EHR Health Information Privacy & Security 3 — Questions and Answers
Question 1: Under the HIPAA Security Rule, which of the following is categorized as an 'addressable' implementation specification?
- Unique user identification
- Emergency access procedure
- Encryption and decryption of data at rest (Correct answer)
- Activity log review procedures
Correct answer: Encryption and decryption of data at rest
Encryption of data at rest is an addressable specification, meaning covered entities must implement it or document an equivalent alternative measure.
Question 2: What does the term 'minimum necessary' standard require of covered entities?
- Only the minimum number of staff may view any PHI
- PHI used or disclosed should be limited to what is needed for the intended purpose (Correct answer)
- Patients must give minimum consent before PHI is shared
- Only the minimum number of diagnoses may be stored in an EHR
Correct answer: PHI used or disclosed should be limited to what is needed for the intended purpose
The minimum necessary standard requires covered entities to limit PHI access and disclosure to only what is needed to accomplish the intended purpose.
Question 3: Which of the following scenarios qualifies as a HIPAA-permitted disclosure without patient authorization?
- Sharing PHI with a marketing firm to target patients with ads
- Reporting a gunshot wound to law enforcement as required by state law (Correct answer)
- Selling PHI to a pharmaceutical company for research
- Disclosing PHI to an employer for workplace monitoring
Correct answer: Reporting a gunshot wound to law enforcement as required by state law
Disclosures required by law, such as mandatory reporting of gunshot wounds to law enforcement, are permitted under HIPAA without patient authorization.
Question 4: A Business Associate Agreement (BAA) is required when a covered entity shares PHI with:
- Another covered entity for treatment purposes
- A vendor that creates, receives, maintains, or transmits PHI on the entity's behalf (Correct answer)
- A patient requesting their own records
- A state health department for required reporting
Correct answer: A vendor that creates, receives, maintains, or transmits PHI on the entity's behalf
A BAA is required with any business associate — a vendor or third party that handles PHI on behalf of the covered entity.
Question 5: What is the primary purpose of a Risk Analysis under the HIPAA Security Rule?
- To train staff on privacy procedures
- To identify and assess potential risks and vulnerabilities to ePHI confidentiality, integrity, and availability (Correct answer)
- To create a disaster recovery plan
- To audit EHR access logs quarterly
Correct answer: To identify and assess potential risks and vulnerabilities to ePHI confidentiality, integrity, and availability
A Risk Analysis is required to systematically identify threats and vulnerabilities that could affect the security of ePHI.
Question 6: Which of the following best describes 'data integrity' as it applies to EHR security?
- Ensuring only authorized users can access the system
- Ensuring that ePHI is not altered or destroyed in an unauthorized manner (Correct answer)
- Encrypting data during transmission
- Backing up data to an offsite location
Correct answer: Ensuring that ePHI is not altered or destroyed in an unauthorized manner
Data integrity means ensuring that ePHI remains accurate and unaltered except through authorized processes.
Question 7: How long must covered entities generally retain HIPAA-related documentation such as policies and procedures?
- 3 years from creation or last effective date
- 6 years from creation or last effective date (Correct answer)
- 10 years from creation
- Indefinitely
Correct answer: 6 years from creation or last effective date
HIPAA requires covered entities to retain documentation of policies, procedures, and actions for 6 years from the date of creation or last effective date.
Under the HIPAA Security Rule, which of the following is categorized as an 'addressable' implementation specification?