CHP Equipment Operation & Maintenance 2 — Questions and Answers
Question 1: Before disposing of a photocopier that processed PHI, a covered entity must:
- Return it to the manufacturer for destruction
- Sanitize or destroy the internal hard drive to prevent PHI exposure (Correct answer)
- Document the disposal date in the equipment log only
- Obtain written permission from affected patients
Correct answer: Sanitize or destroy the internal hard drive to prevent PHI exposure
Modern photocopiers store images on internal hard drives, which must be sanitized or physically destroyed before disposal to prevent unauthorized PHI disclosure.
Question 2: Which HIPAA Security Rule standard directly requires covered entities to control physical access to workstations that access ePHI?
- Audit Controls (§164.312(b))
- Workstation Security (§164.310(c)) (Correct answer)
- Transmission Security (§164.312(e)(1))
- Access Control (§164.312(a)(1))
Correct answer: Workstation Security (§164.310(c))
The Workstation Security standard (§164.310(c)) specifically requires physical safeguards for workstations that access ePHI, including positioning, screen locks, and restricted access.
Question 3: A third-party technician needs to repair a server containing ePHI. What must be in place before granting access?
- A signed non-disclosure agreement with the technician
- A Business Associate Agreement (BAA) with the vendor (Correct answer)
- A HIPAA training certificate from the technician
- Approval from the state health department
Correct answer: A Business Associate Agreement (BAA) with the vendor
Any vendor whose work may expose them to ePHI must have a BAA with the covered entity before being granted access, as required by the HIPAA Privacy and Security Rules.
Question 4: An organization is retiring old laptops used by clinical staff. Which media sanitization method is most appropriate for laptops with sensitive ePHI?
- Deleting all user accounts on the device
- Performing a factory reset using the OS recovery partition
- Cryptographic erasure or physical destruction of storage media (Correct answer)
- Overwriting the recycle bin and emptying it permanently
Correct answer: Cryptographic erasure or physical destruction of storage media
NIST SP 800-88 guidelines recommend cryptographic erasure or physical destruction to ensure ePHI is unrecoverable from retired media.
Question 5: Under HIPAA, which entity is responsible for ensuring that medical equipment used under a maintenance contract adequately protects ePHI?
- The equipment manufacturer exclusively
- The FDA medical device division
- The covered entity, through proper BAAs and oversight of business associates (Correct answer)
- The maintenance contractor, since they own the liability
Correct answer: The covered entity, through proper BAAs and oversight of business associates
Covered entities remain responsible for ePHI protection and must ensure maintenance contractors are bound by BAAs and comply with applicable HIPAA Security Rule safeguards.
Question 6: A hospital's MRI machine logs patient scan data directly to a networked drive. Which Security Rule implementation specification best governs activity monitoring for this device?
- Contingency Plan
- Audit Controls (§164.312(b)) (Correct answer)
- Business Associate Contracts
- Device and Media Controls
Correct answer: Audit Controls (§164.312(b))
Audit Controls (§164.312(b)) require hardware, software, and procedural mechanisms to record and examine activity in information systems that contain or use ePHI.
Question 7: When a covered entity loans a laptop containing ePHI to a traveling clinician, which safeguard is MOST critical to implement?
- Color-coded asset tags
- Full-disk encryption (Correct answer)
- A printed copy of the HIPAA Privacy Notice
- Manual log-in/log-out tracking sheets
Correct answer: Full-disk encryption
Full-disk encryption ensures that if the device is lost or stolen, ePHI cannot be accessed without the decryption key, satisfying the Security Rule's encryption addressable specification.
Before disposing of a photocopier that processed PHI, a covered entity must: