CHP Equipment Operation & Maintenance 3 โ Questions and Answers
Question 1: A nurse's personal smartphone is used to photograph wound progress for the patient record. Under HIPAA, this practice requires:
- No policy because smartphones are not covered devices
- A formal BYOD policy that addresses ePHI handling, encryption, and remote wipe capability (Correct answer)
- Only verbal authorization from the supervising physician
- Patient consent forms filed in the chart
Correct answer: A formal BYOD policy that addresses ePHI handling, encryption, and remote wipe capability
BYOD (Bring Your Own Device) programs must include formal policies covering ePHI safeguards such as encryption, containerization, and remote wipe to comply with the HIPAA Security Rule.
Question 2: Which feature of a mobile device management (MDM) platform most directly supports HIPAA's requirement for ePHI protection on portable devices?
- App store purchase controls
- Remote wipe capability in case of loss or theft (Correct answer)
- Carrier billing management
- Social media access restrictions
Correct answer: Remote wipe capability in case of loss or theft
Remote wipe allows an organization to erase ePHI from a lost or stolen device, directly addressing the Security Rule's device and media controls requirement.
Question 3: A tablet used for electronic prescribing is left unattended at a nursing station for 20 minutes. Which automatic control would BEST mitigate unauthorized ePHI access?
- Daily password changes
- Automatic logoff after a period of inactivity (Correct answer)
- Assigning the device to a single nurse permanently
- Restricting prescribing to desktop computers only
Correct answer: Automatic logoff after a period of inactivity
Automatic logoff (ยง164.312(a)(2)(iii)) is an addressable implementation specification that prevents unauthorized access when a workstation or device is left unattended.
Question 4: An organization discovers that a vendor-managed infusion pump transmits patient data over an unencrypted Wi-Fi channel. The FIRST step should be:
- Replace all infusion pumps immediately
- Notify the FDA and suspend pump use
- Conduct a risk analysis to assess the likelihood and impact of a breach (Correct answer)
- Issue a press release disclosing the vulnerability
Correct answer: Conduct a risk analysis to assess the likelihood and impact of a breach
A risk analysis is the foundational required step under ยง164.308(a)(1) to evaluate the probability and impact of potential ePHI exposure before deciding on remediation.
Question 5: A practice manager finds an old fax machine that occasionally received PHI now needs decommissioning. Which action is MOST important?
- Donating it to a local school to reduce e-waste
- Clearing stored fax memory and any internal print logs before disposal (Correct answer)
- Placing a 'do not use' sign on the machine
- Filing a breach report with HHS before disposal
Correct answer: Clearing stored fax memory and any internal print logs before disposal
Fax machines with memory must have stored transmissions and internal logs cleared before disposal to prevent unauthorized access to stored PHI, per Device and Media Controls.
Question 6: What does HIPAA's 'Unique User Identification' implementation specification (ยง164.312(a)(2)(i)) require for shared medical equipment?
- Each department must have one shared login credential
- Every user must be assigned and use a unique identifier to track individual access (Correct answer)
- Shared logins are acceptable if password-protected
- Biometric identification must be used for all ePHI access
Correct answer: Every user must be assigned and use a unique identifier to track individual access
Unique User Identification requires that each individual user be assigned a unique ID so that access to ePHI can be tracked and attributed to specific persons.
Question 7: A telehealth platform used on clinic-owned tablets sends video directly through a public internet connection without a BAA in place with the software vendor. This is:
- Acceptable if the sessions are less than 15 minutes
- A HIPAA violation because the vendor is a business associate without a BAA (Correct answer)
- Compliant because video is not considered ePHI
- Acceptable under the HIPAA Safe Harbor provision for small practices
Correct answer: A HIPAA violation because the vendor is a business associate without a BAA
A telehealth software vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate, and a BAA is required before use.
A nurse's personal smartphone is used to photograph wound progress for the patient record.
Under HIPAA, this practice requires: