CHI Risk Management & Mitigation 3 — Questions and Answers
Question 1: A hospital's EHR vendor experiences a ransomware attack that disrupts patient record access. Which risk category best describes this event?
- Strategic risk
- Third-party / supply chain risk (Correct answer)
- Compliance risk
- Reputational risk
Correct answer: Third-party / supply chain risk
When a vendor's security failure causes disruption to a covered entity, it represents third-party or supply chain risk, highlighting the importance of Business Associate Agreements.
Question 2: In health informatics, what is the purpose of a Data Flow Diagram (DFD) during a risk assessment?
- To document organizational hierarchy
- To map how PHI moves between systems, processes, and external entities (Correct answer)
- To track software development progress
- To visualize network bandwidth utilization
Correct answer: To map how PHI moves between systems, processes, and external entities
DFDs identify all points where PHI is created, stored, transmitted, or destroyed, enabling risk assessors to uncover exposure points across data flows.
Question 3: Which security concept ensures that PHI cannot be altered or destroyed in an unauthorized manner?
- Confidentiality
- Availability
- Integrity (Correct answer)
- Non-repudiation
Correct answer: Integrity
Integrity, one of the three HIPAA Security Rule principles, ensures that electronic PHI is not improperly modified or deleted.
Question 4: An organization decides to discontinue a high-risk legacy system with no feasible control options. Which risk strategy is being employed?
- Risk mitigation
- Risk acceptance
- Risk avoidance (Correct answer)
- Risk transference
Correct answer: Risk avoidance
Risk avoidance eliminates the risk entirely by discontinuing the activity, system, or process that creates the exposure.
Question 5: Which role is primarily responsible for ensuring a risk management program aligns with organizational strategy and approving risk tolerance levels?
- Chief Information Security Officer (CISO)
- IT Help Desk Manager
- Board of Directors or Senior Leadership (Correct answer)
- System Administrator
Correct answer: Board of Directors or Senior Leadership
Risk tolerance and enterprise-wide risk appetite decisions must be set and approved by senior leadership or the board, as they reflect organizational strategy.
Question 6: What is the main advantage of using quantitative risk analysis over qualitative analysis?
- It is faster and requires fewer resources
- It produces numeric financial estimates enabling cost-benefit comparisons for controls (Correct answer)
- It relies solely on expert judgment
- It eliminates the need for threat modeling
Correct answer: It produces numeric financial estimates enabling cost-benefit comparisons for controls
Quantitative analysis produces monetary values (e.g., Annual Loss Expectancy) that allow organizations to compare control costs against expected losses.
Question 7: A covered entity implements automatic session timeouts on all EHR workstations. This is an example of which type of safeguard under the HIPAA Security Rule?
- Physical safeguard
- Technical safeguard (Correct answer)
- Administrative safeguard
- Operational safeguard
Correct answer: Technical safeguard
Automatic logoff is explicitly listed as a technical safeguard implementation specification under the HIPAA Security Rule's Access Control standard.
A hospital's EHR vendor experiences a ransomware attack that disrupts patient record access.
Which risk category best describes this event?