CHPS Healthcare IT and Security Technologies 1 — Questions and Answers
Question 1: Which technology provides the strongest protection for ePHI stored on a lost or stolen laptop under HIPAA?
- Password-protected BIOS
- Full-disk encryption using FIPS 140-2 validated modules (Correct answer)
- Multi-factor authentication for Windows login
- Remote wipe capability via MDM
Correct answer: Full-disk encryption using FIPS 140-2 validated modules
Full-disk encryption using FIPS 140-2 validated cryptographic modules renders data unreadable on a stolen device and qualifies for HIPAA's encryption safe harbor.
Question 2: In a healthcare EHR environment, which access control model most effectively enforces the Minimum Necessary standard?
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Role-Based Access Control (RBAC) (Correct answer)
- Attribute-Based Access Control (ABAC)
Correct answer: Role-Based Access Control (RBAC)
RBAC restricts ePHI access based on defined job roles, naturally enforcing the Minimum Necessary standard by limiting access to what each role requires.
Question 3: What is a 'break-the-glass' procedure in the context of healthcare IT?
- An emergency protocol for physical access to server rooms during fires
- An audit-logged override mechanism allowing emergency access to restricted PHI when needed for patient care (Correct answer)
- A procedure for destroying PHI media in emergencies
- A policy for escalating cybersecurity incidents to senior management
Correct answer: An audit-logged override mechanism allowing emergency access to restricted PHI when needed for patient care
Break-the-glass is an emergency access override that allows authorized users to access restricted PHI in urgent clinical situations, with all access fully audit-logged.
Question 4: Which healthcare interoperability standard defines the format for electronic exchange of clinical data including medications, allergies, and diagnoses?
- DICOM
- HL7 FHIR (Correct answer)
- X12 EDI
- SNOMED CT
Correct answer: HL7 FHIR
HL7 FHIR (Fast Healthcare Interoperability Resources) is the current standard for healthcare data exchange, enabling structured clinical data sharing between systems.
Question 5: A healthcare organization is evaluating a mobile health (mHealth) app that will access patient ePHI. Under HIPAA, which consideration is MOST critical before deployment?
- Whether the app has been approved by the FDA
- Whether the app vendor has signed a BAA and the app uses appropriate encryption and access controls (Correct answer)
- Whether the app is available on both iOS and Android platforms
- Whether the app has at least 4 stars in the app store
Correct answer: Whether the app vendor has signed a BAA and the app uses appropriate encryption and access controls
Before deploying any mHealth app that accesses ePHI, the vendor must execute a BAA and the app must implement appropriate safeguards including encryption and access controls.
Question 6: Which security control is MOST effective at detecting unauthorized internal access to ePHI by snooping employees?
- Firewall with intrusion prevention system
- User and Entity Behavior Analytics (UEBA) (Correct answer)
- Data Loss Prevention (DLP) system
- Web application firewall (WAF)
Correct answer: User and Entity Behavior Analytics (UEBA)
UEBA establishes behavioral baselines for each user and alerts on anomalous access patterns, making it highly effective at detecting insider threats like snooping.
Which technology provides the strongest protection for ePHI stored on a lost or stolen laptop under HIPAA?