CHISSP CHISSP Healthcare Information Security & Risk Management 1 โ Questions and Answers
Question 1: Which risk management framework is most commonly adopted by US healthcare organizations to align information security with regulatory requirements?
- NIST Cybersecurity Framework (Correct answer)
- ISO/IEC 27001
- COBIT 5
- PCI DSS
Correct answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework is widely adopted by US healthcare organizations because it aligns with HIPAA Security Rule requirements and provides a flexible, risk-based approach.
Question 2: What is the primary purpose of a Healthcare Risk Analysis (HRA) under the HIPAA Security Rule?
- To identify and evaluate risks to the confidentiality, integrity, and availability of ePHI (Correct answer)
- To audit employee access logs for unauthorized activity
- To document physical security controls for server rooms
- To assess the financial impact of a data breach
Correct answer: To identify and evaluate risks to the confidentiality, integrity, and availability of ePHI
HIPAA's Security Rule ยง164.308(a)(1) requires covered entities to conduct an accurate and thorough assessment of potential risks to ePHI as the foundation of their security program.
Question 3: A healthcare organization classifies a threat as having HIGH likelihood and LOW impact. Which risk treatment action is MOST appropriate?
- Monitor and accept (Correct answer)
- Immediately remediate
- Transfer via cyber insurance
- Avoid by discontinuing the system
Correct answer: Monitor and accept
High likelihood/low impact risks generally fall into an acceptable risk zone that warrants monitoring rather than costly immediate remediation.
Question 4: Which of the following BEST describes residual risk in healthcare information security?
- Risk remaining after controls have been applied (Correct answer)
- Risk identified during the initial threat assessment
- Risk transferred to a business associate
- Risk eliminated through encryption
Correct answer: Risk remaining after controls have been applied
Residual risk is the level of risk that remains after security controls and countermeasures have been implemented, which must be accepted by management.
Question 5: Under the HIPAA Security Rule, which type of safeguard covers workforce training and security management policies?
- Administrative safeguards (Correct answer)
- Physical safeguards
- Technical safeguards
- Operational safeguards
Correct answer: Administrative safeguards
Administrative safeguards under ยง164.308 include policies, procedures, workforce training, and security management processes that govern how ePHI is protected.
Question 6: What is the recommended approach when a healthcare organization cannot fully remediate a known vulnerability due to legacy system constraints?
- Implement compensating controls and document the accepted risk (Correct answer)
- Immediately decommission the legacy system
- Report the vulnerability to HHS without further action
- Encrypt all data on the system and consider it compliant
Correct answer: Implement compensating controls and document the accepted risk
Compensating controls and documented risk acceptance are the recognized approach when full remediation is not feasible, provided the residual risk is within acceptable bounds.
Which risk management framework is most commonly adopted by US healthcare organizations to align information security with regulatory requirements?