CHPS Healthcare Information Security Controls 1 — Questions and Answers
Question 1: Under the HIPAA Security Rule, which of the following is classified as an 'Addressable' implementation specification?
- Unique user identification
- Emergency access procedure
- Automatic logoff (Correct answer)
- Audit controls
Correct answer: Automatic logoff
Automatic logoff is an Addressable specification under the Access Control standard, meaning entities must implement it if reasonable and appropriate or document why an equivalent measure was chosen.
Question 2: Which HIPAA Security Rule standard requires covered entities to implement policies to prevent, detect, contain, and correct security violations?
- Workforce Training and Awareness
- Security Incident Procedures
- Security Management Process (Correct answer)
- Evaluation
Correct answer: Security Management Process
The Security Management Process standard (45 CFR §164.308(a)(1)) is the overarching standard requiring risk analysis, risk management, sanction policy, and activity review.
Question 3: What is the primary purpose of a risk analysis under the HIPAA Security Rule?
- To document all workforce members with access to ePHI
- To identify and assess threats, vulnerabilities, and risks to ePHI confidentiality, integrity, and availability (Correct answer)
- To create an audit trail for all ePHI access events
- To validate encryption key management procedures
Correct answer: To identify and assess threats, vulnerabilities, and risks to ePHI confidentiality, integrity, and availability
A risk analysis identifies and assesses potential threats and vulnerabilities to ePHI to determine the likelihood and impact of security incidents.
Question 4: Under the HIPAA Security Rule, which safeguard category includes workstation use policies and facility access controls?
- Administrative Safeguards
- Technical Safeguards
- Physical Safeguards (Correct answer)
- Organizational Safeguards
Correct answer: Physical Safeguards
Physical Safeguards govern physical access to facilities and workstations, including facility access controls, workstation use policies, and device and media controls.
Question 5: A healthcare organization discovers that an employee's workstation has been accessed by an unauthorized user. According to the HIPAA Security Rule, this should be documented under which process?
- Workforce Clearance Procedure
- Security Incident Procedures (Correct answer)
- Information Access Management
- Contingency Plan
Correct answer: Security Incident Procedures
Security Incident Procedures require covered entities to document and respond to suspected or known security incidents, including unauthorized access events.
Question 6: Which of the following HIPAA Security Rule requirements addresses the need for a covered entity to restore ePHI data after a disaster?
- Disaster Recovery Plan (Correct answer)
- Emergency Mode Operation Plan
- Data Backup Plan
- Testing and Revision Procedures
Correct answer: Disaster Recovery Plan
The Disaster Recovery Plan implementation specification (45 CFR §164.308(a)(7)(ii)(B)) requires procedures to restore lost data in the event of an emergency or disaster.
Under the HIPAA Security Rule, which of the following is classified as an 'Addressable' implementation specification?