CHPS Certified in Healthcare Privacy and Security MCQ 5 — Questions and Answers
Question 1: Under the HIPAA Privacy Rule, an individual's authorization for use or disclosure of PHI is NOT required for which of the following purposes?
- Marketing communications
- Sale of PHI to a data broker
- Public health activities authorized by law (Correct answer)
- Psychotherapy notes disclosure to an insurer
Correct answer: Public health activities authorized by law
The Privacy Rule permits covered entities to disclose PHI without authorization for public health activities, such as reporting communicable diseases to public health authorities.
Question 2: A risk register entry shows a threat with high likelihood and high impact. According to standard risk management, the BEST initial response strategy is to:
- Accept the risk and document it
- Transfer the risk to an insurer
- Mitigate the risk by implementing controls (Correct answer)
- Avoid the risk by stopping the business activity
Correct answer: Mitigate the risk by implementing controls
High-likelihood, high-impact risks should first be mitigated through security controls to reduce either the likelihood or the impact to an acceptable level.
Question 3: Which HIPAA-required document informs patients about how their PHI may be used and their privacy rights, and must be provided at first service delivery?
- Business Associate Agreement (BAA)
- Authorization Form
- Notice of Privacy Practices (NPP) (Correct answer)
- Accounting of Disclosures
Correct answer: Notice of Privacy Practices (NPP)
The Notice of Privacy Practices must describe how PHI may be used and disclosed, individual rights, and covered entity duties, and must be provided to patients at first point of service.
Question 4: A healthcare organization uses a firewall, intrusion detection system, and antivirus software as layers of protection. This approach is known as:
- Zero-trust architecture
- Defense in depth (Correct answer)
- Security through obscurity
- Least privilege principle
Correct answer: Defense in depth
Defense in depth uses multiple, overlapping security controls so that if one layer fails, additional layers continue to protect ePHI from compromise.
Question 5: Under HIPAA, which of the following statements about the Right of Access is TRUE?
- Covered entities must provide access within 15 days
- Covered entities may charge a reasonable cost-based fee for copies (Correct answer)
- Access may be permanently denied if the record is voluminous
- Psychotherapy notes must be provided upon request
Correct answer: Covered entities may charge a reasonable cost-based fee for copies
Covered entities may charge a reasonable, cost-based fee for providing copies of PHI, covering labor, supplies, and postage, but may not profit from access requests.
Question 6: An audit log system records who accessed ePHI, when, and what actions were taken. Under the HIPAA Security Rule, this is classified as which type of safeguard?
- Physical safeguard – workstation security
- Administrative safeguard – information access management
- Technical safeguard – audit controls (Correct answer)
- Organizational requirement – business associate contracts
Correct answer: Technical safeguard – audit controls
Audit controls are a required technical safeguard under the HIPAA Security Rule, mandating mechanisms to record and examine activity in systems that contain ePHI.
Question 7: Which privacy principle requires that only the minimum amount of PHI necessary to accomplish the intended purpose be used or disclosed?
- Data minimization / Minimum necessary standard (Correct answer)
- Purpose limitation
- Storage limitation
- Accuracy principle
Correct answer: Data minimization / Minimum necessary standard
The minimum necessary standard in HIPAA requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to what is needed for the stated purpose.
Under the HIPAA Privacy Rule, an individual's authorization for use or disclosure of PHI is NOT required for which of the following purposes?