Information Security & HIPAA Compliance Flashcards
7 cards from real Epic Skills Assessment practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Security & HIPAA Compliance flashcards as text
Which of the following best describes the concept of 'role-based access control' in an EHR system like Epic?
Answer: Access privileges are granted based on a user's job function and responsibilities
Role-based access control (RBAC) grants permissions based on the user's organizational role, ensuring staff only access information relevant to their duties.
A third-party vendor needs access to a hospital's Epic environment to perform system maintenance. What must be in place before this access is granted?
Answer: A signed Business Associate Agreement (BAA)
A Business Associate Agreement (BAA) is legally required between a covered entity and any vendor (business associate) who may access PHI.
Which of the following is the MOST effective way to protect ePHI transmitted over a public network?
Answer: Encrypting the data before transmission
Encryption renders ePHI unreadable during transmission, so even if intercepted, the data cannot be understood without the decryption key.
An employee receives an email that appears to be from Epic Systems requesting their login credentials to 'verify their account.' This is most likely:
Answer: A phishing attack attempting to steal credentials
Legitimate organizations never request credentials via email; this is a classic phishing tactic designed to steal login information.
Under HIPAA, which category of health information can be freely used and shared without patient authorization?
Answer: PHI shared for treatment, payment, and healthcare operations (TPO)
HIPAA permits covered entities to use and disclose PHI without patient authorization specifically for treatment, payment, and healthcare operations purposes.
What is the purpose of an audit log in an Epic system?
Answer: To track and record all user activity for accountability and security review
Audit logs create a tamper-evident record of who accessed or modified data, when, and from where, supporting accountability and breach investigation.
Which of the following scenarios would most likely require reporting to the Office for Civil Rights (OCR)?
Answer: A laptop containing unencrypted PHI for 600 patients is stolen
Breaches affecting 500 or more individuals must be reported to OCR and the media within 60 days; a stolen unencrypted laptop containing PHI for 600 patients meets this threshold.