← All CHP Flashcard Decks

Administrative, Physical & Technical Safeguards Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Administrative, Physical & Technical Safeguards flashcards as text
  1. Under the HIPAA Security Rule, which of the following is an example of an administrative safeguard?

    Answer: Conducting a periodic security risk analysis

    A security risk analysis is an administrative safeguard because it involves policies and procedures for managing workforce behavior and security management processes.

  2. A covered entity must implement a contingency plan as part of its administrative safeguards. Which element is NOT required by the HIPAA Security Rule contingency plan standard?

    Answer: Off-site data replication schedule

    The Security Rule requires a data backup plan, disaster recovery plan, and emergency mode operation plan, but does not specifically mandate an off-site data replication schedule.

  3. What is the primary purpose of the HIPAA Security Rule's workforce security standard?

    Answer: To implement procedures for authorizing and supervising workforce members who work with ePHI

    The workforce security standard requires covered entities to implement procedures to ensure workforce members have appropriate access to ePHI and to prevent unauthorized access.

  4. A hospital's security officer discovers that a terminated employee's system access was not revoked for 10 days after termination. Which administrative safeguard was violated?

    Answer: Termination procedures under workforce security

    Termination procedures are an addressable implementation specification under workforce security that require prompt revocation of access when employment ends.

  5. Under HIPAA administrative safeguards, how often must a covered entity update its security risk analysis?

    Answer: Periodically and when environmental or operational changes occur

    The Security Rule requires the risk analysis to be performed periodically and whenever there are changes to the environment or operations that could affect ePHI security.

  6. Which scenario best demonstrates compliance with HIPAA's information access management standard?

    Answer: Access to ePHI is granted based on each employee's job role and minimum necessary need

    Information access management requires granting ePHI access based on job roles and the minimum necessary standard to limit exposure.

  7. A covered entity's security awareness and training program is considered which type of HIPAA safeguard?

    Answer: Administrative safeguard

    Security awareness and training is explicitly listed as a standard under administrative safeguards in the HIPAA Security Rule at 45 CFR § 164.308(a)(5).