CTP Digital Privacy and Security 5 — Questions and Answers
Question 1: A telehealth practice discovers that a former employee's access credentials were never deactivated after termination. This is a failure of which HIPAA safeguard category?
- Technical safeguards
- Physical safeguards
- Administrative safeguards (Correct answer)
- Organizational requirements
Correct answer: Administrative safeguards
Establishing and following workforce clearance procedures, including timely access termination, is an administrative safeguard requirement under HIPAA.
Question 2: Which of the following BEST describes 'data at rest' in a telehealth environment?
- ePHI being transmitted between a patient's device and the telehealth server
- ePHI stored on servers, databases, or backup media when not actively in use (Correct answer)
- ePHI displayed on a provider's screen during an active visit
- ePHI in transit through a VPN tunnel
Correct answer: ePHI stored on servers, databases, or backup media when not actively in use
Data at rest refers to ePHI stored on any medium — servers, hard drives, or backups — that is not currently being transmitted.
Question 3: A telehealth provider conducts sessions from a home office where family members may overhear conversations. The MOST appropriate mitigation is:
- Conducting sessions only during nighttime hours when others are asleep
- Using a private, dedicated space with a door and conducting sessions with headphones (Correct answer)
- Asking patients not to share sensitive information during video visits
- Installing a white noise machine in the main living area
Correct answer: Using a private, dedicated space with a door and conducting sessions with headphones
A private, closed space with headphones limits incidental disclosures to household members, satisfying HIPAA's reasonable safeguards requirement.
Question 4: What is the key difference between a HIPAA 'privacy' violation and a HIPAA 'security' violation?
- Privacy violations are always more severe than security violations
- Privacy relates to improper use or disclosure of PHI; security relates specifically to failures protecting ePHI (Correct answer)
- Security violations only apply to paper records
- Privacy violations require federal reporting; security violations do not
Correct answer: Privacy relates to improper use or disclosure of PHI; security relates specifically to failures protecting ePHI
The Privacy Rule governs all PHI (any format), while the Security Rule specifically applies to electronic PHI (ePHI) and its technical, administrative, and physical protections.
Question 5: A patient in a telehealth session uses an unsecured public Wi-Fi network. Which risk does this PRIMARILY introduce?
- Increased latency making the video call choppy
- Potential interception of session data by third parties on the same network (Correct answer)
- Violation of the provider's HIPAA obligations
- Automatic session timeout by the telehealth platform
Correct answer: Potential interception of session data by third parties on the same network
Public Wi-Fi networks lack encryption controls, making session data vulnerable to interception by other users on the same network.
Question 6: Under HIPAA, which of the following is NOT considered a required implementation specification of the Security Rule's Access Control standard?
- Unique user identification
- Automatic logoff
- Biometric authentication for all users (Correct answer)
- Emergency access procedure
Correct answer: Biometric authentication for all users
Biometric authentication is not a required HIPAA specification; unique user IDs, emergency access procedures, and automatic logoff are required or addressable specifications.
Question 7: A covered telehealth entity experiences a breach affecting 600 patients in Texas. In addition to notifying HHS and affected individuals, what additional notification is required?
- Notify the state medical board within 24 hours
- Notify prominent media outlets in the state because more than 500 residents are affected (Correct answer)
- Notify the FBI cybercrime division
- Notify each patient's insurance carrier
Correct answer: Notify prominent media outlets in the state because more than 500 residents are affected
HIPAA requires notification to prominent media outlets when a breach affects more than 500 residents of a state or jurisdiction.
A telehealth practice discovers that a former employee's access credentials were never deactivated after termination.
This is a failure of which HIPAA safeguard category?