CHPS Trivia 3 — Questions and Answers
Question 1: Which NIST publication provides the primary framework for federal information security programs and is widely used in healthcare security?
- NIST SP 800-53 (Correct answer)
- NIST SP 800-171
- NIST SP 800-37
- NIST CSF
Correct answer: NIST SP 800-53
NIST SP 800-53 provides a catalog of security and privacy controls for federal information systems and is a key reference for healthcare security programs.
Question 2: What is the primary distinction between 'required' and 'addressable' implementation specifications under the HIPAA Security Rule?
- Required specs must be implemented exactly; addressable specs may be adapted or not implemented if documented (Correct answer)
- Required specs apply to large entities; addressable specs apply to small ones
- Required specs involve encryption; addressable specs involve training
- There is no meaningful distinction
Correct answer: Required specs must be implemented exactly; addressable specs may be adapted or not implemented if documented
Required specifications must be implemented as stated, while addressable specifications allow entities to assess reasonableness and document alternative measures or reasons for non-implementation.
Question 3: Which entity enforces the HIPAA Privacy Rule for most covered entities?
- FTC
- OCR (HHS Office for Civil Rights) (Correct answer)
- CMS
- OIG
Correct answer: OCR (HHS Office for Civil Rights)
The HHS Office for Civil Rights (OCR) is the primary enforcement agency for the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.
Question 4: What type of risk analysis is specifically required by the HIPAA Security Rule?
- Qualitative only
- Quantitative only
- Accurate and thorough assessment of potential risks to ePHI confidentiality, integrity, and availability (Correct answer)
- Annual penetration testing
Correct answer: Accurate and thorough assessment of potential risks to ePHI confidentiality, integrity, and availability
The Security Rule requires an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI held by the entity.
Question 5: In healthcare security, what does the acronym 'CIA' stand for in the context of information security?
- Central Intelligence Agency
- Confidentiality, Integrity, Availability (Correct answer)
- Control, Identify, Authenticate
- Compliance, Integration, Assurance
Correct answer: Confidentiality, Integrity, Availability
The CIA triad — Confidentiality, Integrity, and Availability — represents the three core principles of information security that HIPAA's Security Rule is designed to protect.
Question 6: Which HIPAA provision allows a covered entity to disclose PHI to a public health authority without patient authorization?
- Treatment, Payment, and Operations (TPO) exception
- Public interest and benefit activities exception (Correct answer)
- Research waiver
- Judicial order exception
Correct answer: Public interest and benefit activities exception
HIPAA's public interest and benefit activities exception permits disclosures to public health authorities for activities like disease surveillance and outbreak control without patient authorization.
Question 7: What is the legal document that governs the relationship between a covered entity and a Business Associate under HIPAA?
- Data Use Agreement
- Business Associate Agreement (BAA) (Correct answer)
- Service Level Agreement
- Memorandum of Understanding
Correct answer: Business Associate Agreement (BAA)
A Business Associate Agreement (BAA) is the required contract that establishes the permitted uses and disclosures of PHI by a Business Associate on behalf of a covered entity.
Which NIST publication provides the primary framework for federal information security programs and is widely used in healthcare security?