CHPS Certified in Healthcare Privacy and Security 3 — Questions and Answers
Question 1: Which HIPAA standard requires covered entities to have written contracts with business associates before sharing PHI?
- Business Associate Agreement (BAA) (Correct answer)
- Data Sharing Protocol (DSP)
- Memorandum of Understanding (MOU)
- Privacy Impact Assessment (PIA)
Correct answer: Business Associate Agreement (BAA)
A Business Associate Agreement (BAA) is the HIPAA-required written contract that establishes the permitted uses and disclosures of PHI by a business associate.
Question 2: Under the HIPAA minimum necessary standard, which of the following disclosures is exempt?
- Disclosures to the individual who is the subject of the PHI (Correct answer)
- Disclosures for payment purposes
- Disclosures to business associates
- Disclosures for health care operations
Correct answer: Disclosures to the individual who is the subject of the PHI
The minimum necessary standard does not apply to disclosures made to the individual who is the subject of the PHI.
Question 3: What is 'shoulder surfing' in the context of healthcare information security?
- Observing someone's screen or keyboard to steal credentials or PHI (Correct answer)
- Intercepting wireless network traffic in a clinical setting
- Impersonating a clinician to gain system access
- Redirecting email communications to an unauthorized inbox
Correct answer: Observing someone's screen or keyboard to steal credentials or PHI
Shoulder surfing is a social engineering technique where an attacker physically observes a user's screen or keystrokes to obtain sensitive information.
Question 4: An organization implements full-disk encryption on all laptops. Under HIPAA's Breach Notification Rule, if an encrypted laptop is stolen, the organization should:
- Not report it as a breach if the encryption meets HHS guidance (Correct answer)
- Report it to HHS within 60 days regardless
- Notify affected individuals within 30 days
- Conduct a full risk analysis and report to law enforcement
Correct answer: Not report it as a breach if the encryption meets HHS guidance
Data encrypted in accordance with HHS guidance is considered 'unusable, unreadable, or indecipherable' and therefore its loss does not constitute a reportable breach.
Question 5: Which of the following is an example of a physical safeguard required by the HIPAA Security Rule?
- Workstation use policies and physical access controls to facilities (Correct answer)
- Audit controls and automatic logoff
- Encryption and decryption mechanisms
- User authentication and unique user identification
Correct answer: Workstation use policies and physical access controls to facilities
Physical safeguards include facility access controls, workstation use policies, and device and media controls to protect electronic PHI from physical threats.
Question 6: A healthcare organization wants to use patient data for a research study. Under HIPAA, which option does NOT require individual patient authorization?
- Research using a limited data set with a Data Use Agreement (Correct answer)
- Research involving direct contact with patients
- Research that uses fully identifiable PHI
- Research that shares data with external commercial entities
Correct answer: Research using a limited data set with a Data Use Agreement
Using a limited data set (with most direct identifiers stripped) under a DUA is one pathway that doesn't require individual patient authorization for research.
Question 7: Which term describes the HIPAA concept that limits PHI use to the amount needed to accomplish the intended purpose?
- Minimum necessary (Correct answer)
- Need to know
- Least privilege
- Data minimization
Correct answer: Minimum necessary
The HIPAA minimum necessary standard requires that covered entities make reasonable efforts to limit PHI use, disclosure, and requests to the minimum needed for the purpose.
Which HIPAA standard requires covered entities to have written contracts with business associates before sharing PHI?