HCISPP Access Control & Identity Management in Healthcare 2 — Questions and Answers
Question 1: A covered entity wants to ensure that only authorized users access PHI stored in its EHR system. Which technical safeguard required by the HIPAA Security Rule DIRECTLY addresses this?
- Audit controls
- Transmission security
- Unique user identification (Correct answer)
- Encryption and decryption
Correct answer: Unique user identification
The HIPAA Security Rule's unique user identification requirement mandates that each user be assigned a unique identifier so that access to PHI can be tracked and attributed to a specific individual.
Question 2: In a healthcare context, 'privileged access' typically refers to:
- Access granted to patients to view their own medical records
- Elevated system or administrative rights granted to IT staff or database administrators (Correct answer)
- Physician-level permissions to order controlled substances
- The ability to override EHR alerts and warnings
Correct answer: Elevated system or administrative rights granted to IT staff or database administrators
Privileged access refers to elevated permissions that allow users such as system administrators or DBAs to manage, configure, or modify IT systems, which requires stricter controls and monitoring.
Question 3: A healthcare organization conducts quarterly reviews to ensure that access permissions for all users remain appropriate for their current roles. This process is known as:
- Penetration testing
- Access recertification or access review (Correct answer)
- Identity proofing
- Risk stratification
Correct answer: Access recertification or access review
Access recertification (or access review) is a periodic process in which managers validate that each user's current access rights are still appropriate for their role, reducing accumulation of unnecessary privileges.
Question 4: A nurse logs into a shared workstation using her credentials and then walks away without logging out. A colleague then views a patient record under her session. Which control would BEST prevent this scenario?
- Requiring biometric authentication at login
- Implementing automatic session timeout and screen lock (Correct answer)
- Enforcing password complexity requirements
- Using an intrusion detection system
Correct answer: Implementing automatic session timeout and screen lock
Automatic session timeout and screen lock ensures that an unattended session is secured after a period of inactivity, preventing unauthorized access via another person's open session.
Question 5: Which identity management concept involves verifying that a person is who they claim to be before granting them a digital credential or account in a healthcare system?
- Authorization
- Identity proofing (Correct answer)
- Access governance
- Credential lifecycle management
Correct answer: Identity proofing
Identity proofing is the process of verifying an individual's claimed identity (e.g., checking government ID or employment records) before issuing a digital credential or system account.
Question 6: In healthcare, 'context-based access control' might be used to restrict access to PHI based on which of the following factors?
- The color of the hospital badge worn by the employee
- The time of day, location, and device being used to access data (Correct answer)
- The number of patients assigned to the clinician
- The employee's years of service at the organization
Correct answer: The time of day, location, and device being used to access data
Context-based access control evaluates situational factors such as time of day, geographic location, and device type to dynamically determine whether access should be granted, adding a layer of security beyond static role assignments.
Question 7: Which of the following BEST describes the 'principle of least privilege' in a healthcare IT environment?
- Users are granted the lowest level of encryption for non-sensitive data
- Users receive only the access rights necessary to perform their specific job functions (Correct answer)
- New employees are given no access until their training is complete
- System administrators restrict all remote access to the EHR
Correct answer: Users receive only the access rights necessary to perform their specific job functions
The principle of least privilege limits each user's access rights to only what is needed for their specific role, minimizing the potential damage from compromised accounts or insider threats.
A covered entity wants to ensure that only authorized users access PHI stored in its EHR system.
Which technical safeguard required by the HIPAA Security Rule DIRECTLY addresses this?