CHPS Certified in Healthcare Privacy and Security 4 — Questions and Answers
Question 1: Under the HITECH Act, which entities became directly liable for compliance with certain HIPAA Privacy and Security Rule provisions?
- Business associates (Correct answer)
- Covered entities only
- State health departments
- Health information exchanges
Correct answer: Business associates
The HITECH Act extended direct liability for HIPAA compliance to business associates, making them independently subject to enforcement.
Question 2: A hospital's Security Officer is conducting a risk analysis. Which NIST document provides the most comprehensive guidance for conducting a risk assessment?
- NIST SP 800-30 (Correct answer)
- NIST SP 800-66
- NIST SP 800-53
- NIST SP 800-122
Correct answer: NIST SP 800-30
NIST SP 800-30 is the Guide for Conducting Risk Assessments and provides a structured framework for identifying and evaluating information security risks.
Question 3: What is the goal of 'de-identification' of PHI under HIPAA?
- To remove identifiers so the information cannot reasonably identify an individual (Correct answer)
- To encrypt PHI so only authorized users can read it
- To anonymize only the patient's name and date of birth
- To convert PHI into a limited data set for research
Correct answer: To remove identifiers so the information cannot reasonably identify an individual
De-identification removes or obscures the 18 HIPAA-specified identifiers so that the remaining data cannot reasonably be used to identify an individual.
Question 4: Which of the following is a required implementation specification under the HIPAA Security Rule's Administrative Safeguards?
- Workforce training and management (Correct answer)
- Facility access controls
- Workstation security
- Encryption of data at rest
Correct answer: Workforce training and management
Workforce training and management, including security awareness training, is a required implementation specification within the Administrative Safeguards of the HIPAA Security Rule.
Question 5: A covered entity discloses PHI to a public health authority to prevent the spread of disease. This is an example of:
- A permitted disclosure without patient authorization (Correct answer)
- A required disclosure mandated by HIPAA
- A breach requiring notification
- A violation of the minimum necessary standard
Correct answer: A permitted disclosure without patient authorization
HIPAA permits disclosures of PHI to public health authorities for activities such as disease surveillance, investigation, and intervention without requiring patient authorization.
Question 6: Which concept in information security ensures that data has not been altered or destroyed in an unauthorized manner?
- Integrity (Correct answer)
- Confidentiality
- Availability
- Authenticity
Correct answer: Integrity
Integrity is the security property that ensures information is accurate, complete, and has not been tampered with by unauthorized parties.
Question 7: An employee repeatedly accesses the medical records of a celebrity patient out of curiosity without a treatment, payment, or operations need. This is best described as:
- Snooping — an internal privacy violation (Correct answer)
- An incidental disclosure
- A permissible use for health care operations
- An authorized disclosure under the Privacy Rule
Correct answer: Snooping — an internal privacy violation
Accessing PHI without a permissible purpose (such as treatment, payment, or operations) constitutes a privacy violation commonly called snooping or workforce misconduct.
Under the HITECH Act, which entities became directly liable for compliance with certain HIPAA Privacy and Security Rule provisions?