CHP Risk Management & Compliance Audits 2 — Questions and Answers
Question 1: During a HIPAA compliance audit, what is the PRIMARY purpose of reviewing an organization's Notice of Privacy Practices (NPP)?
- To verify patients receive required disclosures about PHI use (Correct answer)
- To assess the organization's revenue cycle management
- To evaluate the physical security of server rooms
- To confirm employee background check procedures
Correct answer: To verify patients receive required disclosures about PHI use
The NPP must inform patients how their PHI may be used and disclosed, and auditors verify it meets all required content elements under the Privacy Rule.
Question 2: Which of the following BEST describes a 'gap analysis' in the context of HIPAA risk management?
- A financial audit comparing budgeted versus actual security spending
- A comparison of current compliance posture against required standards to identify deficiencies (Correct answer)
- An assessment of network bandwidth utilization
- A review of employee turnover rates in the IT department
Correct answer: A comparison of current compliance posture against required standards to identify deficiencies
A gap analysis identifies where an organization's current controls fall short of HIPAA requirements, forming the foundation for a remediation plan.
Question 3: Under HIPAA, which type of risk assessment methodology involves assigning numerical probability and impact scores to identified threats?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Residual risk assessment
- Inherent risk assessment
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses numerical values to calculate risk levels, enabling organizations to prioritize remediation based on measurable scores.
Question 4: A covered entity discovers that a workforce member has been accessing patient records without a legitimate work reason for six months. What HIPAA violation does this most directly represent?
- Breach of the Minimum Necessary standard (Correct answer)
- Failure to implement audit controls
- Violation of the Security Rule's encryption requirement
- Non-compliance with the Breach Notification Rule timeline
Correct answer: Breach of the Minimum Necessary standard
HIPAA's Minimum Necessary standard requires workforce members to access only the PHI needed to perform their job functions.
Question 5: When conducting an internal HIPAA audit, which document serves as the authoritative baseline for evaluating administrative safeguard compliance?
- The organization's strategic business plan
- The HIPAA Security Rule (45 CFR Part 164, Subpart C) (Correct answer)
- The Joint Commission accreditation standards
- The organization's employee handbook
Correct answer: The HIPAA Security Rule (45 CFR Part 164, Subpart C)
The HIPAA Security Rule codified at 45 CFR Part 164, Subpart C, establishes the required and addressable administrative safeguard standards.
Question 6: Which corrective action plan (CAP) component is MOST critical following an OCR investigation finding of non-compliance?
- A public statement acknowledging the violation
- Specific milestones and timelines for achieving compliance (Correct answer)
- Termination of all employees involved in the incident
- Immediate shutdown of affected systems
Correct answer: Specific milestones and timelines for achieving compliance
OCR requires CAPs to include specific, measurable milestones and deadlines so that progress toward full compliance can be monitored and verified.
Question 7: A business associate fails to report a security incident to the covered entity within a reasonable timeframe. What is the covered entity's BEST immediate response?
- Immediately terminate the business associate agreement
- Assess whether the incident constitutes a reportable breach and document the BA's notification failure (Correct answer)
- Report the business associate directly to the FBI
- Issue a press release informing affected patients
Correct answer: Assess whether the incident constitutes a reportable breach and document the BA's notification failure
The covered entity must first determine if a breach occurred and document the BA's failure, as both the breach assessment and the BA's non-compliance require separate remediation.
During a HIPAA compliance audit, what is the PRIMARY purpose of reviewing an organization's Notice of Privacy Practices (NPP)?