← All CHP Flashcard Decks

Administrative, Physical & Technical Safeguards Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Administrative, Physical & Technical Safeguards flashcards as text
  1. A business associate uses a cloud storage service to store ePHI. Under HIPAA, who is responsible for ensuring the cloud service provider has appropriate safeguards in place?

    Answer: Both the covered entity and the business associate

    Both the covered entity and the business associate share responsibility for ensuring that subcontractors and vendors have appropriate safeguards through business associate agreements.

  2. What distinguishes a 'required' implementation specification from an 'addressable' one under the HIPAA Security Rule?

    Answer: Required specifications must be implemented; addressable specifications may be implemented, modified, or alternatively addressed based on the entity's risk assessment

    Required specifications must be implemented as written; addressable specifications allow covered entities to assess whether the specification is reasonable and appropriate given their environment.

  3. A practice management company processes insurance claims for a covered entity and stores ePHI on its servers. Under the Security Rule, this company must implement safeguards as a:

    Answer: Business associate

    A company that processes ePHI on behalf of a covered entity is a business associate and must implement all three categories of HIPAA Security Rule safeguards.

  4. When conducting a HIPAA risk analysis, which factor must be evaluated as part of the administrative safeguard requirements?

    Answer: The probability and criticality of potential risks to ePHI confidentiality, integrity, and availability

    A risk analysis must assess the probability and potential impact of threats to ePHI to determine appropriate risk management measures.

  5. A covered entity's password management policy requires unique passwords and prohibits sharing. This policy is best categorized under which HIPAA standard?

    Answer: Access control — unique user identification

    Unique user identification is a required implementation specification under access controls, requiring each user to have a distinct identifier to track individual ePHI access.

  6. Which of the following scenarios correctly applies the minimum necessary standard to ePHI access controls?

    Answer: A radiologist is given access to only imaging records and relevant patient demographics needed for her role

    The minimum necessary standard requires limiting ePHI access to only what is needed for each workforce member to perform their specific job function.

  7. Under HIPAA, which safeguard category specifically addresses the encryption of ePHI stored on portable devices such as laptops?

    Answer: Physical safeguards — device and media controls

    Device and media controls under physical safeguards govern the management of hardware and portable media that store ePHI, including policies around encryption of portable devices.