CHPS HIPAA Security Rule Compliance 2 — Questions and Answers
Question 1: Under the Technical Safeguards of the HIPAA Security Rule, which implementation specification for Access Control is designated as 'required'?
- Unique user identification (Correct answer)
- Automatic logoff
- Encryption and decryption
- Emergency access procedure
Correct answer: Unique user identification
Unique user identification is a required implementation specification, ensuring each user is assigned a unique name or number to track user identity and activity within ePHI systems.
Question 2: What is the purpose of the Audit Controls standard under the HIPAA Security Rule's Technical Safeguards?
- To implement hardware, software, or procedural mechanisms that record and examine activity in information systems containing ePHI (Correct answer)
- To restrict access to ePHI based on user roles
- To encrypt ePHI during transmission over open networks
- To automatically terminate inactive sessions after a set period
Correct answer: To implement hardware, software, or procedural mechanisms that record and examine activity in information systems containing ePHI
Audit Controls require the implementation of mechanisms to record and examine system activity, enabling organizations to review access patterns and detect unauthorized use of ePHI.
Question 3: In the context of the HIPAA Security Rule, what does 'integrity' of ePHI mean?
- ePHI has not been altered or destroyed in an unauthorized manner (Correct answer)
- ePHI is accessible to authorized users when needed
- ePHI is protected from unauthorized disclosure
- ePHI is backed up and recoverable after a disaster
Correct answer: ePHI has not been altered or destroyed in an unauthorized manner
The Security Rule defines integrity as ensuring that ePHI is not altered or destroyed in an unauthorized manner, which corresponds to the 'I' in the CIA triad.
Question 4: The HIPAA Security Rule's Transmission Security standard is designed to protect ePHI when it is:
- Transmitted over electronic communications networks (Correct answer)
- Stored on portable devices such as laptops
- Accessed by workforce members at workstations
- Transferred between departments within the same facility
Correct answer: Transmitted over electronic communications networks
The Transmission Security standard requires covered entities to implement technical security measures to guard against unauthorized access to ePHI transmitted over electronic communications networks.
Question 5: Under the HIPAA Security Rule's Physical Safeguards, what does the Workstation Use standard require?
- Policies and procedures specifying proper functions performed at workstations and the physical attributes of the surroundings of workstations with access to ePHI (Correct answer)
- Encryption of all data stored on workstations
- Automatic screen locks after a period of inactivity
- A formal check-in process for all users accessing workstations
Correct answer: Policies and procedures specifying proper functions performed at workstations and the physical attributes of the surroundings of workstations with access to ePHI
The Workstation Use standard requires policies defining proper workstation functions and the physical environment of workstations that access ePHI, such as positioning screens away from unauthorized viewers.
Question 6: Which of the following best describes the purpose of a Business Associate Agreement (BAA) under the HIPAA Security Rule?
- To contractually require business associates to implement appropriate safeguards to protect ePHI they create, receive, maintain, or transmit on behalf of a covered entity (Correct answer)
- To transfer legal liability for breaches from the covered entity to the business associate
- To certify that a vendor has passed a HIPAA compliance audit
- To authorize a business associate to disclose ePHI to other third parties
Correct answer: To contractually require business associates to implement appropriate safeguards to protect ePHI they create, receive, maintain, or transmit on behalf of a covered entity
A BAA is a required contract that establishes the permitted uses and disclosures of ePHI by a business associate and obligates the associate to implement appropriate security safeguards.
Question 7: The Contingency Plan standard under the HIPAA Security Rule's Administrative Safeguards requires which of the following implementation specifications as 'required' (not addressable)?
- Data backup plan and disaster recovery plan
- Emergency mode operation plan and testing and revision procedures
- Applications and data criticality analysis
- Both A and B (Correct answer)
Correct answer: Both A and B
The required contingency plan implementation specifications are the data backup plan, disaster recovery plan, and emergency mode operation plan; testing/revision procedures and criticality analysis are addressable.
Under the Technical Safeguards of the HIPAA Security Rule, which implementation specification for Access Control is designated as 'required'?