Free Certified in Healthcare Privacy and Security Questions and Answers — Questions and Answers
Question 1: Which of the following HIPAA standards would contain the policies and procedures that specify the process for authorizing access to PHI?
- Access control
- Data privacy
- Access authorization (Correct answer)
- General authorization
Correct answer: Access authorization
Policies and procedures that define the process for granting access to protected health information (PHI) are typically addressed in the "Access Authorization" standard of the Health Insurance Portability and Accountability Act (HIPAA). Access authorization refers to the controls and mechanisms put in place to ensure that only authorized individuals can access PHI. <br> <br> The Access Authorization standard under HIPAA includes requirements for covered entities (such as healthcare providers, health plans, and healthcare clearinghouses) to implement policies and procedures that govern the granting and revoking of access to PHI. These policies and procedures should specify who can access PHI, under what circumstances, and for what purposes. They also typically outline the processes for reviewing and approving access requests, ensuring appropriate user authentication and authorization, and maintaining audit trails to track access to PHI.
Question 2: Which of the following rules outlines the steps in implementing several policies and processes to safeguard the security of credit, debit, and cash card transactions?
- Labor cost
- Payment Card Industry Data Security Standard (PCD DDS) (Correct answer)
- Financial remuneration
- No further action is required
Correct answer: Payment Card Industry Data Security Standard (PCD DDS)
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards established by the major credit card companies (Visa, Mastercard, American Express, Discover, and JCB International) to ensure the protection of cardholder data. PCI DSS specifies a series of policies and procedures that organizations handling credit, debit, and cash card transactions must implement to safeguard cardholder information.
Question 3: No later than 60 days from the date of discovery, written notice of a breach must be sent to each individual.
- Post the breach on the company website
- First class mail or e-mail (Correct answer)
- Encryption and destruction
- Risk avoidance
Correct answer: First class mail or e-mail
According to the HIPAA Breach Notification Rule, covered entities are required to provide written notification to individuals whose protected health information (PHI) has been breached. The notification must be completed without unreasonable delay, but no later than 60 days from the date of discovery of the breach. <br> <br> Regarding the method of notification, the rule does not specify a particular means of communication. However, it states that covered entities should use the individual's preferred method of contact if that information is available. First-class mail and email are commonly used methods for delivering breach notifications. The choice between these methods depends on the contact information available for the affected individuals and their indicated preferences.
Question 4: What kind of threat is equipment theft?
- Risk acceptance
- Burden of proof
- Acts of man (Correct answer)
- Workstation use
Correct answer: Acts of man
The theft of equipment is considered an example of a threat known as "acts of man" or "human threats." Acts of man refer to intentional or deliberate actions carried out by individuals that pose a risk to the security and safety of assets, information, or systems.
Question 5: How long after someone passes away does medical information cease to be safeguarded by HIPAA rules and is no longer deemed protected health information?
- September 23, 2014
- 50 (Correct answer)
- September 20, 2020
- Waiver
Correct answer: 50
Under the HIPAA Privacy Rule, a deceased person's health information stops being protected health information 50 years after death. The dated options and 'waiver' are distractors—HIPAA defines a fixed 50-year period, not a specific calendar date or a waiver-based condition.
Question 6: An organization has just implemented a new policy that spells out how it would physically safeguard the five clinics it owns. This is an illustration of a (n)
- Facility security plan (Correct answer)
- Security update
- Burden of proof
- Exclusion
Correct answer: Facility security plan
The implementation of a new policy that outlines how an organization protects the physical space of its clinics is an example of a Facility Security Plan. <br> <br> A Facility Security Plan is a comprehensive set of policies, procedures, and protocols designed to safeguard the physical security of an organization's facilities. It covers various aspects such as access control, surveillance systems, visitor management, emergency response, incident reporting, and other security measures.
Question 7: An example of a policy that details the tasks that may be carried out on computers and laptops inside an organization
- Risk avoidance
- Workstation use (Correct answer)
- Exclusion
- Security update
Correct answer: Workstation use
Workstation Use is the HIPAA Security Rule physical safeguard standard that requires policies specifying the proper functions, manner of performance, and physical environment for devices that access ePHI. Risk avoidance is a risk-management strategy, not a usage policy, and exclusion and security update do not define what tasks may be performed on workstations.
Which of the following HIPAA standards would contain the policies and procedures that specify the process for authorizing access to PHI?