Administrative Safeguards Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Administrative Safeguards flashcards as text
What is the required minimum content of a HIPAA Security Risk Analysis?
Answer: An accurate and thorough assessment of potential risks and vulnerabilities to ePHI confidentiality, integrity, and availability
The risk analysis must be an accurate and thorough assessment of potential risks and vulnerabilities to all ePHI that an organization creates, receives, maintains, or transmits.
Under HIPAA Administrative Safeguards, 'log-in monitoring' is classified as:
Answer: An addressable implementation specification under security awareness and training
Log-in monitoring is an addressable implementation specification under the security awareness and training standard, focusing on training staff to monitor login attempts.
A covered entity conducts a risk assessment and identifies that unencrypted laptops pose a significant risk to ePHI. The entity decides not to encrypt them due to cost. This decision is:
Answer: Not acceptable because risk management must address identified risks
Risk management requires implementing security measures sufficient to reduce identified risks to a reasonable and appropriate level; simply accepting a significant risk without mitigation violates this requirement.
Which HIPAA standard requires covered entities to document the rationale for security policy decisions?
Answer: Documentation standard
The documentation standard (§164.316) requires covered entities to maintain written policies and procedures and to document decisions, including reasons for implementing or not implementing certain controls.
An evaluation under HIPAA's Administrative Safeguards must be performed:
Answer: Periodically and in response to environmental or operational changes
Covered entities must perform a periodic technical and nontechnical evaluation based on standards and in response to environmental or operational changes affecting ePHI security.
A cloud vendor stores ePHI on behalf of a hospital. Under Administrative Safeguards, this vendor must be treated as:
Answer: A business associate requiring a signed BAA
Any third party that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate and must have a BAA in place.
Which of the following is NOT a required implementation specification under the Contingency Plan standard?
Answer: Intrusion detection procedure
Intrusion detection is not part of the contingency plan standard; the required specifications are data backup, disaster recovery, emergency mode operation, testing/revision, and applications/data criticality analysis.