← All HIPAA Flashcard Decks

Administrative Safeguards Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Administrative Safeguards flashcards as text
  1. What is the required minimum content of a HIPAA Security Risk Analysis?

    Answer: An accurate and thorough assessment of potential risks and vulnerabilities to ePHI confidentiality, integrity, and availability

    The risk analysis must be an accurate and thorough assessment of potential risks and vulnerabilities to all ePHI that an organization creates, receives, maintains, or transmits.

  2. Under HIPAA Administrative Safeguards, 'log-in monitoring' is classified as:

    Answer: An addressable implementation specification under security awareness and training

    Log-in monitoring is an addressable implementation specification under the security awareness and training standard, focusing on training staff to monitor login attempts.

  3. A covered entity conducts a risk assessment and identifies that unencrypted laptops pose a significant risk to ePHI. The entity decides not to encrypt them due to cost. This decision is:

    Answer: Not acceptable because risk management must address identified risks

    Risk management requires implementing security measures sufficient to reduce identified risks to a reasonable and appropriate level; simply accepting a significant risk without mitigation violates this requirement.

  4. Which HIPAA standard requires covered entities to document the rationale for security policy decisions?

    Answer: Documentation standard

    The documentation standard (§164.316) requires covered entities to maintain written policies and procedures and to document decisions, including reasons for implementing or not implementing certain controls.

  5. An evaluation under HIPAA's Administrative Safeguards must be performed:

    Answer: Periodically and in response to environmental or operational changes

    Covered entities must perform a periodic technical and nontechnical evaluation based on standards and in response to environmental or operational changes affecting ePHI security.

  6. A cloud vendor stores ePHI on behalf of a hospital. Under Administrative Safeguards, this vendor must be treated as:

    Answer: A business associate requiring a signed BAA

    Any third party that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate and must have a BAA in place.

  7. Which of the following is NOT a required implementation specification under the Contingency Plan standard?

    Answer: Intrusion detection procedure

    Intrusion detection is not part of the contingency plan standard; the required specifications are data backup, disaster recovery, emergency mode operation, testing/revision, and applications/data criticality analysis.