Risk Management & Mitigation Flashcards
7 cards from real CHI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Mitigation flashcards as text
A health IT organization is selecting between two risk mitigation controls. Control A costs $50,000 and reduces ALE by $40,000; Control B costs $20,000 and reduces ALE by $35,000. Which control offers better value?
Answer: Control B, because its net benefit ($15,000) is higher relative to cost
Control B yields a net benefit of $15,000 ($35k reduction − $20k cost) vs. Control A's net benefit of −$10,000, making Control B the more cost-effective choice.
Which activity is part of the MONITOR step in a continuous risk management lifecycle?
Answer: Tracking control effectiveness and emerging threats over time
The Monitor step involves ongoing observation of control performance, environmental changes, and new threat intelligence to ensure risk posture remains acceptable.
A patient portal suffers a SQL injection attack exposing 600 patients' PHI. Under HIPAA, to which entity must the covered entity report this breach if it affects fewer than 500 individuals in a single state?
Answer: HHS Office for Civil Rights in the annual summary report
For breaches affecting fewer than 500 individuals, HIPAA requires reporting to HHS OCR in an annual log submitted no later than 60 days after the end of the calendar year.
Which term describes the process of systematically identifying assets, threats, vulnerabilities, and likelihood to calculate overall organizational risk exposure?
Answer: Risk assessment
A risk assessment is the structured process of identifying assets, analyzing threats and vulnerabilities, and estimating the likelihood and impact of potential harm.
An organization implements multi-factor authentication (MFA) on all remote access to clinical systems. This control primarily addresses which risk scenario?
Answer: Unauthorized access resulting from compromised user credentials
MFA adds a second verification factor so that a stolen or guessed password alone cannot grant unauthorized remote access to clinical systems.
What is the purpose of a 'heat map' in risk management reporting?
Answer: To visualize risk ratings by plotting likelihood against impact for quick prioritization
A risk heat map plots each identified risk on a likelihood vs. impact grid, color-coded by severity, enabling leadership to quickly identify and prioritize the highest risks.
Under the HIPAA Security Rule, which implementation specification requires organizations to have policies for handling PHI disposal and hardware reuse?
Answer: Device and Media Controls
The Device and Media Controls standard under the HIPAA Security Rule requires covered entities to implement policies for the disposal, reuse, and accountability of electronic media containing PHI.