CIIP Healthcare Information Security and Privacy 1 — Questions and Answers
Question 1: Under HIPAA, which of the following is considered Protected Health Information (PHI) in a radiology context?
- Patient name combined with a radiological diagnosis (Correct answer)
- De-identified DICOM images with all tags removed
- Aggregate statistical reports with no patient identifiers
- Anonymized teaching files approved by IRB
Correct answer: Patient name combined with a radiological diagnosis
PHI includes any individually identifiable health information, such as a patient name linked to a diagnosis or imaging study.
Question 2: Which HIPAA rule specifically governs the technical safeguards for electronic PHI stored in PACS?
- HIPAA Security Rule (Correct answer)
- HIPAA Privacy Rule
- HIPAA Breach Notification Rule
- HIPAA Enforcement Rule
Correct answer: HIPAA Security Rule
The HIPAA Security Rule mandates administrative, physical, and technical safeguards for electronic PHI (ePHI), including systems like PACS.
Question 3: A radiology technologist accidentally emails a patient's MRI report to the wrong recipient. Under HIPAA, this is classified as a:
- Breach of unsecured PHI (Correct answer)
- Minor privacy incident with no reporting obligation
- Permitted disclosure for treatment purposes
- Business associate violation only
Correct answer: Breach of unsecured PHI
An accidental disclosure of unsecured PHI to an unauthorized recipient meets the definition of a HIPAA breach requiring notification.
Question 4: Which encryption standard is recommended by NIST for protecting ePHI at rest in imaging systems?
- AES-256 (Correct answer)
- DES-56
- RC4-128
- MD5 hashing
Correct answer: AES-256
AES-256 (Advanced Encryption Standard with 256-bit keys) is the NIST-recommended standard for encrypting ePHI at rest.
Question 5: In the context of imaging informatics, what is the primary purpose of role-based access control (RBAC)?
- Ensure users can only access PHI necessary for their job function (Correct answer)
- Encrypt all data transmitted between modalities
- Automatically de-identify images before archiving
- Log all system errors to an audit trail
Correct answer: Ensure users can only access PHI necessary for their job function
RBAC restricts system access based on a user's organizational role, enforcing the minimum necessary standard for PHI access.
Question 6: Which of the following is a required element of a HIPAA Security Rule risk analysis for an imaging department?
- Identifying potential threats and vulnerabilities to ePHI (Correct answer)
- Publishing all security policies on the department intranet
- Encrypting only images that contain visible patient faces
- Performing annual penetration tests on all workstations
Correct answer: Identifying potential threats and vulnerabilities to ePHI
A risk analysis must identify potential threats and vulnerabilities to ePHI as a foundational requirement of the HIPAA Security Rule.
Under HIPAA, which of the following is considered Protected Health Information (PHI) in a radiology context?