CPHIMS CPHIMS Healthcare Privacy and Security 2 — Questions and Answers
Question 1: Under HIPAA, which of the following is NOT considered protected health information (PHI)?
- A patient's diagnosis documented in the EHR
- De-identified health data meeting Safe Harbor standards (Correct answer)
- Insurance claim data linked to a specific individual
- Lab results transmitted electronically
Correct answer: De-identified health data meeting Safe Harbor standards
De-identified health data that meets HIPAA's Safe Harbor or Expert Determination standards is not considered PHI and is not subject to HIPAA protections.
Question 2: A healthcare organization experiences a ransomware attack that encrypts patient records. Under HIPAA Breach Notification Rule, when must affected individuals be notified?
- Within 24 hours of discovery
- Within 60 days of discovery (Correct answer)
- Within 30 days of discovery
- Within 90 days of discovery
Correct answer: Within 60 days of discovery
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovery of a breach.
Question 3: Which NIST framework component focuses on recovering systems and services after a cybersecurity incident?
- Identify
- Protect
- Respond
- Recover (Correct answer)
Correct answer: Recover
The NIST Cybersecurity Framework 'Recover' function focuses on restoring capabilities and services impaired by a cybersecurity incident.
Question 4: An employee accesses patient records of a celebrity out of curiosity without a treatment purpose. This is an example of which type of HIPAA violation?
- Incidental disclosure
- Unauthorized access (snooping) (Correct answer)
- Minimum necessary violation
- Willful neglect with correction
Correct answer: Unauthorized access (snooping)
Accessing patient records without a legitimate treatment, payment, or operations purpose is considered unauthorized access or 'snooping,' a serious HIPAA violation.
Question 5: What is the primary purpose of a Business Associate Agreement (BAA) under HIPAA?
- To authorize third parties to sell patient data
- To ensure vendors safeguard PHI they access on behalf of a covered entity (Correct answer)
- To eliminate the need for encryption of transmitted data
- To allow unlimited data sharing between healthcare organizations
Correct answer: To ensure vendors safeguard PHI they access on behalf of a covered entity
A BAA is a contract that requires business associates to appropriately safeguard PHI they create, receive, maintain, or transmit on behalf of a covered entity.
Question 6: Which access control model assigns permissions based on a user's role within an organization rather than individual identity?
- Discretionary Access Control (DAC)
- Mandatory Access Control (MAC)
- Role-Based Access Control (RBAC) (Correct answer)
- Attribute-Based Access Control (ABAC)
Correct answer: Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) grants permissions based on organizational roles, making it the most widely used model in healthcare IT systems.
Question 7: Under the HIPAA Privacy Rule, a patient's right to request an amendment to their health record applies when:
- The patient disagrees with a clinical diagnosis
- The record contains information the patient believes is inaccurate or incomplete (Correct answer)
- The patient wants to delete all records older than 5 years
- The covered entity made the record available to a third party
Correct answer: The record contains information the patient believes is inaccurate or incomplete
Patients have the right to request amendments to their PHI if they believe information in their record is incorrect or incomplete, though the covered entity may deny the request.
Under HIPAA, which of the following is NOT considered protected health information (PHI)?