CHP Administrative, Physical & Technical Safeguards 2 โ Questions and Answers
Question 1: Under the HIPAA Security Rule, which of the following is an example of an administrative safeguard?
- Installing firewall software on servers
- Conducting a periodic security risk analysis (Correct answer)
- Using badge access controls for server rooms
- Encrypting data transmitted over public networks
Correct answer: Conducting a periodic security risk analysis
A security risk analysis is an administrative safeguard because it involves policies and procedures for managing workforce behavior and security management processes.
Question 2: A covered entity must implement a contingency plan as part of its administrative safeguards. Which element is NOT required by the HIPAA Security Rule contingency plan standard?
- Data backup plan
- Disaster recovery plan
- Off-site data replication schedule (Correct answer)
- Emergency mode operation plan
Correct answer: Off-site data replication schedule
The Security Rule requires a data backup plan, disaster recovery plan, and emergency mode operation plan, but does not specifically mandate an off-site data replication schedule.
Question 3: What is the primary purpose of the HIPAA Security Rule's workforce security standard?
- To ensure all employees receive the same level of access to ePHI
- To implement procedures for authorizing and supervising workforce members who work with ePHI (Correct answer)
- To require background checks for all healthcare workers
- To establish salary bands for security personnel
Correct answer: To implement procedures for authorizing and supervising workforce members who work with ePHI
The workforce security standard requires covered entities to implement procedures to ensure workforce members have appropriate access to ePHI and to prevent unauthorized access.
Question 4: A hospital's security officer discovers that a terminated employee's system access was not revoked for 10 days after termination. Which administrative safeguard was violated?
- Security awareness training
- Access control management
- Workforce clearance procedure
- Termination procedures under workforce security (Correct answer)
Correct answer: Termination procedures under workforce security
Termination procedures are an addressable implementation specification under workforce security that require prompt revocation of access when employment ends.
Question 5: Under HIPAA administrative safeguards, how often must a covered entity update its security risk analysis?
- Annually without exception
- Every three years
- Periodically and when environmental or operational changes occur (Correct answer)
- Only when a breach occurs
Correct answer: Periodically and when environmental or operational changes occur
The Security Rule requires the risk analysis to be performed periodically and whenever there are changes to the environment or operations that could affect ePHI security.
Question 6: Which scenario best demonstrates compliance with HIPAA's information access management standard?
- All clinical staff share a single login to speed up workflow
- Access to ePHI is granted based on each employee's job role and minimum necessary need (Correct answer)
- Administrators can access all ePHI to facilitate cross-departmental coordination
- Patients can access other patients' records to review community health data
Correct answer: Access to ePHI is granted based on each employee's job role and minimum necessary need
Information access management requires granting ePHI access based on job roles and the minimum necessary standard to limit exposure.
Question 7: A covered entity's security awareness and training program is considered which type of HIPAA safeguard?
- Technical safeguard
- Physical safeguard
- Administrative safeguard (Correct answer)
- Hybrid safeguard
Correct answer: Administrative safeguard
Security awareness and training is explicitly listed as a standard under administrative safeguards in the HIPAA Security Rule at 45 CFR ยง 164.308(a)(5).
Under the HIPAA Security Rule, which of the following is an example of an administrative safeguard?