← All CHP Flashcard Decks

Equipment Operation & Maintenance Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Equipment Operation & Maintenance flashcards as text
  1. Before disposing of a photocopier that processed PHI, a covered entity must:

    Answer: Sanitize or destroy the internal hard drive to prevent PHI exposure

    Modern photocopiers store images on internal hard drives, which must be sanitized or physically destroyed before disposal to prevent unauthorized PHI disclosure.

  2. Which HIPAA Security Rule standard directly requires covered entities to control physical access to workstations that access ePHI?

    Answer: Workstation Security (§164.310(c))

    The Workstation Security standard (§164.310(c)) specifically requires physical safeguards for workstations that access ePHI, including positioning, screen locks, and restricted access.

  3. A third-party technician needs to repair a server containing ePHI. What must be in place before granting access?

    Answer: A Business Associate Agreement (BAA) with the vendor

    Any vendor whose work may expose them to ePHI must have a BAA with the covered entity before being granted access, as required by the HIPAA Privacy and Security Rules.

  4. An organization is retiring old laptops used by clinical staff. Which media sanitization method is most appropriate for laptops with sensitive ePHI?

    Answer: Cryptographic erasure or physical destruction of storage media

    NIST SP 800-88 guidelines recommend cryptographic erasure or physical destruction to ensure ePHI is unrecoverable from retired media.

  5. Under HIPAA, which entity is responsible for ensuring that medical equipment used under a maintenance contract adequately protects ePHI?

    Answer: The covered entity, through proper BAAs and oversight of business associates

    Covered entities remain responsible for ePHI protection and must ensure maintenance contractors are bound by BAAs and comply with applicable HIPAA Security Rule safeguards.

  6. A hospital's MRI machine logs patient scan data directly to a networked drive. Which Security Rule implementation specification best governs activity monitoring for this device?

    Answer: Audit Controls (§164.312(b))

    Audit Controls (§164.312(b)) require hardware, software, and procedural mechanisms to record and examine activity in information systems that contain or use ePHI.

  7. When a covered entity loans a laptop containing ePHI to a traveling clinician, which safeguard is MOST critical to implement?

    Answer: Full-disk encryption

    Full-disk encryption ensures that if the device is lost or stolen, ePHI cannot be accessed without the decryption key, satisfying the Security Rule's encryption addressable specification.

Equipment Operation & Maintenance Flashcards — CHP Study Cards with Answers