EHR Health Information Privacy & Security 4 — Questions and Answers
Question 1: A patient requests an amendment to their health record. The covered entity may deny the request if:
- The amendment would improve the accuracy of the record
- The record was not created by the covered entity (Correct answer)
- The patient provides a valid reason for the change
- The record is less than one year old
Correct answer: The record was not created by the covered entity
A covered entity may deny an amendment request if the record was not created by that entity, among other valid grounds.
Question 2: Which type of malware encrypts an organization's files and demands payment for the decryption key?
- Spyware
- Ransomware (Correct answer)
- Adware
- Trojan horse
Correct answer: Ransomware
Ransomware encrypts the victim's data and demands a ransom payment in exchange for the decryption key.
Question 3: Under the HITECH Act, which entities were directly subject to HIPAA Security Rule requirements for the first time?
- Covered entities only
- Business associates of covered entities (Correct answer)
- State health departments
- Insurance clearing houses
Correct answer: Business associates of covered entities
HITECH extended direct HIPAA Security Rule liability to business associates, who were previously only bound contractually through BAAs.
Question 4: A nurse shares a patient's HIV status with the patient's employer without authorization. Under HIPAA, this is:
- Permitted under the public interest exception
- An impermissible disclosure of PHI (Correct answer)
- Allowed if the employer provides health insurance
- Permitted because the nurse is a covered entity workforce member
Correct answer: An impermissible disclosure of PHI
Disclosing a patient's PHI to their employer without authorization is an impermissible disclosure under HIPAA.
Question 5: Which of the following is a physical safeguard required by the HIPAA Security Rule?
- Password complexity policies
- Workstation use policies specifying appropriate computer functions
- Facility access controls limiting physical access to ePHI systems (Correct answer)
- Automatic logoff settings
Correct answer: Facility access controls limiting physical access to ePHI systems
Facility access controls — such as locks, badges, and surveillance — are physical safeguards required to limit physical access to systems containing ePHI.
Question 6: What is the timeframe within which a covered entity must notify affected individuals of a breach of unsecured PHI?
- Immediately upon discovery
- Within 30 days of discovery
- Within 60 days of discovery (Correct answer)
- Within 60 days of the breach being confirmed
Correct answer: Within 60 days of discovery
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering the breach.
Question 7: Which authentication method provides the strongest security for EHR access?
- Single-factor authentication using a password
- Two-factor authentication combining a password and a security token (Correct answer)
- Shared login credentials for a clinical team
- Biometric-only authentication
Correct answer: Two-factor authentication combining a password and a security token
Two-factor authentication (something you know + something you have) significantly strengthens access security compared to a password alone.
A patient requests an amendment to their health record.
The covered entity may deny the request if: