← All CHP Flashcard Decks

Risk Management & Compliance Audits Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Compliance Audits flashcards as text
  1. A healthcare organization conducts a HIPAA risk assessment using a 5×5 risk matrix. What do the two axes of this matrix typically represent?

    Answer: Likelihood of a threat occurrence and magnitude of potential impact

    A standard risk matrix plots likelihood (probability) against impact (magnitude of harm) to produce a composite risk level for each identified threat-vulnerability pair.

  2. Which of the following represents a 'physical safeguard' that an auditor would evaluate during a HIPAA Security Rule compliance review?

    Answer: Facility access controls and workstation use policies

    Physical safeguards include facility access controls, workstation use and security policies, and device and media controls that protect the physical environment where ePHI is stored.

  3. An organization's risk management plan documents that certain risks will be 'transferred.' In HIPAA compliance, what is the most common mechanism for risk transfer?

    Answer: Purchasing cyber liability insurance and executing business associate agreements

    Risk transfer shifts financial or operational responsibility to a third party, most commonly through cyber insurance policies and contractually binding BA agreements.

  4. During a HIPAA audit, an auditor reviews workforce training records. Which finding would be MOST concerning?

    Answer: New hires received privacy training six months after their start date

    HIPAA requires that workforce members receive privacy training within a reasonable period of joining the organization; a six-month delay indicates a systematic compliance gap.

  5. Which scenario demonstrates appropriate use of a HIPAA 'contingency plan' as evaluated in a compliance audit?

    Answer: Documented data backup, disaster recovery, and emergency mode operation procedures for ePHI systems

    The Security Rule's contingency plan standard requires covered entities to establish data backup plans, disaster recovery plans, and emergency mode operation procedures.

  6. A covered entity's compliance program includes quarterly vulnerability scans and annual penetration tests. How does this relate to HIPAA risk management?

    Answer: These are technical tools that identify vulnerabilities, which must then feed into the broader risk analysis process

    Vulnerability scans and penetration tests identify technical weaknesses, but their findings must be incorporated into the organization's overall risk analysis and remediation process.

  7. When OCR selects covered entities for desk audits under the HIPAA Audit Program, what is the PRIMARY document they typically request first?

    Answer: Current risk analysis and risk management documentation

    OCR's audit protocol consistently prioritizes review of the risk analysis and risk management plan as foundational evidence of Security Rule compliance.