CHPC Privacy Risk Management Questions and Answers — Questions and Answers
Question 1: A large health system is planning to implement a new enterprise-wide electronic health record (EHR) system. To proactively identify and mitigate potential privacy risks before the system goes live, which of the following tools is MOST appropriate to use?
- A breach risk assessment
- A security risk analysis
- A Privacy Impact Assessment (PIA) (Correct answer)
- A business continuity plan
Correct answer: A Privacy Impact Assessment (PIA)
A Privacy Impact Assessment (PIA) is a systematic process used to identify and mitigate potential privacy risks associated with new projects, systems, or technologies before they are implemented. A security risk analysis focuses on vulnerabilities to ePHI, a breach risk assessment is conducted after an impermissible disclosure occurs, and a business continuity plan addresses operational recovery, not proactive privacy risk identification.
Question 2: A compliance officer is explaining the distinction between HIPAA's Risk Analysis and Risk Management requirements to a new privacy analyst. Which statement BEST summarizes the relationship between these two components?
- Risk Analysis is the process of purchasing insurance to transfer risk, while Risk Management is the process of accepting residual risk.
- Risk Analysis involves implementing security controls, and Risk Management is the process of documenting those controls.
- Risk Analysis and Risk Management are interchangeable terms for the same ongoing process of vulnerability scanning.
- Risk Analysis is the process of identifying and evaluating potential risks and vulnerabilities, whereas Risk Management is the process of implementing measures to reduce those identified risks. (Correct answer)
Correct answer: Risk Analysis is the process of identifying and evaluating potential risks and vulnerabilities, whereas Risk Management is the process of implementing measures to reduce those identified risks.
The HIPAA Security Rule requires two distinct but related actions: risk analysis and risk management. Risk analysis is the 'diagnostic' phase of identifying and evaluating risks to ePHI. Risk management is the subsequent 'treatment' phase, where the organization implements security measures to reduce the identified risks to a reasonable and appropriate level.
Question 3: A hospital employee accidentally faxes a patient's discharge summary, which includes their name, diagnosis, and treatment plan, to a local grocery store instead of the correct post-acute care facility. When conducting the mandatory four-factor breach risk assessment, which factor is most significantly elevated by the recipient being a grocery store?
- The nature and extent of the PHI involved.
- The unauthorized person who received the PHI. (Correct answer)
- Whether the PHI was actually acquired or viewed.
- The extent to which the risk to the PHI has been mitigated.
Correct answer: The unauthorized person who received the PHI.
Under the four-factor breach risk assessment, the identity of the unauthorized recipient is a critical factor. A recipient like a grocery store has no obligation to protect the PHI, increasing the risk of compromise compared to another HIPAA-covered entity that has its own legal and ethical duties to safeguard the information.
Question 4: Which of the following frameworks, while not mandatory for all healthcare organizations, provides a voluntary, risk-based approach with core functions like 'Identify, Protect, Detect, Respond, Recover' that is widely recognized and cross-walked to the HIPAA Security Rule?
- ISO 27001
- HITRUST CSF
- NIST Cybersecurity Framework (CSF) (Correct answer)
- COBIT Framework
Correct answer: NIST Cybersecurity Framework (CSF)
The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) is a voluntary framework that provides a structured, risk-based approach to cybersecurity. Its core functions ('Identify, Protect, Detect, Respond, Recover') are widely adopted in healthcare, and HHS has provided a crosswalk to demonstrate how its use can help support compliance with the HIPAA Security Rule.
Question 5: A privacy officer is performing a breach risk assessment after an unencrypted laptop was stolen from an employee's car. The laptop contained a spreadsheet with the names, medical record numbers, and birth dates of 200 patients. Which of the following, if true, would be the STRONGEST mitigating factor in this assessment?
- The employee immediately reported the theft to the police and the privacy officer.
- The organization has a policy requiring encryption, which the employee violated.
- The laptop was password-protected at the operating system level.
- The laptop was remotely wiped within an hour of the theft, and the wipe was confirmed successful. (Correct answer)
Correct answer: The laptop was remotely wiped within an hour of the theft, and the wipe was confirmed successful.
The fourth factor of a HIPAA breach risk assessment is the extent to which the risk has been mitigated. Successfully and verifiably wiping the device remotely ensures that the data was destroyed and could not be acquired or viewed, which is the most effective mitigation strategy among the choices. While reporting and passwords are good practices, they do not eliminate the risk that the data was accessed like a confirmed remote wipe does.
Question 6: The NIST Privacy Framework is designed to help organizations manage privacy risk. It is distinct from but complementary to cybersecurity frameworks. What is a primary focus of the NIST Privacy Framework?
- Mandating specific encryption standards for data at rest and in transit.
- Exclusively managing risks from unauthorized access by external hackers.
- Managing risks arising from authorized data processing activities, such as collection, use, and disclosure. (Correct answer)
- Certifying that an organization is fully compliant with all state and federal privacy laws.
Correct answer: Managing risks arising from authorized data processing activities, such as collection, use, and disclosure.
The NIST Privacy Framework is a tool for managing privacy risks throughout the entire data lifecycle. A key distinction is its focus on risks arising from authorized data processing (i.e., how data is collected, stored, used, and shared), not just from unauthorized access or security breaches. It helps organizations build patient trust by managing data ethically and in predictable ways.
A large health system is planning to implement a new enterprise-wide electronic health record (EHR) system.
To proactively identify and mitigate potential privacy risks before the system goes live, which of the following tools is MOST appropriate to use?