CPHIMS CPHIMS Healthcare Privacy and Security 5 — Questions and Answers
Question 1: Which federal law, in addition to HIPAA, directly impacts privacy of substance use disorder treatment records?
- HITECH Act
- 42 CFR Part 2 (Correct answer)
- Gramm-Leach-Bliley Act
- FERPA
Correct answer: 42 CFR Part 2
42 CFR Part 2 provides additional, stricter confidentiality protections for records of patients treated for substance use disorders at federally assisted programs, beyond HIPAA requirements.
Question 2: A healthcare IT professional implements two-factor authentication (2FA) for EHR access. Which security principle does this PRIMARILY support?
- Non-repudiation
- Data integrity
- Authentication assurance (Correct answer)
- Data availability
Correct answer: Authentication assurance
Two-factor authentication strengthens authentication assurance by requiring users to prove identity through two independent factors, reducing the risk of unauthorized access from stolen credentials.
Question 3: The HITECH Act strengthened HIPAA by:
- Eliminating the need for Business Associate Agreements
- Extending HIPAA Security Rule obligations directly to business associates and increasing penalties (Correct answer)
- Allowing unlimited secondary use of patient data for research
- Removing breach notification requirements for small practices
Correct answer: Extending HIPAA Security Rule obligations directly to business associates and increasing penalties
The Health Information Technology for Economic and Clinical Health (HITECH) Act extended HIPAA Security Rule requirements directly to business associates and significantly increased civil and criminal penalties for violations.
Question 4: A hospital performs a vulnerability scan and discovers an unpatched operating system on a workstation accessing the EHR. What is the BEST immediate action?
- Document the finding and schedule patching during the next maintenance window in 6 months
- Isolate the workstation from the network and apply the security patch promptly (Correct answer)
- Notify HHS of the vulnerability
- Disable the EHR system until all workstations are scanned
Correct answer: Isolate the workstation from the network and apply the security patch promptly
Isolating the vulnerable workstation prevents potential exploitation while the patch is applied, balancing security risk management with minimal operational disruption.
Question 5: Which of the following is an example of an 'addressable' implementation specification under the HIPAA Security Rule?
- Access control
- Audit controls
- Integrity controls
- Automatic logoff (Correct answer)
Correct answer: Automatic logoff
Automatic logoff is an addressable implementation specification, meaning covered entities must assess whether it is a reasonable and appropriate safeguard given their environment and document their decision.
Question 6: A covered entity receives a subpoena for patient records from an attorney. Under HIPAA, the covered entity may disclose the records without patient authorization if:
- The attorney represents a major health plan
- Satisfactory assurances are provided that the patient has been notified or a qualified protective order is in place (Correct answer)
- The subpoena is from a state court rather than federal court
- The records are older than 7 years
Correct answer: Satisfactory assurances are provided that the patient has been notified or a qualified protective order is in place
HIPAA permits disclosure in response to a subpoena without authorization only if the covered entity receives satisfactory assurances that the requesting party has made reasonable efforts to notify the patient or obtain a qualified protective order.
Question 7: What is the primary goal of a healthcare organization's incident response plan (IRP) for a data breach?
- To permanently delete all compromised data to prevent further exposure
- To contain the breach, eradicate the threat, recover systems, and fulfill notification obligations (Correct answer)
- To immediately report all incidents to law enforcement
- To identify which employees caused the breach and terminate them
Correct answer: To contain the breach, eradicate the threat, recover systems, and fulfill notification obligations
An incident response plan guides an organization through contain-eradicate-recover phases while ensuring compliance with HIPAA breach notification and other regulatory obligations.
Which federal law, in addition to HIPAA, directly impacts privacy of substance use disorder treatment records?