โ† All CPCA Flashcard Decks

Compliance and Auditing Flashcards

7 cards from real CPCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance and Auditing flashcards as text
  1. A compliance officer at a healthcare organization receives a request from law enforcement for patient records without a court order. What should the officer do first?

    Answer: Consult legal counsel before releasing any patient information

    Before releasing any protected health information, the compliance officer should consult with legal counsel to determine whether the request meets HIPAA's permissible disclosure requirements.

  2. During an audit, a CPCA discovers that a vendor with access to sensitive data has not signed a Business Associate Agreement (BAA). Under which regulation is this a violation?

    Answer: HIPAA

    Under HIPAA, covered entities must have a signed Business Associate Agreement with any vendor that creates, receives, maintains, or transmits protected health information on their behalf.

  3. Which metric is most useful for tracking the effectiveness of a compliance remediation program over time?

    Answer: Mean time to remediate (MTTR) identified compliance findings

    Mean time to remediate (MTTR) measures how quickly an organization resolves identified compliance findings, directly reflecting the effectiveness of the remediation process.

  4. An auditor reviews an organization's change management process and finds that changes are being implemented without formal approval. Which ITIL process is being violated?

    Answer: Change Management

    Change Management requires formal approval through a Change Advisory Board (CAB) or similar process before implementing changes to production systems.

  5. What is the purpose of a compliance risk register?

    Answer: To document, prioritize, and track identified compliance risks and their mitigation status

    A compliance risk register is a structured document that captures identified compliance risks, their likelihood and impact, assigned owners, and the status of mitigation efforts.

  6. Under the NIST Cybersecurity Framework (CSF), which function focuses on identifying, investigating, and containing a cybersecurity event?

    Answer: Respond

    The Respond function of the NIST CSF covers activities to take action regarding a detected cybersecurity incident, including containment, eradication, and communication.

  7. A CPCA is conducting a third-party vendor risk assessment. Which factor is most critical to evaluate when the vendor processes regulated data?

    Answer: The vendor's own compliance certifications and audit reports (e.g., SOC 2, ISO 27001)

    When a vendor processes regulated data, their compliance certifications and independent audit reports (such as SOC 2 or ISO 27001) are the most direct evidence of their security and compliance controls.