CHP Safety & Infection Control 2 — Questions and Answers
Question 1: Under HIPAA, which entity is primarily responsible for establishing physical safeguards to prevent unauthorized access to areas where PHI is stored or processed?
- The U.S. Department of Health and Human Services
- The covered entity or business associate (Correct answer)
- The local health department
- The National Institute of Standards and Technology
Correct answer: The covered entity or business associate
HIPAA's Security Rule requires covered entities and business associates to implement physical safeguards to protect electronic PHI from unauthorized access.
Question 2: A healthcare worker suspects a colleague is not following proper hand hygiene protocols before accessing workstations containing ePHI. What is the BEST first step?
- Immediately report the colleague to the state medical board
- Document the behavior and report it to the Privacy or Security Officer (Correct answer)
- Ignore it since hand hygiene is an infection control matter, not a HIPAA matter
- Confront the colleague publicly to deter others
Correct answer: Document the behavior and report it to the Privacy or Security Officer
Workforce members should report potential policy violations to the Privacy or Security Officer, who can investigate and address the issue appropriately.
Question 3: Which type of facility control helps prevent contamination of PHI-containing systems in a clinical environment by limiting access to clean versus dirty zones?
- Logical access controls
- Physical separation or zoning protocols (Correct answer)
- Encryption at rest
- Audit log reviews
Correct answer: Physical separation or zoning protocols
Physical separation of clean and dirty zones is an infection control and safety measure that also supports HIPAA physical safeguard requirements by limiting unauthorized access.
Question 4: A hospital is implementing a new HIPAA-compliant workstation policy in isolation rooms used for infectious patients. Which measure BEST addresses both infection control and HIPAA security?
- Allow staff to use personal mobile devices to avoid touching shared equipment
- Use dedicated, easily disinfectable workstations with automatic screen lock and session timeout (Correct answer)
- Remove all workstations from isolation rooms to reduce contamination risk
- Store all PHI on paper charts kept outside the isolation room
Correct answer: Use dedicated, easily disinfectable workstations with automatic screen lock and session timeout
Dedicated, disinfectable workstations with automatic screen lock and session timeout address both infection control (cleanable surfaces) and HIPAA security (access controls).
Question 5: Which HIPAA Security Rule standard specifically requires covered entities to protect against unauthorized physical access to systems storing ePHI?
- Technical Safeguards — Access Control
- Physical Safeguards — Facility Access Controls (Correct answer)
- Administrative Safeguards — Workforce Training
- Organizational Requirements — Business Associate Contracts
Correct answer: Physical Safeguards — Facility Access Controls
The Physical Safeguards — Facility Access Controls standard requires covered entities to implement policies to limit physical access to electronic information systems while ensuring authorized access.
Question 6: In a healthcare setting, shared keyboards and touchscreens used to access ePHI are routinely disinfected. From a HIPAA perspective, why is this practice also relevant?
- HIPAA mandates specific disinfection schedules for all medical equipment
- Contaminated surfaces can harbor pathogens that spread between users, potentially exposing PHI through unclean hands (Correct answer)
- HIPAA requires all input devices to be replaced monthly to ensure hygiene
- Disinfection schedules must be reported annually to HHS
Correct answer: Contaminated surfaces can harbor pathogens that spread between users, potentially exposing PHI through unclean hands
Infection control practices like disinfecting shared input devices reduce cross-contamination risks and support the integrity of access controls by promoting safe, clean system use.
Question 7: A business associate agreement (BAA) is being negotiated with a medical waste disposal company that handles documents containing PHI. Which element is MOST critical to include regarding infection and safety controls?
- A requirement that waste workers obtain HIPAA certification
- Provisions ensuring PHI is destroyed in a manner that is both sanitary and renders it unreadable and unrecoverable (Correct answer)
- A clause allowing the covered entity to inspect the vendor's facilities monthly
- A requirement for the vendor to report all workplace injuries to HHS
Correct answer: Provisions ensuring PHI is destroyed in a manner that is both sanitary and renders it unreadable and unrecoverable
The BAA must ensure PHI destruction methods are both safe (sanitary) and compliant with HIPAA's requirement that PHI be rendered unreadable and unrecoverable.
Under HIPAA, which entity is primarily responsible for establishing physical safeguards to prevent unauthorized access to areas where PHI is stored or processed?