency access procedure
- Encryption and decryption
Correct answer: Unique user identification
Unique user identification is a required implementation specification, ensuring each user is assigned a unique name or number to track user identity and activity within ePHI systems.
Question 130: A healthcare organization discovers that its EHR vendor suffered a cyberattack that exposed ePHI. Under HIPAA, the FIRST step the covered entity should take is:
- Submit a complaint to OCR before conducting an internal assessment
- Immediately send breach notifications to all potentially affected patients
- Confirm the scope of the incident with the vendor and obtain details to conduct its own HIPAA breach risk assessment (Correct answer)
- Terminate the BAA with the vendor immediately
Correct answer: Confirm the scope of the incident with the vendor and obtain details to conduct its own HIPAA breach risk assessment
Before taking any notification actions, the covered entity must gather information from the vendor to conduct its own four-factor risk assessment to determine whether a reportable breach occurred.
Question 131: Which technology provides the strongest protection for ePHI stored on a lost or stolen laptop under HIPAA?
- Remote wipe capability via MDM
- Password-protected BIOS
- Multi-factor authentication for Windows login
- Full-disk encryption using FIPS 140-2 validated modules (Correct answer)
Correct answer: Full-disk encryption using FIPS 140-2 validated modules
Full-disk encryption using FIPS 140-2 validated cryptographic modules renders data unreadable on a stolen device and qualifies for HIPAA's encryption safe harbor.
Question 132: Under HIPAA, which of the following is considered a 'hybrid entity'?
- A hospital that operates across multiple states
- An entity that uses both paper and electronic health records
- A business associate that also acts as a covered entity
- An organization that performs both covered and non-covered functions (Correct answer)
Correct answer: An organization that performs both covered and non-covered functions
A hybrid entity is an organization that performs both HIPAA-covered healthcare functions and non-covered functions and has designated its health care components accordingly.
Question 133: Under the HIPAA Privacy Rule, a covered entity must designate which role to be responsible for developing and implementing its privacy policies?
- Compliance Officer
- Health Information Manager
- Chief Information Officer (CIO)
- Privacy Officer (Correct answer)
Correct answer: Privacy Officer
The HIPAA Privacy Rule at 45 CFR ยง164.530(a) requires covered entities to designate a Privacy Officer responsible for privacy policy development and implementation.
Question 134: When a business associate discovers a breach of PHI, within what timeframe must it notify the covered entity?
- Within 24 hours of discovery
- Within 30 days of discovery
- Without unreasonable delay and within 60 days of discovery (Correct answer)
- Immediately, with no delay
Correct answer: Without unreasonable delay and within 60 days of discovery
A business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 days following discovery.
Question 135: In healthcare security, what is the primary purpose of a 'penetration test'?
- Auditing user account permissions for compliance
- Simulating real-world attacks to identify exploitable vulnerabilities before malicious actors do (Correct answer)
- Testing the physical strength of server room locks
- Stress-testing application performance under high load
Correct answer: Simulating real-world attacks to identify exploitable vulnerabilities before malicious actors do
Penetration testing uses ethical hackers to simulate real attacks against healthcare systems, identifying exploitable vulnerabilities that automated scans may miss.
Question 136: Which of the following encryption standards is generally accepted for protecting ePHI in transit under HIPAA Security Rule guidance?
- TLS 1.2 or higher (Correct answer)
- SSL 2.0
- MD5 hashing
- TLS 1.0
Correct answer: TLS 1.2 or higher
NIST and HHS guidance recommend TLS 1.2 or higher for encrypting ePHI in transit, as older protocols have known vulnerabilities.
Question 137: A healthcare organization's contingency plan must include which of the following as a required component under the HIPAA Security Rule?
- A data backup plan (Correct answer)
- An off-site storage agreement
- A quarterly disaster drill schedule
- A disaster recovery vendor contract
Correct answer: A data backup plan
The HIPAA Security Rule requires a data backup plan as a required implementation specification within the contingency plan standard.
Question 138: Which of the following situations falls under the minimal standards?
- Business associate agreement
- Information system activity review
- Disclosures for business associates activities (Correct answer)
- Certificate authorities
Correct answer: Disclosures for business associates activities
The minimum necessary requirements apply to the scenario of "disclosures for business associates' activities." <br> <br> Under the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule, the minimum necessary standard requires covered entities (such as healthcare providers, health plans, and healthcare clearinghouses) to make reasonable efforts to limit the use, disclosure, or request of protected health information (PHI) to the minimum necessary to accomplish the intended purpose.
Question 139: After three unsuccessful log-in attempts in three minutes, a system is programmed to lock a user out. This is an illustration of
- Log-in monitoring (Correct answer)
- Risk mitigation
- Password management
- Security reminders
Correct answer: Log-in monitoring
Log-in monitoring refers to the practice of tracking and analyzing log-in attempts to detect and respond to suspicious or unauthorized activities related to user authentication. It involves monitoring and analyzing log-in events, such as successful and unsuccessful log-in attempts, to identify patterns or anomalies that may indicate potential security threats or breaches.
Question 140: What is the primary purpose of a risk analysis under the HIPAA Security Rule?
- To create an audit trail for all ePHI access events
- To document all workforce members with access to ePHI
- To identify and assess threats, vulnerabilities, and risks to ePHI confidentiality, integrity, and availability (Correct answer)
- To validate encryption key management procedures
Correct answer: To identify and assess threats, vulnerabilities, and risks to ePHI confidentiality, integrity, and availability
A risk analysis identifies and assesses potential threats and vulnerabilities to ePHI to determine the likelihood and impact of security incidents.
Question 141: When must a covered entity notify the Secretary of HHS of a breach affecting fewer than 500 individuals in a single state?
- Within 60 days of the breach occurrence date
- Within 60 days of the end of the calendar year in which the breach was discovered (Correct answer)
- Within 30 days of breach discovery
- Within 60 days of discovery
Correct answer: Within 60 days of the end of the calendar year in which the breach was discovered
Small breaches (fewer than 500 individuals) must be logged and reported to HHS annually no later than 60 days after the end of the calendar year in which they were discovered.
Question 142: The organization must take action if a health insurance provider contacts a member to advertise a line of car insurance it sells.
- All electronic systems
- Risk avoidance
- After 6 years
- Authorization for disclosure for marketing purposes (Correct answer)
Correct answer: Authorization for disclosure for marketing purposes
If a health insurance company is making a communication to a member promoting a vehicle insurance product offered by the same company, the organization needs the member's "authorization for disclosure for marketing purposes."
Question 143: Which of the following events would NOT qualify as a 'breach' under the HIPAA Breach Notification Rule?
- A workforce member accesses a patient's record for treatment purposes under a valid TPO purpose (Correct answer)
- A workforce member accidentally emails a patient's discharge summary to the wrong provider
- A billing clerk views patient records that are unrelated to her job function
- A laptop containing unencrypted ePHI is stolen from a locked car
Correct answer: A workforce member accesses a patient's record for treatment purposes under a valid TPO purpose
Accessing PHI for legitimate treatment, payment, or operations purposes is not an impermissible use and therefore does not constitute a breach under HIPAA.
Question 144: How does the HIPAA Security Rule define electronic protected health information (ePHI)?
- Any health data stored on a computer system, regardless of whether it identifies an individual
- Protected health information transmitted via the internet or email only
- Individually identifiable health information that is created, received, maintained, or transmitted in electronic form (Correct answer)
- Medical records converted from paper format to electronic form
Correct answer: Individually identifiable health information that is created, received, maintained, or transmitted in electronic form
ePHI is individually identifiable health information that a covered entity creates, receives, maintains, or transmits in electronic form, covering all electronic media, not just internet transmissions.
Question 145: What kind of threat is equipment theft?
- Risk acceptance
- Burden of proof
- Acts of man (Correct answer)
- Workstation use
Correct answer: Acts of man
The theft of equipment is considered an example of a threat known as "acts of man" or "human threats." Acts of man refer to intentional or deliberate actions carried out by individuals that pose a risk to the security and safety of assets, information, or systems.
Question 146: In healthcare cybersecurity, what does the term 'patch management' refer to?
- Creating backup copies of software configurations
- Monitoring network traffic for unusual data patterns
- The systematic process of identifying, acquiring, testing, and deploying software updates to fix vulnerabilities (Correct answer)
- Managing software licensing agreements for clinical applications
Correct answer: The systematic process of identifying, acquiring, testing, and deploying software updates to fix vulnerabilities
Patch management is the structured process of keeping software current with security and functional updates to remediate known vulnerabilities before they are exploited.
Question 147: Under the HIPAA Security Rule, which of the following is classified as an 'Addressable' implementation specification?
- Audit controls
- Unique user identification
- Emergency access procedure
- Automatic logoff (Correct answer)
Correct answer: Automatic logoff
Automatic logoff is an Addressable specification under the Access Control standard, meaning entities must implement it if reasonable and appropriate or document why an equivalent measure was chosen.
Question 148: Under HIPAA, which of the following PHI disposal methods is considered a safe harbor that renders a breach not reportable?
- Moving PHI to a secure internal archive
- Proper destruction (shredding, degaussing) rendering PHI unreadable or indecipherable (Correct answer)
- Deleting files from a computer hard drive
- Applying password protection to PHI files
Correct answer: Proper destruction (shredding, degaussing) rendering PHI unreadable or indecipherable
PHI that has been rendered unreadable, indecipherable, or destroyed through proper methods (shredding paper, degaussing/purging media) is excluded from breach notification requirements.
Question 149: Under HIPAA, which term describes a vendor that provides services to a covered entity and creates, receives, maintains, or transmits PHI in the course of providing those services?
- Qualified Service Organization
- Covered Entity
- Hybrid Entity
- Business Associate (Correct answer)
Correct answer: Business Associate
A business associate is a person or entity that performs services for a covered entity involving the use or disclosure of PHI, and must sign a Business Associate Agreement.
Question 150: What does the Evaluation standard under the HIPAA Security Rule's Administrative Safeguards require a covered entity to perform?
- Periodic technical and non-technical evaluations of the security policies and procedures in response to environmental or operational changes (Correct answer)
- A formal penetration test of all network-connected devices
- An annual third-party audit of all ePHI systems
- A review of all workforce access logs on a quarterly basis
Correct answer: Periodic technical and non-technical evaluations of the security policies and procedures in response to environmental or operational changes
The Evaluation standard requires covered entities to periodically assess how well their security policies and procedures meet the Security Rule requirements, particularly after operational or environmental changes.
Question 151: Which of the following BEST describes the concept of 'data minimization' in healthcare privacy program management?
- Reducing the number of systems that store PHI to fewer than three
- Limiting access to PHI to only the Privacy Officer and Security Officer
- Collecting and using only the minimum PHI necessary to accomplish the intended purpose (Correct answer)
- Deleting all PHI after 30 days regardless of retention requirements
Correct answer: Collecting and using only the minimum PHI necessary to accomplish the intended purpose
Data minimization means collecting, using, and retaining only the minimum PHI necessary for the specific purpose, consistent with HIPAA's Minimum Necessary standard.
Certified in Healthcare Privacy and Security (CHPS)
The CHPS credential, awarded by AHIMA, validates expertise in healthcare privacy and security program management, HIPAA compliance, information technology safeguards, and regulatory enforcement across healthcare organizations.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong โ answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds