Risk Assessment & Mitigation Flashcards
7 cards from real CMAS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Mitigation flashcards as text
A practice experiences a data breach affecting 600 patients' PHI. What is the HIPAA breach notification timeline for notifying the Secretary of HHS?
Answer: Within 60 days of discovery of the breach
For breaches affecting 500 or more individuals, covered entities must notify HHS simultaneously with patient notification — within 60 days of discovery.
Which type of risk analysis is recommended by HIPAA's Security Rule for covered entities?
Answer: An accurate and thorough assessment of potential risks and vulnerabilities to ePHI
The HIPAA Security Rule (45 CFR §164.308) requires covered entities to conduct an accurate and thorough risk analysis of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
A medical office manager discovers an employee is accessing patient records outside their job duties. This is BEST described as:
Answer: A workforce-related security incident and potential HIPAA Privacy Rule violation
Unauthorized employee access to patient records is a workforce-related security incident that violates the minimum necessary standard under HIPAA's Privacy Rule.
Which of the following is an example of an administrative safeguard under the HIPAA Security Rule?
Answer: Implementing workforce security training and access management policies
Administrative safeguards are policies and procedures governing workforce conduct, including security training programs and access management — not physical or technical controls.
A practice's risk mitigation plan includes purchasing additional malpractice coverage, upgrading EHR security, and training staff on fall prevention. These actions collectively represent:
Answer: A multi-modal risk management approach combining transfer, reduction, and prevention
Using insurance (transfer), EHR security upgrades (reduction), and fall prevention training (prevention/reduction) demonstrates a multi-modal approach addressing different risk categories.
Which government agency oversees HIPAA enforcement and investigates privacy and security complaints against covered entities?
Answer: Office for Civil Rights (OCR) within HHS
The Office for Civil Rights (OCR) within the Department of Health and Human Services is responsible for enforcing HIPAA Privacy and Security Rules and investigating breach complaints.
A medical administrative specialist reviews the practice's disaster recovery plan. Which scenario represents the HIGHEST priority risk requiring a documented recovery procedure?
Answer: Extended EHR system downtime preventing access to patient records during active patient care
EHR downtime during active patient care poses an immediate patient safety and operational risk, requiring a documented downtime procedure and recovery plan as the highest priority.