Administrative Safeguards Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Administrative Safeguards flashcards as text
Under HIPAA's Administrative Safeguards, what is the primary purpose of a contingency plan?
Answer: To respond to emergencies that damage systems containing ePHI
The contingency plan standard requires covered entities to establish policies for responding to emergencies or disasters that damage systems containing ePHI.
Which component of the contingency plan addresses how a covered entity will continue operating in the event of a system failure?
Answer: Emergency mode operation plan
The emergency mode operation plan is required to enable continuation of critical business processes for protection of the security of ePHI during system failure.
A hospital's security officer discovers that a workforce member accessed patient records without authorization. Under Administrative Safeguards, what must occur?
Answer: The hospital must apply appropriate sanctions against the workforce member
The sanction policy standard requires covered entities to apply appropriate sanctions against workforce members who fail to comply with security policies.
What does the 'assigned security responsibility' standard under Administrative Safeguards require?
Answer: One individual must be identified as responsible for security policies and procedures
Covered entities must identify one person — often called the Security Officer — who is responsible for developing and implementing security policies.
Under HIPAA, an authorization and/or supervision implementation specification requires covered entities to:
Answer: Supervise workforce members who work with ePHI
Workforce members who work with ePHI must be supervised as appropriate, especially those working in locations with physical access to facilities with ePHI.
How often must covered entities review and modify their security policies under HIPAA's Administrative Safeguards?
Answer: Periodically, based on environmental or operational changes
HIPAA requires periodic review of security policies when environmental or operational changes affect the security of ePHI, not on a fixed schedule.
A covered entity uses a clearinghouse to process claims. Under the workforce clearance procedure, what must be done before granting this clearinghouse access to ePHI?
Answer: Implement procedures to verify authorization of access is appropriate
Workforce clearance procedures require implementing processes to determine whether access to ePHI by a workforce member is appropriate before granting such access.