CPHIMS CPHIMS Healthcare Privacy and Security 4 — Questions and Answers
Question 1: A healthcare organization wants to share patient data for a research study without obtaining individual authorizations. Which HIPAA mechanism allows this?
- Business Associate Agreement
- Limited Data Set with a Data Use Agreement (Correct answer)
- Notice of Privacy Practices
- Incidental disclosure exception
Correct answer: Limited Data Set with a Data Use Agreement
A Limited Data Set (with certain direct identifiers removed) combined with a Data Use Agreement allows sharing of PHI for research, public health, or health care operations without individual authorization.
Question 2: Which of the following best describes the concept of 'data integrity' in healthcare information security?
- Ensuring only authorized users can access data
- Ensuring data is accurate, complete, and has not been improperly altered (Correct answer)
- Ensuring data is available when needed
- Ensuring data is encrypted during transmission
Correct answer: Ensuring data is accurate, complete, and has not been improperly altered
Data integrity ensures that health information is accurate, complete, and protected from unauthorized modification, forming a key pillar of the CIA (Confidentiality, Integrity, Availability) triad.
Question 3: A covered entity discovers that a laptop containing unencrypted PHI was stolen. Under HIPAA, this event is presumed to be:
- An incidental disclosure requiring no action
- A breach unless the organization can demonstrate low probability of PHI compromise (Correct answer)
- A minor security incident with no notification requirements
- Only reportable if more than 500 patients are affected
Correct answer: A breach unless the organization can demonstrate low probability of PHI compromise
Under HIPAA, an impermissible use or disclosure is presumed to be a breach unless the covered entity can demonstrate through a four-factor risk assessment that there is a low probability that PHI was compromised.
Question 4: Which security control is MOST effective at preventing unauthorized physical access to server rooms containing healthcare data?
- Firewall configuration
- Multi-factor authentication for network access
- Badge-access systems with biometric verification (Correct answer)
- Data loss prevention software
Correct answer: Badge-access systems with biometric verification
Physical access controls such as badge-access with biometric verification directly prevent unauthorized individuals from physically entering restricted areas housing sensitive healthcare systems.
Question 5: What is the role of a Chief Privacy Officer (CPO) in a healthcare organization?
- Managing network security and firewall configurations
- Overseeing compliance with privacy laws and policies governing patient information (Correct answer)
- Conducting penetration testing of clinical systems
- Approving all vendor contracts involving data sharing
Correct answer: Overseeing compliance with privacy laws and policies governing patient information
The CPO is responsible for developing, implementing, and maintaining the organization's privacy program, ensuring compliance with applicable privacy laws and regulations.
Question 6: Under the HIPAA Security Rule, which safeguard category includes policies for workforce training on security awareness?
- Technical Safeguards
- Physical Safeguards
- Administrative Safeguards (Correct answer)
- Operational Safeguards
Correct answer: Administrative Safeguards
Administrative Safeguards include policies and procedures related to workforce training, security management processes, and assigned security responsibility.
Question 7: A patient requests an accounting of disclosures of their PHI. Under HIPAA, which disclosures MUST be included in this accounting?
- Disclosures for treatment, payment, and operations
- Disclosures for public health reporting without patient authorization (Correct answer)
- All disclosures made in the last 10 years
- Disclosures to health plan sponsors
Correct answer: Disclosures for public health reporting without patient authorization
Patients have the right to an accounting of disclosures made for purposes other than treatment, payment, healthcare operations, and certain other exceptions, including public health activities.
A healthcare organization wants to share patient data for a research study without obtaining individual authorizations.
Which HIPAA mechanism allows this?