Epic Skills Assessment Information Security & HIPAA Compliance 2 — Questions and Answers
Question 1: Which of the following best describes the concept of 'role-based access control' in an EHR system like Epic?
- Users can access any record they need by requesting temporary permission
- Access privileges are granted based on a user's job function and responsibilities (Correct answer)
- All clinical staff have equal access to all patient records system-wide
- Access is determined solely by the patient's consent preferences
Correct answer: Access privileges are granted based on a user's job function and responsibilities
Role-based access control (RBAC) grants permissions based on the user's organizational role, ensuring staff only access information relevant to their duties.
Question 2: A third-party vendor needs access to a hospital's Epic environment to perform system maintenance. What must be in place before this access is granted?
- A signed Business Associate Agreement (BAA) (Correct answer)
- A signed Notice of Privacy Practices
- An individual HIPAA waiver from each patient
- Approval from the state health department
Correct answer: A signed Business Associate Agreement (BAA)
A Business Associate Agreement (BAA) is legally required between a covered entity and any vendor (business associate) who may access PHI.
Question 3: Which of the following is the MOST effective way to protect ePHI transmitted over a public network?
- Using a strong password on the sending workstation
- Encrypting the data before transmission (Correct answer)
- Sending data in small batches to reduce exposure
- Requiring the recipient to acknowledge receipt
Correct answer: Encrypting the data before transmission
Encryption renders ePHI unreadable during transmission, so even if intercepted, the data cannot be understood without the decryption key.
Question 4: An employee receives an email that appears to be from Epic Systems requesting their login credentials to 'verify their account.' This is most likely:
- A legitimate security audit by the IT department
- A phishing attack attempting to steal credentials (Correct answer)
- A standard password reset notification
- An authorized penetration testing exercise
Correct answer: A phishing attack attempting to steal credentials
Legitimate organizations never request credentials via email; this is a classic phishing tactic designed to steal login information.
Question 5: Under HIPAA, which category of health information can be freely used and shared without patient authorization?
- PHI shared for treatment, payment, and healthcare operations (TPO) (Correct answer)
- PHI shared for marketing campaigns by covered entities
- PHI sold to data analytics companies for research
- PHI disclosed to employers for workplace safety decisions
Correct answer: PHI shared for treatment, payment, and healthcare operations (TPO)
HIPAA permits covered entities to use and disclose PHI without patient authorization specifically for treatment, payment, and healthcare operations purposes.
Question 6: What is the purpose of an audit log in an Epic system?
- To automatically correct errors in patient records
- To track and record all user activity for accountability and security review (Correct answer)
- To generate reports for insurance billing purposes
- To back up patient data in case of a system failure
Correct answer: To track and record all user activity for accountability and security review
Audit logs create a tamper-evident record of who accessed or modified data, when, and from where, supporting accountability and breach investigation.
Question 7: Which of the following scenarios would most likely require reporting to the Office for Civil Rights (OCR)?
- A nurse accidentally views the wrong patient's allergies before self-correcting
- A laptop containing unencrypted PHI for 600 patients is stolen (Correct answer)
- A physician discusses a patient's condition with a consulting specialist
- A patient requests a copy of their own medical record
Correct answer: A laptop containing unencrypted PHI for 600 patients is stolen
Breaches affecting 500 or more individuals must be reported to OCR and the media within 60 days; a stolen unencrypted laptop containing PHI for 600 patients meets this threshold.
Which of the following best describes the concept of 'role-based access control' in an EHR system like Epic?