CIIP Healthcare Information Security and Privacy 2 — Questions and Answers
Question 1: What is the maximum number of days a covered entity has to notify affected individuals after discovering a HIPAA breach?
- 60 days (Correct answer)
- 30 days
- 90 days
- 10 days
Correct answer: 60 days
HIPAA requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI.
Question 2: Which DICOM attribute must be removed to properly de-identify an image per DICOM PS3.15 standard?
- Patient Name (0010,0010) (Correct answer)
- Photometric Interpretation (0028,0004)
- Transfer Syntax UID (0002,0010)
- Rows (0028,0010)
Correct answer: Patient Name (0010,0010)
Patient Name (0010,0010) is a core identifying attribute that must be removed or anonymized per DICOM de-identification profiles.
Question 3: A Business Associate Agreement (BAA) is required when a PACS vendor:
- Has access to ePHI while providing services to a covered entity (Correct answer)
- Only sells hardware with no access to patient data
- Provides general IT support unrelated to health data
- Operates solely within a foreign jurisdiction
Correct answer: Has access to ePHI while providing services to a covered entity
A BAA is legally required whenever a business associate handles, stores, or transmits ePHI on behalf of a covered entity.
Question 4: Which type of audit log is most critical for detecting unauthorized access to imaging studies in a PACS environment?
- Access audit log tracking user logins and study views (Correct answer)
- System performance log tracking server CPU usage
- Network bandwidth log for DICOM transmissions
- Backup completion log for archived images
Correct answer: Access audit log tracking user logins and study views
Access audit logs record who viewed or accessed specific studies and are essential for detecting unauthorized PHI access in PACS.
Question 5: What does the principle of 'minimum necessary' require in an imaging informatics context?
- Staff should access only the PHI needed to perform their specific job duties (Correct answer)
- Imaging systems should store the minimum number of images per study
- Encryption keys should use the minimum acceptable key length
- Backup retention should be the minimum required by state law
Correct answer: Staff should access only the PHI needed to perform their specific job duties
The minimum necessary principle requires limiting PHI access and disclosure to what is reasonably needed to accomplish the intended purpose.
Question 6: Which federal regulation, beyond HIPAA, governs the cybersecurity posture of healthcare organizations connected to federal networks?
- NIST Cybersecurity Framework (CSF) (Correct answer)
- Sarbanes-Oxley Act (SOX)
- Payment Card Industry DSS (PCI-DSS)
- Federal Information Security Management Act (FISMA) for non-federal entities
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework provides voluntary but widely adopted guidance for managing cybersecurity risk in healthcare beyond HIPAA's requirements.
What is the maximum number of days a covered entity has to notify affected individuals after discovering a HIPAA breach?