← All CHP Flashcard Decks

Risk Management & Compliance Audits Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Compliance Audits flashcards as text
  1. Which HIPAA concept requires organizations to implement security measures that are reasonable and appropriate based on their size, complexity, and capabilities?

    Answer: Flexibility and scalability standard

    HIPAA's flexibility and scalability standard acknowledges that one-size-fits-all solutions are impractical, allowing organizations to tailor controls to their specific circumstances.

  2. During a risk analysis, an organization identifies that unencrypted laptops are used by field nurses. Which risk treatment option involves implementing full-disk encryption?

    Answer: Risk mitigation

    Risk mitigation reduces the likelihood or impact of a threat by implementing controls such as encryption to protect PHI on mobile devices.

  3. Which of the following is an example of 'residual risk' in HIPAA risk management?

    Answer: The risk that remains after implementing security controls

    Residual risk is the remaining exposure after controls have been applied; organizations must decide whether this level is acceptable or requires additional safeguards.

  4. A HIPAA audit reveals an organization has not updated its risk assessment in four years. Why is this problematic under the Security Rule?

    Answer: Risk assessments must reflect current threats, vulnerabilities, and operational changes

    The Security Rule requires ongoing, not one-time, risk analysis that accounts for environmental and operational changes that introduce new vulnerabilities.

  5. Under the HIPAA Enforcement Rule, which factor can INCREASE the civil money penalty tier for a violation?

    Answer: The organization had a prior history of identical violations

    OCR considers prior compliance history as an aggravating factor, which can elevate violations to higher penalty tiers with greater per-violation fines.

  6. Which audit control is specifically required by the HIPAA Security Rule to track activity in information systems containing ePHI?

    Answer: Hardware, software, and procedural mechanisms that record and examine activity

    The Security Rule requires audit controls — mechanisms that record and allow examination of system activity — but allows flexibility in how they are implemented.

  7. An organization's compliance officer wants to prioritize remediation efforts after a risk assessment. Which approach is MOST aligned with HIPAA risk management best practices?

    Answer: Prioritize risks with the highest combination of likelihood and impact

    HIPAA risk management requires prioritizing risks based on their overall level, which combines the probability of occurrence with the magnitude of potential harm.