← All HIPAA Flashcard Decks

The HIPAA Security Rule Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 The HIPAA Security Rule flashcards as text
  1. Which of the following is an example of a physical safeguard under the HIPAA Security Rule?

    Answer: Facility access controls

    Physical safeguards include facility access controls, workstation use policies, and device and media controls to protect physical access to ePHI.

  2. What is the primary purpose of a Risk Analysis under the HIPAA Security Rule?

    Answer: To identify and assess vulnerabilities to ePHI confidentiality, integrity, and availability

    A Risk Analysis identifies potential threats and vulnerabilities to ePHI so covered entities can implement appropriate safeguards.

  3. Under the HIPAA Security Rule, which standard requires covered entities to have policies for responding to a security incident?

    Answer: Security Incident Procedures

    The Security Incident Procedures standard requires covered entities to identify, respond to, mitigate, and document security incidents involving ePHI.

  4. A hospital uses an automatic logoff feature that locks workstations after 10 minutes of inactivity. This is an example of which type of safeguard?

    Answer: Technical safeguard

    Automatic logoff is a technical safeguard that prevents unauthorized access to ePHI on idle workstations.

  5. Which of the following best describes an 'addressable' implementation specification under the Security Rule?

    Answer: It must be implemented, or a documented alternative must be adopted if reasonable and appropriate

    Addressable specifications require covered entities to assess whether implementation is reasonable and appropriate, and to document their decision either way.

  6. What type of safeguard includes policies and procedures for creating and maintaining retrievable exact copies of ePHI?

    Answer: Administrative safeguard — Contingency Plan

    The Contingency Plan standard under Administrative Safeguards includes the required Data Backup Plan, which ensures retrievable copies of ePHI.

  7. Which entity is directly required to comply with the HIPAA Security Rule?

    Answer: Covered entities and their business associates

    The Security Rule applies directly to covered entities (health plans, providers, clearinghouses) and their business associates.