CHISSP CHISSP Healthcare Information Security & Risk Management 2 โ Questions and Answers
Question 1: Which asset classification level typically applies to electronic Protected Health Information (ePHI) in a US healthcare organization?
- Restricted / Highly Confidential (Correct answer)
- Internal Use Only
- Public
- Sensitive but Unclassified
Correct answer: Restricted / Highly Confidential
ePHI is classified at the highest confidentiality level because unauthorized disclosure triggers HIPAA breach notification and significant legal penalties.
Question 2: A security analyst discovers that a business associate is storing ePHI without encryption on portable media. Which HIPAA safeguard has been violated?
- Technical safeguards โ encryption and decryption standard (Correct answer)
- Administrative safeguards โ workforce training
- Physical safeguards โ workstation use policy
- Organizational safeguards โ business associate agreement
Correct answer: Technical safeguards โ encryption and decryption standard
HIPAA ยง164.312(a)(2)(iv) addresses encryption and decryption as an addressable technical safeguard for ePHI on portable media.
Question 3: In a healthcare threat model, which threat actor is statistically responsible for the MOST healthcare data breaches according to HHS breach reports?
- Insider threats (workforce members) (Correct answer)
- Nation-state advanced persistent threats
- Script kiddies using commodity malware
- Competitors conducting corporate espionage
Correct answer: Insider threats (workforce members)
HHS breach portal data consistently shows that insider threats โ including accidental disclosures and intentional snooping by workforce members โ account for the largest share of healthcare breaches.
Question 4: What is the PRIMARY goal of a Business Impact Analysis (BIA) in a healthcare information security program?
- Identify critical systems and quantify the operational impact of their disruption (Correct answer)
- Document regulatory fines for non-compliance scenarios
- Map network topology for firewall configuration
- Determine encryption key rotation schedules
Correct answer: Identify critical systems and quantify the operational impact of their disruption
A BIA identifies critical business processes, the systems supporting them, and the financial/operational impact of downtime, informing recovery time and recovery point objectives.
Question 5: Which concept describes the maximum tolerable period that a healthcare system can be offline before unacceptable patient care harm occurs?
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Mean Time to Repair (MTTR)
Correct answer: Maximum Tolerable Downtime (MTD)
Maximum Tolerable Downtime (MTD) is the absolute upper limit of outage duration beyond which the organization cannot recover or patient harm becomes unacceptable.
Question 6: A penetration test on a hospital network reveals that IoT medical devices run unpatched firmware. Which risk mitigation strategy is MOST feasible given FDA regulatory constraints?
- Network segmentation isolating medical devices on a dedicated VLAN (Correct answer)
- Immediately applying vendor patches to all devices
- Replacing all IoT devices with air-gapped alternatives
- Disabling network connectivity on all medical devices
Correct answer: Network segmentation isolating medical devices on a dedicated VLAN
Network segmentation is the most practical control because FDA-regulated medical devices often cannot be patched without voiding clearance, making isolation the primary mitigation.
Which asset classification level typically applies to electronic Protected Health Information (ePHI) in a US healthcare organization?