Risk Management & Compliance Audits Flashcards
7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Compliance Audits flashcards as text
Which scenario best illustrates the concept of 'threat' in a HIPAA risk analysis context?
Answer: A ransomware attack targeting healthcare organizations
A threat is a potential danger to PHI, such as a ransomware attack, whereas a vulnerability is a weakness that a threat could exploit.
During a mock HIPAA audit, an assessor requests documentation of the organization's sanction policy. What does this policy MUST address?
Answer: Penalties for workforce members who violate privacy and security policies
The HIPAA Privacy and Security Rules require covered entities to apply appropriate sanctions against workforce members who fail to comply with their privacy and security policies.
A hospital is evaluating whether to accept residual risk after implementing encryption on mobile devices. Who has the authority to formally accept this residual risk?
Answer: Senior leadership or an authorized risk owner within the organization
Risk acceptance must be formally documented and approved by an appropriate organizational authority, typically senior leadership or a designated risk owner.
Which of the following HIPAA audit scenarios would most likely result in the highest civil money penalty tier?
Answer: Willful neglect of HIPAA requirements that was not corrected within the required timeframe
The highest penalty tier applies to violations due to willful neglect that are not corrected, with penalties up to $1.9 million per violation category per year.
What is the primary distinction between a HIPAA 'required' safeguard and an 'addressable' safeguard under the Security Rule?
Answer: Required safeguards must be implemented as written; addressable safeguards allow equivalent alternatives if justified
Addressable safeguards must be implemented, implemented differently, or not implemented with documented justification based on the organization's risk environment.
A compliance audit finds that a covered entity uses a cloud EHR vendor without a signed BAA. What is the IMMEDIATE compliance obligation?
Answer: Execute a BAA retroactively and document the gap
The organization must immediately execute a BAA to come into compliance and document the period of non-compliance, as retroactive agreements are legally recognized remediation steps.
Which HIPAA Security Rule standard specifically requires organizations to guard against unauthorized access to ePHI transmitted over electronic communications networks?
Answer: Transmission security (§164.312(e)(1))
The transmission security standard requires technical security measures to guard against unauthorized access to ePHI being transmitted over electronic communications networks.