CTP Digital Privacy and Security 3 — Questions and Answers
Question 1: A telehealth provider uses a personal smartphone for patient video visits without any mobile device management (MDM) software. Which risk does this PRIMARILY create?
- Reduced battery life on the device
- Inability to enforce remote wipe if the device is lost or stolen (Correct answer)
- Slower internet connection during video calls
- Incompatibility with telehealth software updates
Correct answer: Inability to enforce remote wipe if the device is lost or stolen
Without MDM, there is no mechanism to remotely wipe ePHI from a lost or stolen personal device, creating a significant breach risk.
Question 2: Which of the following BEST describes a 'man-in-the-middle' (MITM) attack in a telehealth context?
- A hacker physically steals a provider's laptop
- An attacker intercepts and potentially alters communications between a patient and provider (Correct answer)
- A disgruntled employee downloads patient records without authorization
- A phishing email tricks a provider into resetting their password
Correct answer: An attacker intercepts and potentially alters communications between a patient and provider
In a MITM attack, an attacker secretly intercepts and can alter communications between two parties who believe they are communicating directly.
Question 3: A telehealth organization is evaluating a new EHR vendor. Which security document should the organization request FIRST to assess the vendor's security posture?
- The vendor's marketing brochure
- A SOC 2 Type II audit report (Correct answer)
- The vendor's financial statements
- A list of the vendor's other healthcare clients
Correct answer: A SOC 2 Type II audit report
A SOC 2 Type II report provides an independent auditor's assessment of a vendor's security controls over a defined period of time.
Question 4: Under the HIPAA Breach Notification Rule, what is the maximum time a covered entity has to notify the Secretary of HHS of a breach affecting 500 or more individuals?
- 24 hours
- 60 calendar days from discovery (Correct answer)
- 60 calendar days from the date of the breach
- Within 60 days of the end of the calendar year in which the breach occurred
Correct answer: 60 calendar days from discovery
For breaches affecting 500 or more individuals, HHS must be notified within 60 calendar days of discovery of the breach.
Question 5: A telehealth session is recorded with patient consent. Where should this recording be stored to remain HIPAA compliant?
- In the provider's personal Dropbox account
- In a HIPAA-compliant cloud storage solution with a signed BAA (Correct answer)
- On the patient's personal device only
- On any cloud platform as long as access is password-protected
Correct answer: In a HIPAA-compliant cloud storage solution with a signed BAA
Recordings containing ePHI must be stored in a HIPAA-compliant cloud environment where the vendor has signed a BAA.
Question 6: What is the PRIMARY goal of conducting a HIPAA Security Risk Analysis (SRA)?
- To satisfy a one-time federal documentation requirement
- To identify, assess, and document potential risks and vulnerabilities to ePHI (Correct answer)
- To train staff on password management policies
- To generate a list of approved telehealth software vendors
Correct answer: To identify, assess, and document potential risks and vulnerabilities to ePHI
The SRA is designed to systematically identify threats and vulnerabilities to ePHI so that appropriate safeguards can be implemented.
Question 7: A provider accidentally sends a patient's therapy notes to the wrong patient via a secure portal. This is BEST categorized as:
- A security incident requiring IT remediation only
- A HIPAA privacy breach requiring breach notification analysis (Correct answer)
- A minor administrative error with no reporting requirements
- A business associate violation because the portal caused the error
Correct answer: A HIPAA privacy breach requiring breach notification analysis
Misdirected disclosure of ePHI to the wrong patient constitutes a potential breach and must undergo a four-factor breach notification analysis.
A telehealth provider uses a personal smartphone for patient video visits without any mobile device management (MDM) software.
Which risk does this PRIMARILY create?