HCISPP Information Governance and Risk Questions and Answers — Questions and Answers
Question 1: A rural clinic's risk analysis identifies a high-impact, low-likelihood risk of a natural disaster disabling their on-premise data center. Lacking the budget for a geographically separate hot site, the clinic's leadership decides to purchase a comprehensive cybersecurity and business interruption insurance policy. This action is an example of which risk treatment strategy?
- Risk Mitigation
- Risk Avoidance
- Risk Transference (Correct answer)
- Risk Acceptance
Correct answer: Risk Transference
Risk Transference involves shifting the financial impact of a potential risk to a third party. Purchasing an insurance policy is a classic example of this strategy, as the insurance company assumes the financial liability for the covered disruptive event.
Question 2: Within a mature healthcare information governance program, which role is typically responsible for the day-to-day management and operational control of a specific data asset, including implementing and maintaining technical security controls as defined by policies and standards?
- Data Owner
- Data Steward
- Data Custodian (Correct answer)
- Data Protection Officer (DPO)
Correct answer: Data Custodian
The Data Custodian is the role responsible for the technical environment and management of the data asset. They implement the security controls and operational procedures defined by the Data Owner and Data Stewards. The Owner has ultimate accountability, the Steward defines business rules, and the DPO focuses on compliance.
Question 3: A hospital's legal department issues a 'legal hold' on all electronic and paper records related to a specific patient due to pending litigation. Which of the following information governance processes is MOST directly and immediately impacted by this action?
- Data Classification
- Data Backup and Recovery
- Information Risk Analysis
- Record Retention and Disposition (Correct answer)
Correct answer: Record Retention and Disposition
A legal hold is a directive to preserve data and suspend normal retention and disposition schedules when litigation is anticipated. This action directly overrides standard policies that would otherwise lead to the routine destruction or deletion of the specified information, ensuring it is available for the legal process.
Question 4: A healthcare system's main Information Security Policy states, 'All ePHI must be encrypted in transit and at rest.' To implement this, the IT department creates a document specifying that TLS 1.3 or higher must be used for all data in transit and AES-256 for all data at rest. According to the policy, standard, procedure, and guideline hierarchy, how would the IT department's document be BEST classified?
- A policy
- A standard (Correct answer)
- A guideline
- A procedure
Correct answer: A standard
A standard provides the mandatory, specific technical requirements needed to comply with a high-level policy. The policy states the 'what' (encrypt data), while the standard defines the 'how' with specific, compulsory rules (use TLS 1.3, use AES-256).
Question 5: ARMA International's Generally Accepted Recordkeeping Principles® (GARP) provides a framework for effective information governance. Which principle specifically addresses the need to ensure that an organization's records are authentic and reliable?
- Principle of Accountability
- Principle of Integrity (Correct answer)
- Principle of Protection
- Principle of Availability
Correct answer: Principle of Integrity
The GARP Principle of Integrity states that an information governance program shall be constructed so the records and information managed by the organization have a reasonable and suitable guarantee of authenticity and reliability.
Question 6: A healthcare research institution is creating a data classification scheme for its information assets, which include patient-consented research data, anonymized statistical data, employee PII, and public research papers. Which of the following is the MOST critical driver for classifying this data?
- Data storage cost
- Data accessibility speed
- Data sensitivity and regulatory requirements (Correct answer)
- Data creation date
Correct answer: Data sensitivity and regulatory requirements
In healthcare, the primary driver for data classification is the sensitivity of the information (e.g., PHI, PII) and the associated legal and regulatory requirements (e.g., HIPAA, Common Rule) that dictate specific protection levels. Cost, access speed, and age are secondary considerations that are influenced by this primary classification.
A rural clinic's risk analysis identifies a high-impact, low-likelihood risk of a natural disaster disabling their on-premise data center.
Lacking the budget for a geographically separate hot site, the clinic's leadership decides to purchase a comprehensive cybersecurity and business interruption insurance policy.
This action is an example of which risk treatment strategy?