← All CHP Flashcard Decks

Equipment Operation & Maintenance Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Equipment Operation & Maintenance flashcards as text
  1. A hospital's networked glucose monitoring system stores patient readings but lacks user authentication. Under HIPAA, this is considered:

    Answer: A vulnerability requiring remediation through risk management or documented compensating controls

    Glucose readings linked to a patient are ePHI; a device lacking authentication presents a security risk that must be addressed through HIPAA's Security Management Process.

  2. What is the PRIMARY purpose of a hardware asset inventory under the HIPAA Security Rule?

    Answer: To track all hardware and media containing ePHI to support accountability and security management

    A hardware asset inventory supports the Device and Media Controls standard by enabling organizations to know where ePHI resides and to manage equipment throughout its lifecycle.

  3. A physical therapist uses a tablet at multiple patient locations throughout the day. Which HIPAA-compliant practice should govern use of this device?

    Answer: A screen lock with a PIN or biometric should activate automatically after each session

    Automatic screen locks between sessions prevent unauthorized access to ePHI if the device is set down or lost, satisfying both the Workstation Security and Access Control standards.

  4. Under the HIPAA Security Rule, when a covered entity's business associate performs remote maintenance on equipment containing ePHI, which safeguard is MOST important?

    Answer: The session should use encrypted, authenticated remote access channels with activity logging

    Remote maintenance sessions involving ePHI must use encrypted and authenticated channels, and session activity must be logged to satisfy Audit Controls and Transmission Security standards.

  5. A covered entity discovers that a decommissioned server was sold at auction without sanitization, and the buyer found patient billing data on the drive. What type of event has likely occurred?

    Answer: A breach of unsecured PHI requiring the covered entity to follow breach notification procedures

    An impermissible disclosure of unsecured PHI is presumed to be a breach under the HIPAA Breach Notification Rule, triggering notification obligations to affected individuals, HHS, and potentially media.

  6. Which HIPAA Security Rule standard governs procedures for creating and restoring ePHI backup copies from medical equipment?

    Answer: Contingency Plan — Data Backup Plan (§164.308(a)(7)(ii)(A))

    The Contingency Plan's Data Backup Plan implementation specification requires establishing and implementing procedures to create and maintain exact retrievable copies of ePHI.

  7. A clinic uses a shared printer to print patient encounter forms. Which physical safeguard BEST reduces the risk of PHI exposure at the printer?

    Answer: Implementing print-release or pull-print technology requiring user authentication at the device

    Pull-print (or print-release) technology requires users to authenticate at the printer before documents are released, preventing PHI from sitting unattended in the output tray.

Equipment Operation & Maintenance Flashcards — CHP Study Cards with Answers