CHPS Certified in Healthcare Privacy and Security 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered a 'hybrid entity'?
- An organization that performs both covered and non-covered functions (Correct answer)
- A hospital that operates across multiple states
- A business associate that also acts as a covered entity
- An entity that uses both paper and electronic health records
Correct answer: An organization that performs both covered and non-covered functions
A hybrid entity is an organization that performs both HIPAA-covered healthcare functions and non-covered functions and has designated its health care components accordingly.
Question 2: Which NIST framework publication provides guidance specifically for protecting health information in cybersecurity programs?
- NIST SP 800-66 (Correct answer)
- NIST SP 800-53
- NIST SP 800-171
- NIST SP 800-37
Correct answer: NIST SP 800-66
NIST SP 800-66 is the resource guide for implementing the HIPAA Security Rule and provides practical guidance for healthcare organizations.
Question 3: A patient requests an amendment to their medical record because they believe information is incorrect. Under HIPAA, the covered entity may deny the request if:
- The record was not created by the covered entity (Correct answer)
- The patient has previously requested amendments
- The record is older than seven years
- The information is stored in an EHR system
Correct answer: The record was not created by the covered entity
A covered entity may deny an amendment request if the PHI was not created by that entity, among other permissible reasons.
Question 4: What is the primary purpose of a Data Use Agreement (DUA) under HIPAA?
- To permit use of a limited data set by a recipient for specific purposes (Correct answer)
- To authorize a business associate to access all PHI
- To replace the need for patient authorization for research
- To establish penalties for unauthorized disclosure
Correct answer: To permit use of a limited data set by a recipient for specific purposes
A DUA is required when a covered entity shares a limited data set (with most direct identifiers removed) with a recipient for research, public health, or health care operations.
Question 5: Under the HIPAA Breach Notification Rule, what is the maximum number of days a covered entity has to notify affected individuals of a breach?
- 60 days (Correct answer)
- 30 days
- 90 days
- 45 days
Correct answer: 60 days
Covered entities must notify affected individuals of a breach without unreasonable delay and no later than 60 calendar days after discovery.
Question 6: Which of the following access control models is most commonly recommended for healthcare environments to enforce least privilege?
- Role-Based Access Control (RBAC) (Correct answer)
- Mandatory Access Control (MAC)
- Discretionary Access Control (DAC)
- Rule-Based Access Control
Correct answer: Role-Based Access Control (RBAC)
RBAC grants access based on a user's job role, which aligns well with the least-privilege principle in healthcare settings.
Question 7: A covered entity discovers a breach affecting 600 residents of a single state. In addition to notifying individuals, the entity must:
- Notify the Secretary of HHS within 60 days and notify prominent media outlets in the state (Correct answer)
- Only notify the Secretary of HHS within 60 days
- Notify law enforcement and the state Attorney General
- Post a notice on its website for 90 days
Correct answer: Notify the Secretary of HHS within 60 days and notify prominent media outlets in the state
For breaches affecting more than 500 residents of a state or jurisdiction, the covered entity must notify HHS and prominent media outlets in that state within 60 days.
Under HIPAA, which of the following is considered a 'hybrid entity'?