EHR Health Information Privacy & Security 5 — Questions and Answers
Question 1: A covered entity discovers that an unauthorized person accessed 600 patient records. Which breach notification action is required?
- Notify only the 600 affected individuals
- Notify affected individuals and the Secretary of HHS; no media notice needed
- Notify affected individuals, the Secretary of HHS, and prominent local media outlets (Correct answer)
- No notification is required if the breach was accidental
Correct answer: Notify affected individuals, the Secretary of HHS, and prominent local media outlets
When a breach affects 500 or more individuals in a state or jurisdiction, the covered entity must notify affected individuals, HHS, and prominent local media.
Question 2: Which of the following best describes 'chain of trust' in the context of health information exchange?
- A legal agreement ensuring only trusted courts may access PHI
- A series of agreements ensuring all entities in an exchange network protect PHI appropriately (Correct answer)
- An encryption protocol for transmitting PHI
- A patient consent form for data sharing
Correct answer: A series of agreements ensuring all entities in an exchange network protect PHI appropriately
Chain of trust refers to a series of BAAs and agreements ensuring all parties in a data exchange network commit to protecting PHI.
Question 3: What is the primary goal of data encryption during transmission (data in transit)?
- To compress the data to reduce bandwidth
- To prevent unauthorized interception from reading the data (Correct answer)
- To verify the identity of the sender
- To ensure data is stored in a HIPAA-compliant format
Correct answer: To prevent unauthorized interception from reading the data
Encrypting data in transit ensures that even if the transmission is intercepted, the data cannot be read without the decryption key.
Question 4: A patient has the right under HIPAA to request restrictions on disclosures of their PHI. When MUST a covered entity honor such a request?
- Whenever the patient submits the request in writing
- When the patient requests restriction of disclosure to a health plan for a service paid out-of-pocket in full (Correct answer)
- When the restriction involves emergency treatment
- When the patient's attorney requests the restriction
Correct answer: When the patient requests restriction of disclosure to a health plan for a service paid out-of-pocket in full
Under HITECH, covered entities must honor a patient's request to restrict disclosure to a health plan when the patient has paid for the service entirely out-of-pocket.
Question 5: Which of the following is an example of a technical safeguard under the HIPAA Security Rule?
- Shredding paper records containing patient information
- Installing a lock on a server room door
- Implementing automatic session timeouts in the EHR system (Correct answer)
- Conducting background checks on workforce members
Correct answer: Implementing automatic session timeouts in the EHR system
Automatic session timeouts are a technical safeguard that prevent unauthorized access to an unattended workstation logged into the EHR.
Question 6: Under HIPAA, a 'covered entity' includes all of the following EXCEPT:
- Health plans
- Healthcare clearinghouses
- Healthcare providers who transmit health information electronically
- A life insurance company that does not conduct standard healthcare transactions (Correct answer)
Correct answer: A life insurance company that does not conduct standard healthcare transactions
A life insurance company that does not conduct standard HIPAA healthcare transactions is not a covered entity under HIPAA.
Question 7: Which concept ensures that users can only perform actions within the EHR that are necessary for their specific job duties and no more?
- Need-to-know / least privilege principle (Correct answer)
- Open access policy
- Dual control principle
- Separation of duties
Correct answer: Need-to-know / least privilege principle
The least privilege / need-to-know principle restricts user access to only the minimum necessary to perform their job functions.
A covered entity discovers that an unauthorized person accessed 600 patient records.
Which breach notification action is required?