CHPS Certified in Healthcare Privacy and Security 5 — Questions and Answers
Question 1: Under HIPAA, what is the 'right of access' that patients have regarding their PHI?
- The right to inspect and obtain a copy of their PHI held in a designated record set (Correct answer)
- The right to access any provider's network system at any time
- The right to demand deletion of all their PHI immediately
- The right to view real-time system audit logs containing their data
Correct answer: The right to inspect and obtain a copy of their PHI held in a designated record set
The HIPAA right of access gives individuals the right to inspect and receive a copy of their PHI maintained in a covered entity's designated record set.
Question 2: Which of the following is the strongest authentication method for protecting access to an EHR system?
- Multi-factor authentication combining a password and a hardware token (Correct answer)
- A complex alphanumeric password changed every 90 days
- Biometric fingerprint scan alone
- Security questions plus a PIN
Correct answer: Multi-factor authentication combining a password and a hardware token
Multi-factor authentication (MFA) combining something you know (password) and something you have (hardware token) provides the strongest protection against unauthorized access.
Question 3: A healthcare organization's contingency plan must include which of the following as a required component under the HIPAA Security Rule?
- A data backup plan (Correct answer)
- A disaster recovery vendor contract
- An off-site storage agreement
- A quarterly disaster drill schedule
Correct answer: A data backup plan
The HIPAA Security Rule requires a data backup plan as a required implementation specification within the contingency plan standard.
Question 4: Which HIPAA penalty tier applies when a covered entity knew of a violation and failed to correct it within 30 days?
- $10,000–$50,000 per violation with a $1.5 million annual cap (Tier 3/4 range) (Correct answer)
- $100–$50,000 per violation with a $25,000 annual cap
- $1,000–$50,000 per violation with a $100,000 annual cap
- No financial penalty — only corrective action plans are required
Correct answer: $10,000–$50,000 per violation with a $1.5 million annual cap (Tier 3/4 range)
Willful neglect violations that are not corrected fall in the highest penalty tiers, ranging from $10,000 to $50,000 per violation with an annual cap of $1.5 million.
Question 5: What distinguishes a 'Notice of Privacy Practices' (NPP) from a patient authorization under HIPAA?
- An NPP informs patients of how PHI may be used; authorization is patient permission for a specific use (Correct answer)
- An NPP is required only for disclosures; authorization covers all uses
- An NPP replaces the need for any patient authorization
- Authorization is required for treatment; NPP is required for billing
Correct answer: An NPP informs patients of how PHI may be used; authorization is patient permission for a specific use
The NPP is a general notice informing patients of their rights and the entity's privacy practices, while an authorization is a specific patient-signed permission for a use or disclosure not otherwise permitted.
Question 6: A healthcare organization implements a policy requiring all portable media containing PHI to be encrypted. Which HIPAA safeguard category does this policy primarily address?
- Technical safeguards (Correct answer)
- Physical safeguards
- Administrative safeguards
- Organizational safeguards
Correct answer: Technical safeguards
Encryption of data on portable media is a technical safeguard, falling under the HIPAA Security Rule's technical safeguards standard for transmission and storage security.
Question 7: Which of the following best describes 'workforce' as defined under HIPAA?
- Employees, volunteers, trainees, and other persons whose work is under the direct control of a covered entity (Correct answer)
- Only full-time and part-time paid employees of a covered entity
- Licensed healthcare professionals employed by the entity
- Contractors and vendors who access PHI under a BAA
Correct answer: Employees, volunteers, trainees, and other persons whose work is under the direct control of a covered entity
HIPAA defines workforce broadly to include employees, volunteers, trainees, and others under the covered entity's direct control, regardless of compensation.
Under HIPAA, what is the 'right of access' that patients have regarding their PHI?