CHPS Certified in Healthcare Privacy and Security MCQ 3 — Questions and Answers
Question 1: A healthcare organization shares ePHI with a cloud storage vendor. Under HIPAA, the vendor is BEST classified as a:
- Covered entity
- Business associate (Correct answer)
- Hybrid entity
- Conduit exception provider
Correct answer: Business associate
A cloud vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate and must sign a Business Associate Agreement (BAA).
Question 2: The HIPAA Breach Notification Rule requires covered entities to notify affected individuals of an unsecured PHI breach within:
- 30 days of discovery
- 45 days of discovery
- 60 days of discovery (Correct answer)
- 72 hours of discovery
Correct answer: 60 days of discovery
Covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach.
Question 3: Which cryptographic control renders ePHI unusable, unreadable, or indecipherable to unauthorized individuals and can exempt a breach from notification requirements?
- Hashing
- Steganography
- NIST-compliant encryption (Correct answer)
- Tokenization
Correct answer: NIST-compliant encryption
NIST-compliant encryption (following HHS guidance referencing NIST SP 800-111 for data at rest) renders PHI unreadable and qualifies as a safe harbor under the Breach Notification Rule.
Question 4: An organization implements automatic session timeouts for workstations accessing ePHI. This is an example of which HIPAA Security Rule safeguard category?
- Administrative safeguard
- Physical safeguard
- Technical safeguard (Correct answer)
- Organizational requirement
Correct answer: Technical safeguard
Automatic logoff is explicitly listed as an addressable implementation specification under the Access Control technical safeguard in the HIPAA Security Rule.
Question 5: A patient requests an amendment to their medical record because they believe it contains an error. The covered entity denies the request. What must the covered entity provide?
- Written denial and the right to submit a statement of disagreement (Correct answer)
- Verbal explanation within 30 days
- Notice to HHS of the denial
- A corrected record regardless of the denial
Correct answer: Written denial and the right to submit a statement of disagreement
When a covered entity denies an amendment request, it must provide a written denial and inform the individual of the right to submit a statement of disagreement to be included in the record.
Question 6: Under the HIPAA minimum necessary standard, which workforce category is EXEMPT from this limitation when accessing PHI?
- Billing staff
- Treating physicians (Correct answer)
- Health plan employees
- Business associates
Correct answer: Treating physicians
The minimum necessary standard does not apply to disclosures to or requests by a healthcare provider for treatment purposes, because free flow of clinical information is essential to patient care.
Question 7: Which governance framework is MOST commonly used in healthcare to align IT security controls with business objectives and regulatory requirements?
- COSO ERM
- COBIT (Correct answer)
- Six Sigma
- ISO 9001
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is widely used in healthcare IT governance to align security controls with organizational objectives and compliance requirements.
A healthcare organization shares ePHI with a cloud storage vendor.
Under HIPAA, the vendor is BEST classified as a: