โ† All HIPAA Flashcard Decks

Electronic Health Records (EHR) Compliance Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Electronic Health Records (EHR) Compliance flashcards as text
  1. Under HIPAA, which technical safeguard must EHR systems implement to prevent unauthorized access to ePHI during transmission?

    Answer: End-to-end encryption

    HIPAA requires encryption of ePHI during transmission to prevent interception by unauthorized parties.

  2. A covered entity discovers that a business associate's EHR integration has been exposing ePHI for 60 days. What is the first required action?

    Answer: Conduct a risk assessment to determine breach scope

    The first step after discovering a potential breach is conducting a risk assessment to determine whether a reportable breach occurred.

  3. Which HIPAA rule specifically governs the electronic transmission of health information between covered entities?

    Answer: Transactions and Code Sets Rule

    The Transactions and Code Sets Rule requires covered entities to use standard formats (ASC X12) when exchanging health information electronically.

  4. An EHR vendor patches a known vulnerability in their software. Under HIPAA, what must a covered entity do before deploying the patch in a production environment?

    Answer: Test the patch and document the risk analysis

    HIPAA's Security Rule requires covered entities to evaluate and document security patches as part of their risk management process before deployment.

  5. What is the HIPAA requirement regarding minimum necessary access to EHR data for workforce members?

    Answer: Access should be limited to the minimum necessary to perform job functions

    The minimum necessary standard requires covered entities to limit ePHI access to only what is needed for each workforce member's role.

  6. Under the HIPAA Security Rule, how long must audit logs from an EHR system be retained?

    Answer: 6 years

    HIPAA requires that security documentation, including audit logs, be retained for at least 6 years from the date of creation or last effective date.

  7. A hospital's EHR system allows patients to download their records via a patient portal. Under HIPAA, within what timeframe must the hospital fulfill a patient's electronic access request?

    Answer: 30 days

    HIPAA requires covered entities to provide access to ePHI within 30 days of a patient request, with one possible 30-day extension.