CHP Documentation & Record Keeping 3 — Questions and Answers
Question 1: Under the HIPAA Security Rule, how long must covered entities retain security-related documentation?
- 2 years
- 4 years
- 6 years from creation or last effective date (Correct answer)
- 10 years
Correct answer: 6 years from creation or last effective date
The HIPAA Security Rule requires that security policies, procedures, and related documentation be retained for 6 years from the date of creation or the date it was last in effect.
Question 2: What must be included in a covered entity's documentation of its risk analysis?
- Only identified threats to ePHI
- The scope, identified threats and vulnerabilities, current controls, likelihood, and impact assessments (Correct answer)
- Budget allocation for security controls only
- A list of all workforce members with ePHI access
Correct answer: The scope, identified threats and vulnerabilities, current controls, likelihood, and impact assessments
A thorough risk analysis must document the scope of the analysis, potential threats and vulnerabilities, existing security controls, and the likelihood and impact of potential risks to ePHI.
Question 3: An organization updates its password policy. What documentation action is required under HIPAA?
- No documentation is required for password policies
- The new policy must be documented and the prior version retained for 6 years (Correct answer)
- The update must be reported to the OCR
- Only the IT department head needs to sign off on the change
Correct answer: The new policy must be documented and the prior version retained for 6 years
Any changes to HIPAA-required policies must be documented, and prior versions must also be retained for the required 6-year period from when they were last in effect.
Question 4: Which of the following is an example of required Security Rule documentation?
- Employee birthday lists
- Facility access logs and audit trails for ePHI systems (Correct answer)
- Marketing campaign records
- Patient financial billing records
Correct answer: Facility access logs and audit trails for ePHI systems
The Security Rule requires documentation of audit logs, access controls, and other safeguards implemented to protect ePHI from unauthorized access.
Question 5: A small physician practice stores its HIPAA documentation on paper. Is this compliant?
- No, HIPAA requires all documentation to be electronic
- Yes, HIPAA documentation may be maintained in written or electronic form (Correct answer)
- No, paper documentation is not legally defensible
- Yes, but only if the practice employs fewer than 10 people
Correct answer: Yes, HIPAA documentation may be maintained in written or electronic form
HIPAA does not mandate a specific format for documentation and permits covered entities to maintain required records in either written or electronic form.
Question 6: What is the purpose of documenting a covered entity's contingency plan?
- To satisfy IRS tax documentation requirements
- To demonstrate preparedness for ePHI access during system emergencies and ensure continuity (Correct answer)
- To provide marketing material for clients
- To comply with state building codes
Correct answer: To demonstrate preparedness for ePHI access during system emergencies and ensure continuity
Documenting the contingency plan under the Security Rule ensures the organization has a tested, retrievable plan for maintaining access to ePHI during system failures, disasters, or emergencies.
Question 7: If a business associate agreement (BAA) is amended, what must the covered entity do with the original BAA?
- Destroy the original immediately to avoid confusion
- Retain the original BAA for 6 years from when it was last in effect (Correct answer)
- Submit the original BAA to HHS for review
- Archive the original BAA with the state health department
Correct answer: Retain the original BAA for 6 years from when it was last in effect
Superseded BAAs must be retained for 6 years from the date they were last in effect, consistent with HIPAA's general documentation retention requirements.
Under the HIPAA Security Rule, how long must covered entities retain security-related documentation?