CHPS Certified in Healthcare Privacy and Security MCQ 4 — Questions and Answers
Question 1: A hospital must report a breach affecting 600 individuals. In addition to notifying affected individuals, the covered entity must notify:
- The FBI within 30 days
- Prominent media outlets in the affected state and HHS (Correct answer)
- The state attorney general within 15 days
- Local law enforcement immediately
Correct answer: Prominent media outlets in the affected state and HHS
Breaches affecting more than 500 residents of a state require notification to prominent media outlets in that state and to HHS, in addition to individual notification.
Question 2: Which vulnerability scanning approach tests a system from the perspective of an unauthenticated external attacker without prior knowledge of internal architecture?
- White-box testing
- Gray-box testing
- Black-box testing (Correct answer)
- Crystal-box testing
Correct answer: Black-box testing
Black-box testing simulates an external attacker who has no prior knowledge of the system's internal architecture, testing defenses as an outsider would encounter them.
Question 3: A healthcare organization's contingency plan includes procedures to restore ePHI from backups after a disaster. This is BEST described as which plan component?
- Disaster Recovery Plan (Correct answer)
- Emergency Mode Operation Plan
- Data Backup Plan
- Applications and Data Criticality Analysis
Correct answer: Disaster Recovery Plan
The Disaster Recovery Plan specifically addresses procedures for restoring data and systems to operational status after a disaster, as required by the HIPAA Security Rule contingency plan standard.
Question 4: Which NIST publication provides a framework for improving critical infrastructure cybersecurity and is widely referenced in healthcare security programs?
- NIST SP 800-53
- NIST SP 800-66
- NIST Cybersecurity Framework (CSF) (Correct answer)
- NIST SP 800-30
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) organizes security activities into Identify, Protect, Detect, Respond, and Recover functions and is widely adopted in healthcare as a voluntary risk management framework.
Question 5: An employee emails unencrypted PHI to a personal email account 'just to work from home.' Under HIPAA, this is BEST characterized as:
- A permitted disclosure for healthcare operations
- A potential security incident requiring evaluation (Correct answer)
- An acceptable workforce accommodation
- A minor violation with no reporting requirement
Correct answer: A potential security incident requiring evaluation
Sending unencrypted PHI to an unauthorized external account constitutes a potential security incident that must be evaluated to determine whether a reportable breach occurred.
Question 6: The Health Information Technology for Economic and Clinical Health (HITECH) Act primarily expanded HIPAA by:
- Creating a new federal privacy agency
- Strengthening enforcement and extending obligations to business associates (Correct answer)
- Eliminating the need for Notice of Privacy Practices
- Replacing state privacy laws with a single federal standard
Correct answer: Strengthening enforcement and extending obligations to business associates
HITECH strengthened HIPAA enforcement through tiered penalties, required breach notification, and directly extended HIPAA Security Rule obligations to business associates.
Question 7: A covered entity implements a policy requiring all portable devices containing ePHI to use full-disk encryption. This control PRIMARILY addresses which security objective?
- Integrity
- Availability
- Non-repudiation
- Confidentiality (Correct answer)
Correct answer: Confidentiality
Full-disk encryption on portable devices primarily protects confidentiality by ensuring that ePHI cannot be read by unauthorized individuals if a device is lost or stolen.
A hospital must report a breach affecting 600 individuals.
In addition to notifying affected individuals, the covered entity must notify: