CHP Risk Management & Compliance Audits 3 — Questions and Answers
Question 1: Which HIPAA concept requires organizations to implement security measures that are reasonable and appropriate based on their size, complexity, and capabilities?
- Scalability principle
- Flexibility and scalability standard (Correct answer)
- Safe harbor provision
- Risk-based approach
Correct answer: Flexibility and scalability standard
HIPAA's flexibility and scalability standard acknowledges that one-size-fits-all solutions are impractical, allowing organizations to tailor controls to their specific circumstances.
Question 2: During a risk analysis, an organization identifies that unencrypted laptops are used by field nurses. Which risk treatment option involves implementing full-disk encryption?
- Risk avoidance
- Risk transfer
- Risk mitigation (Correct answer)
- Risk acceptance
Correct answer: Risk mitigation
Risk mitigation reduces the likelihood or impact of a threat by implementing controls such as encryption to protect PHI on mobile devices.
Question 3: Which of the following is an example of 'residual risk' in HIPAA risk management?
- The risk that exists before any controls are applied
- The risk that remains after implementing security controls (Correct answer)
- The risk transferred to a business associate via contract
- The risk identified but not yet evaluated
Correct answer: The risk that remains after implementing security controls
Residual risk is the remaining exposure after controls have been applied; organizations must decide whether this level is acceptable or requires additional safeguards.
Question 4: A HIPAA audit reveals an organization has not updated its risk assessment in four years. Why is this problematic under the Security Rule?
- The Security Rule mandates annual risk assessments on a fixed calendar schedule
- Risk assessments must reflect current threats, vulnerabilities, and operational changes (Correct answer)
- Outdated assessments automatically trigger mandatory OCR reporting
- Only business associates are required to maintain current risk assessments
Correct answer: Risk assessments must reflect current threats, vulnerabilities, and operational changes
The Security Rule requires ongoing, not one-time, risk analysis that accounts for environmental and operational changes that introduce new vulnerabilities.
Question 5: Under the HIPAA Enforcement Rule, which factor can INCREASE the civil money penalty tier for a violation?
- The organization self-reported the violation within 30 days
- The organization had a prior history of identical violations (Correct answer)
- The violation affected fewer than 10 individuals
- The organization voluntarily corrected the issue before OCR involvement
Correct answer: The organization had a prior history of identical violations
OCR considers prior compliance history as an aggravating factor, which can elevate violations to higher penalty tiers with greater per-violation fines.
Question 6: Which audit control is specifically required by the HIPAA Security Rule to track activity in information systems containing ePHI?
- Mandatory video surveillance of server rooms
- Hardware, software, and procedural mechanisms that record and examine activity (Correct answer)
- Daily manual review of all user login attempts
- Biometric authentication for every ePHI access event
Correct answer: Hardware, software, and procedural mechanisms that record and examine activity
The Security Rule requires audit controls — mechanisms that record and allow examination of system activity — but allows flexibility in how they are implemented.
Question 7: An organization's compliance officer wants to prioritize remediation efforts after a risk assessment. Which approach is MOST aligned with HIPAA risk management best practices?
- Address the least expensive fixes first to maximize the number of issues resolved
- Prioritize risks with the highest combination of likelihood and impact (Correct answer)
- Fix all technical vulnerabilities before addressing administrative gaps
- Remediate issues in the order they were discovered during the assessment
Correct answer: Prioritize risks with the highest combination of likelihood and impact
HIPAA risk management requires prioritizing risks based on their overall level, which combines the probability of occurrence with the magnitude of potential harm.
Which HIPAA concept requires organizations to implement security measures that are reasonable and appropriate based on their size, complexity, and capabilities?