Information Security & HIPAA Compliance Flashcards
7 cards from real Epic Skills Assessment practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Security & HIPAA Compliance flashcards as text
Under HIPAA, which of the following is considered Protected Health Information (PHI)?
Answer: A patient's name combined with their diagnosis
PHI is any individually identifiable health information, including a patient's name linked to their medical condition.
Which HIPAA rule specifically governs the security of electronic protected health information (ePHI)?
Answer: The Security Rule
The HIPAA Security Rule establishes national standards to protect ePHI that is created, received, used, or maintained by covered entities.
An Epic user shares their login credentials with a colleague covering their shift. This is a violation of which security principle?
Answer: Accountability and non-repudiation
Sharing credentials undermines accountability and non-repudiation, since actions can no longer be traced to the individual who performed them.
A hospital employee accesses the medical record of a celebrity patient out of curiosity, without clinical need. This is best described as a violation of:
Answer: The minimum necessary standard
The minimum necessary standard requires that access to PHI be limited to only what is required to accomplish the intended purpose.
Which of the following is an example of a physical safeguard required by the HIPAA Security Rule?
Answer: Workstation screens positioned to prevent unauthorized viewing
Workstation positioning to prevent unauthorized viewing is a physical safeguard that controls physical access to systems containing ePHI.
Under HIPAA's Breach Notification Rule, covered entities must notify affected individuals of a PHI breach within how many days?
Answer: 60 days
The Breach Notification Rule requires covered entities to notify affected individuals no later than 60 calendar days after discovery of a breach.
In Epic, 'break-the-glass' access is designed to:
Answer: Permit authorized users to access records outside their normal permissions when clinically necessary
Break-the-glass allows authorized users to override normal access restrictions in urgent clinical situations, with all such access logged for audit review.