โ† All CHP Flashcard Decks

CHP Business Associates & Vendor Management Flashcards

6 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CHP Business Associates & Vendor Management flashcards as text
  1. Under the HIPAA Security Rule, the primary purpose of a risk analysis is to:

    Answer: Identify potential threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI

    A risk analysis identifies potential threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI as required by the HIPAA Security Rule.

  2. How often must a covered entity perform a HIPAA Security Rule risk analysis?

    Answer: Periodically and whenever there are significant environmental or operational changes

    HIPAA requires risk analyses to be conducted periodically and whenever significant changes occur in the environment, operations, or technology.

  3. What must follow a completed HIPAA risk analysis?

    Answer: Implementation of a risk management plan addressing identified risks

    A risk analysis must be followed by a risk management plan that prioritizes and addresses the identified risks to ePHI.

  4. When evaluating a cloud service provider to handle ePHI, which factor is most critical from a HIPAA compliance standpoint?

    Answer: Whether the provider will sign a BAA and demonstrates HIPAA compliance

    Any cloud service provider that handles ePHI must be willing to enter a BAA and demonstrate the ability to comply with HIPAA requirements.

  5. How does the HIPAA 'minimum necessary' standard apply to business associates?

    Answer: Business associates must limit PHI access to only what is needed to perform their contracted function

    Business associates must restrict their use and disclosure of PHI to the minimum necessary to fulfill their contracted obligations.

  6. A covered entity that shares PHI with a vendor without executing a required BAA is subject to:

    Answer: HIPAA civil monetary penalties and potential corrective action

    Sharing PHI without a required BAA is itself a HIPAA violation exposing the covered entity to civil monetary penalties and OCR corrective action, regardless of whether a breach occurs.