CTP Digital Privacy and Security 4 — Questions and Answers
Question 1: Which authentication method provides the STRONGEST security for telehealth provider portal logins?
- A complex 12-character password changed every 90 days
- Multi-factor authentication combining a password and a one-time code (Correct answer)
- A shared departmental login with a unique username
- Security questions based on personal information
Correct answer: Multi-factor authentication combining a password and a one-time code
Multi-factor authentication (MFA) significantly reduces unauthorized access risk by requiring two or more independent verification factors.
Question 2: A telehealth provider allows patients to send photos of wounds via SMS text message. What is the MAIN compliance concern with this practice?
- SMS images are too low resolution for clinical assessment
- Standard SMS is not encrypted and does not meet HIPAA security requirements for ePHI (Correct answer)
- Patients may not have adequate data plans for image transmission
- The photos could be accidentally sent to a wrong number
Correct answer: Standard SMS is not encrypted and does not meet HIPAA security requirements for ePHI
Standard SMS messages are transmitted without encryption and lack the access controls required to protect ePHI under HIPAA.
Question 3: What does 'end-to-end encryption' mean in the context of a telehealth video platform?
- The video is encrypted only at the server level before storage
- The video data is encrypted on the sender's device and can only be decrypted by the intended recipient (Correct answer)
- The platform uses a firewall to block unauthorized IP addresses
- Only the audio portion of the call is encrypted
Correct answer: The video data is encrypted on the sender's device and can only be decrypted by the intended recipient
End-to-end encryption ensures that only the communicating parties can decrypt the data, preventing even the service provider from accessing the content.
Question 4: A patient requests access to their telehealth visit recordings and clinical notes. Under HIPAA, the provider must generally respond within:
- 10 business days
- 30 calendar days of receiving the request (Correct answer)
- 60 calendar days of receiving the request
- 90 calendar days of receiving the request
Correct answer: 30 calendar days of receiving the request
HIPAA requires covered entities to act on a patient's request for access to their PHI within 30 calendar days, with one possible 30-day extension.
Question 5: Which of the following is an example of a 'technical safeguard' required under the HIPAA Security Rule?
- Training staff on proper ePHI handling procedures
- Installing locks on server room doors
- Implementing automatic logoff for inactive telehealth platform sessions (Correct answer)
- Drafting a written sanctions policy for policy violators
Correct answer: Implementing automatic logoff for inactive telehealth platform sessions
Automatic logoff is a technical safeguard that terminates a session after a period of inactivity to prevent unauthorized access to ePHI.
Question 6: A telehealth organization's security policy requires a workforce member to verify a patient's identity before each telehealth session. Which security principle does this PRIMARILY address?
- Data integrity
- Authentication and identity verification (Correct answer)
- Audit trail maintenance
- Data minimization
Correct answer: Authentication and identity verification
Verifying patient identity before each session addresses authentication, ensuring that ePHI is disclosed only to the correct individual.
Question 7: When using a third-party telehealth platform, which action BEST demonstrates appropriate due diligence before sharing patient data?
- Confirming the platform has a mobile app available
- Verifying the vendor has signed a BAA and reviewing their security certifications (Correct answer)
- Checking that the platform has a high star rating in app stores
- Ensuring the platform is used by at least 100 other healthcare providers
Correct answer: Verifying the vendor has signed a BAA and reviewing their security certifications
Executing a BAA and reviewing security certifications verifies the vendor's legal commitment and technical capability to protect ePHI.
Which authentication method provides the STRONGEST security for telehealth provider portal logins?