CHPS Healthcare Information Security Controls 2 โ Questions and Answers
Question 1: Which of the following best describes the concept of 'integrity' in the context of the HIPAA Security Rule?
- Ensuring ePHI is accessible to authorized users when needed
- Protecting ePHI from improper alteration or destruction (Correct answer)
- Restricting ePHI access to only authorized workforce members
- Encrypting ePHI during transmission over open networks
Correct answer: Protecting ePHI from improper alteration or destruction
Integrity under HIPAA Security Rule means that ePHI has not been altered or destroyed in an unauthorized manner, preserving its accuracy and completeness.
Question 2: Under the HIPAA Security Rule, what must a covered entity do when it terminates a workforce member's employment?
- Only notify the Privacy Officer of the termination
- Implement a termination procedure that includes removal of system access (Correct answer)
- Archive the employee's ePHI access logs for 6 years
- Submit a workforce change notification to HHS
Correct answer: Implement a termination procedure that includes removal of system access
Workforce Security standards require covered entities to implement termination procedures including removing system access to prevent unauthorized use of ePHI post-employment.
Question 3: A healthcare organization uses a cloud-based EHR. Under HIPAA, which type of agreement must be in place with the cloud provider?
- Service Level Agreement (SLA)
- Business Associate Agreement (BAA) (Correct answer)
- Data Governance Agreement (DGA)
- Non-Disclosure Agreement (NDA)
Correct answer: Business Associate Agreement (BAA)
Cloud providers that create, receive, maintain, or transmit ePHI on behalf of a covered entity are business associates and must have a BAA in place.
Question 4: Under the HIPAA Security Rule, 'audit controls' are best described as:
- Policies governing who may access ePHI workstations
- Hardware, software, or procedural mechanisms that record and examine activity in systems containing ePHI (Correct answer)
- Encryption standards applied to ePHI in transit
- Physical locks and badges controlling server room entry
Correct answer: Hardware, software, or procedural mechanisms that record and examine activity in systems containing ePHI
Audit controls (45 CFR ยง164.312(b)) require mechanisms to record and examine access and activity in information systems that contain or use ePHI.
Question 5: Which of the following encryption standards is generally accepted for protecting ePHI in transit under HIPAA Security Rule guidance?
- SSL 2.0
- TLS 1.0
- TLS 1.2 or higher (Correct answer)
- MD5 hashing
Correct answer: TLS 1.2 or higher
NIST and HHS guidance recommend TLS 1.2 or higher for encrypting ePHI in transit, as older protocols have known vulnerabilities.
Question 6: What is the key difference between the HIPAA Privacy Rule and the HIPAA Security Rule?
- The Privacy Rule applies only to hospitals; the Security Rule applies to all covered entities
- The Privacy Rule covers all PHI in any form; the Security Rule covers only electronic PHI (ePHI) (Correct answer)
- The Privacy Rule is voluntary; the Security Rule is mandatory
- The Privacy Rule is enforced by ONC; the Security Rule is enforced by OCR
Correct answer: The Privacy Rule covers all PHI in any form; the Security Rule covers only electronic PHI (ePHI)
The Privacy Rule applies to protected health information in all forms (oral, paper, electronic), while the Security Rule specifically addresses electronic PHI (ePHI).
Which of the following best describes the concept of 'integrity' in the context of the HIPAA Security Rule?