CHAA HIPAA Privacy and Security Flashcards
6 cards from real CHAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CHAA HIPAA Privacy and Security flashcards as text
What is a 'risk analysis' under the HIPAA Security Rule?
Answer: A comprehensive assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI
A HIPAA risk analysis is a comprehensive assessment that identifies potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. It is a required administrative safeguard and the foundation of a HIPAA security program. The risk analysis must be ongoing, not a one-time event, and must lead to a risk management plan addressing identified threats.
How does HIPAA apply to deceased patients?
Answer: HIPAA protections continue for 50 years after death, and the personal representative of the deceased has the same access rights as the patient would have had
HIPAA continues to protect the PHI of deceased individuals for 50 years following the date of death. The personal representative of the estate (such as the executor) has the same rights regarding the decedent's PHI as the patient would have had when alive. Patient access staff should verify the authority of anyone requesting a deceased patient's information.
What is 'data integrity' in the context of HIPAA?
Answer: Ensuring that ePHI has not been altered or destroyed in an unauthorized manner and remains accurate and complete
Data integrity means ensuring that ePHI has not been improperly altered or destroyed, whether intentionally or accidentally, and that the information remains accurate, complete, and trustworthy. The HIPAA Security Rule requires mechanisms to protect the integrity of ePHI, including technical controls to detect unauthorized modifications and processes to maintain data accuracy.
What is a 'contingency plan' under the HIPAA Security Rule?
Answer: A plan for responding to emergencies or disasters that could damage systems containing ePHI, including data backup, disaster recovery, and emergency operations
A HIPAA contingency plan addresses how an organization will respond to emergencies, disasters, or system failures that could affect ePHI. Required components include a data backup plan, a disaster recovery plan, and an emergency mode operations plan. The plan ensures that critical ePHI remains available and protected even during adverse events such as natural disasters, cyberattacks, or system failures.
What is 'multi-factor authentication' and why is it important for HIPAA?
Answer: A security method requiring two or more verification factors to gain access, significantly reducing the risk of unauthorized access to ePHI
Multi-factor authentication (MFA) requires users to provide two or more verification factors to access a system, such as something they know (password), something they have (phone or token), and something they are (biometric). MFA significantly reduces the risk of unauthorized access to systems containing ePHI, even if passwords are compromised. While not explicitly required by HIPAA, it is strongly recommended and increasingly expected.
What is the HIPAA 'right to request restrictions'?
Answer: A patient's right to ask that the covered entity limit how it uses or discloses PHI for treatment, payment, or operations
Patients have the right to request that the covered entity restrict how it uses or discloses their PHI for treatment, payment, or healthcare operations. While covered entities are generally not required to agree, they must agree to restrict disclosure to a health plan for services paid entirely out of pocket. Any agreed-upon restrictions must be documented and followed.