← All CHSP Flashcard Decks

Security Management Flashcards

6 cards from real CHSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Security Management flashcards as text
  1. According to The Joint Commission Environment of Care standards, which of the following is a required component of a healthcare organization's security management plan?

    Answer: A security risk assessment that identifies security vulnerabilities specific to the organization

    TJC EC.02.01.01 requires healthcare organizations to conduct a security risk assessment to identify their unique security vulnerabilities. The other options may be appropriate responses to identified risks but are not universally required components of every security management plan.

  2. A healthcare safety professional is developing a workplace violence prevention program. Which of the following is the MOST effective primary prevention strategy?

    Answer: Conducting environmental design assessments to reduce violence risk factors

    Environmental design (CPTED — Crime Prevention Through Environmental Design) is a primary prevention approach that modifies the physical environment to reduce the opportunity for violence before it occurs. Panic buttons and physical restraint training are reactive measures, and signage alone is rarely effective as a primary prevention strategy.

  3. Under OSHA's General Duty Clause, healthcare employers are required to protect workers from workplace violence when:

    Answer: The hazard is recognized and a feasible means of abatement exists

    The General Duty Clause (Section 5(a)(1) of the OSH Act) requires employers to address recognized hazards for which feasible abatement methods exist. OSHA does not require a prior incident or a formal complaint — if the hazard is recognized (known or should be known) and can be reasonably abated, the employer has a duty to act.

  4. Which access control strategy is most appropriate for a hospital's high-security area such as a pharmacy or behavioral health unit?

    Answer: Proximity card readers with role-based access permissions and audit logging

    Proximity card readers with role-based permissions and audit logging provide layered security: they limit access to authorized personnel by role, create a time-stamped record of entries and exits, and allow rapid deactivation of credentials when needed. Key-based systems lack audit trails and cannot be quickly deactivated; sign-in logs and cameras alone do not restrict unauthorized access.

  5. A patient with dementia is found missing from a locked unit. This type of event is classified as:

    Answer: A patient elopement requiring a facility-wide security response

    Patient elopement — the unauthorized departure of a patient from a healthcare facility — is a distinct security event category requiring an immediate, coordinated response (search protocol, notification of family, incident report, and often regulatory notification). It is not classified as workplace violence or a medication error, and because a vulnerable patient is at risk, it is never a 'near-miss' even if the patient is found unharmed.

  6. When performing a security vulnerability assessment, the healthcare safety professional should use which framework as a primary reference?

    Answer: The International Association for Healthcare Security and Safety (IAHSS) Healthcare Security Guidelines

    The IAHSS Healthcare Security Guidelines are the industry-standard reference specifically designed for assessing and improving security in healthcare settings. NFPA 101 addresses life safety/fire, OSHA 1910.1200 covers chemical hazard communication, and CMS CoPs address broad operational compliance — none are security assessment frameworks.