HIPAA Electronic Health Records (EHR) Compliance — Questions and Answers
Question 1: Under HIPAA, which of the following is a primary requirement for electronic health record systems handling Protected Health Information (PHI)?
- Storing all records on local servers only
- Implementing access controls that limit PHI access to authorized users (Correct answer)
- Printing all records daily as a backup
- Sharing EHR login credentials among staff for efficiency
Correct answer: Implementing access controls that limit PHI access to authorized users
HIPAA's Security Rule requires covered entities to implement technical access controls ensuring only authorized individuals can access PHI in electronic form.
HIPAA's Security Rule (45 CFR §164.312) mandates technical safeguards including access controls that allow only authorized persons to access ePHI. This includes unique user identification, emergency access procedures, automatic logoff, and encryption. Sharing credentials is a direct violation because it prevents audit trail accuracy and undermines accountability.
Question 2: A hospital migrates to a new EHR system. What HIPAA requirement applies to PHI stored in the old system?
- It must be immediately deleted upon migration
- It must be retained according to applicable retention laws and securely disposed of when no longer needed (Correct answer)
- It can be transferred to a public cloud without restrictions
- It must be printed and stored in physical files
Correct answer: It must be retained according to applicable retention laws and securely disposed of when no longer needed
HIPAA requires that PHI be retained per applicable state and federal retention laws, and disposed of securely when retention periods expire.
HIPAA does not specify retention periods (state law governs), but it does require that once the retention period expires, PHI must be disposed of in a manner that renders it unreadable or indecipherable. During migration, the covered entity must ensure PHI in legacy systems remains protected. Simply deleting without secure sanitization violates HIPAA's disposal standards.
Question 3: Which HIPAA Security Rule standard directly addresses the integrity of electronic PHI in EHR systems?
- Workforce Security
- Integrity Controls (Correct answer)
- Contingency Planning
- Facility Access Controls
Correct answer: Integrity Controls
Integrity controls are required under the Technical Safeguards section of the Security Rule to ensure ePHI is not improperly altered or destroyed.
Under 45 CFR §164.312(c)(1), covered entities must implement policies and procedures to protect ePHI from improper alteration or destruction. Integrity controls such as checksums, message authentication codes, and audit logs verify that EHR data has not been modified without authorization. This is critical for clinical accuracy and legal defensibility of health records.
Question 4: A physician practice uses a cloud-based EHR platform. Under HIPAA, what document is required between the practice and the EHR vendor?
- A Non-Disclosure Agreement (NDA)
- A Business Associate Agreement (BAA) (Correct answer)
- A Service Level Agreement (SLA) only
- A HIPAA Certification Letter
Correct answer: A Business Associate Agreement (BAA)
When a vendor creates, receives, maintains, or transmits PHI on behalf of a covered entity, a Business Associate Agreement is legally required.
Under 45 CFR §164.308(b)(1), covered entities must obtain satisfactory assurances from business associates — including EHR vendors — through a written Business Associate Agreement. The BAA defines the permitted uses of PHI, requires the vendor to safeguard PHI, and outlines breach notification obligations. Failure to execute a BAA is a direct HIPAA violation.
Question 5: Under HIPAA, an EHR system's audit log must capture which of the following?
- Only unsuccessful login attempts
- User activity including access, modifications, and disclosures of PHI (Correct answer)
- Only administrative changes to the system
- System performance metrics only
Correct answer: User activity including access, modifications, and disclosures of PHI
HIPAA requires audit controls that record and examine activity in systems containing ePHI, including who accessed, modified, or disclosed information.
The Security Rule's Technical Safeguards (45 CFR §164.312(b)) require hardware, software, and procedural mechanisms that record and examine activity in information systems containing ePHI. Comprehensive audit logs capture login/logoff times, records accessed, modifications made, and information disclosed. These logs are essential for detecting unauthorized access and investigating breaches.
Question 6: A covered entity discovers that their EHR vendor experienced a data breach. Under HIPAA, when must the covered entity notify affected patients?
- Within 24 hours of discovery
- Within 60 days of discovery of the breach (Correct answer)
- Within 6 months of the breach
- Only if more than 1,000 patients are affected
Correct answer: Within 60 days of discovery of the breach
HIPAA's Breach Notification Rule requires individual notice to affected patients within 60 days of discovering a breach of unsecured PHI.
Under 45 CFR §164.404, covered entities must notify affected individuals without unreasonable delay and no later than 60 days following discovery of a breach. When a business associate (EHR vendor) discovers a breach, they must notify the covered entity, whose 60-day clock then begins. The notification must include a description of the breach, types of PHI involved, steps individuals can take to protect themselves, and contact information.
Question 7: Which of the following best describes the 'minimum necessary' standard as applied to EHR access?
- All staff should have access to all patient records
- Access to PHI should be limited to the minimum needed to perform a job function (Correct answer)
- Minimum necessary only applies to paper records
- Physicians are exempt from minimum necessary requirements
Correct answer: Access to PHI should be limited to the minimum needed to perform a job function
HIPAA's minimum necessary standard requires that access to PHI be restricted to only what is needed for the specific task or role.
Under 45 CFR §164.514(d), covered entities must make reasonable efforts to limit PHI access to the minimum necessary to accomplish the intended purpose. In EHR systems, this is implemented through role-based access controls — a billing clerk needs billing information but not full clinical notes, while a nurse needs clinical data but not financial records. Physicians are not exempt but are generally granted broader access justified by their treatment role.
Question 8: What is the purpose of automatic logoff in an EHR system under HIPAA?
- To reduce server load during peak hours
- To terminate sessions and prevent unauthorized access after a period of inactivity (Correct answer)
- To generate automatic backup copies of open records
- To log patient satisfaction scores automatically
Correct answer: To terminate sessions and prevent unauthorized access after a period of inactivity
Automatic logoff is an addressable implementation specification under HIPAA that terminates sessions after inactivity to prevent unauthorized access to ePHI.
Automatic logoff is listed under Technical Access Controls (45 CFR §164.312(a)(2)(iii)) as an addressable implementation specification. When a workstation is left unattended, automatic logoff terminates the session, preventing unauthorized persons from accessing ePHI. While 'addressable' means covered entities can implement alternatives, the intent — preventing unauthorized access — must be met through some mechanism.
Question 9: An EHR system must transmit patient data to a referring specialist. Which HIPAA requirement applies to this transmission?
- Transmission is prohibited without patient consent for each transfer
- Encryption must be used to protect ePHI during transmission over open networks (Correct answer)
- Only fax transmission is compliant with HIPAA
- No special requirements apply to internal system transmissions
Correct answer: Encryption must be used to protect ePHI during transmission over open networks
HIPAA's Security Rule requires that ePHI transmitted over open networks be encrypted to protect it from unauthorized interception.
Under 45 CFR §164.312(e)(2)(ii), encryption of ePHI in transit is an addressable implementation specification. When transmitting over open networks (internet, email), encryption is effectively required because no equivalent alternative adequately protects the data. Transmission to a specialist constitutes a treatment disclosure permitted without patient authorization under 45 CFR §164.506, but the technical transmission must still be secured.
Question 10: Which federal law expanded HIPAA's requirements and directly increased compliance obligations for EHR systems?
- The Affordable Care Act (ACA)
- The HITECH Act of 2009 (Correct answer)
- The Medicare Access and CHIP Reauthorization Act (MACRA)
- The Health Information Technology Standards Act
Correct answer: The HITECH Act of 2009
The Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 strengthened HIPAA enforcement and extended requirements to business associates including EHR vendors.
The HITECH Act (part of ARRA 2009) dramatically strengthened HIPAA by: extending Security Rule obligations directly to business associates, creating tiered civil penalties up to $1.9 million per violation category per year, establishing a breach notification mandate, requiring HHS to conduct periodic audits, and incentivizing meaningful use of certified EHR technology. HITECH fundamentally changed the HIPAA enforcement landscape.
Question 11: A covered entity implements a new EHR system. What risk analysis requirement does HIPAA impose before go-live?
- A risk analysis is only required after a breach occurs
- A thorough assessment of potential risks and vulnerabilities to ePHI must be conducted (Correct answer)
- Risk analysis is optional for systems under 500 users
- Only the EHR vendor is responsible for risk analysis
Correct answer: A thorough assessment of potential risks and vulnerabilities to ePHI must be conducted
HIPAA requires covered entities to conduct a thorough risk analysis to identify threats and vulnerabilities to ePHI before and throughout system operation.
45 CFR §164.308(a)(1)(ii)(A) requires covered entities to conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. This is a Required implementation specification. Before deploying a new EHR, organizations must analyze threats (malware, unauthorized access, natural disasters), assess vulnerabilities, and implement appropriate risk management measures. This analysis must be documented and regularly updated.
Question 12: Under HIPAA, which of the following represents appropriate de-identification of patient data in an EHR export?
- Replacing patient names with initials
- Removing all 18 HIPAA-defined identifiers or applying statistical methods to achieve de-identification (Correct answer)
- Encrypting the file before sharing
- Requiring a BAA with any recipient
Correct answer: Removing all 18 HIPAA-defined identifiers or applying statistical methods to achieve de-identification
HIPAA provides two methods for de-identification: removal of all 18 specified identifiers (Safe Harbor) or expert statistical determination that re-identification risk is very small.
Under 45 CFR §164.514(b), de-identified information is not PHI and falls outside HIPAA's protections. The Safe Harbor method requires removal of 18 specific identifiers (names, geographic subdivisions smaller than state, dates except year, ages over 89, phone numbers, etc.) and no actual knowledge of re-identification risk. The Expert Determination method requires a statistician to certify that re-identification risk is very small. Partial de-identification (e.g., just removing names) does not meet HIPAA standards.
Question 13: What does HIPAA require regarding contingency planning for EHR systems?
- Contingency plans are only required for hospitals
- Covered entities must have data backup, disaster recovery, and emergency mode operation plans (Correct answer)
- EHR vendors are solely responsible for contingency planning
- A contingency plan is needed only if the organization has over 100 employees
Correct answer: Covered entities must have data backup, disaster recovery, and emergency mode operation plans
HIPAA's Security Rule requires organizations to develop contingency plans including data backup, disaster recovery, and emergency mode operation procedures.
45 CFR §164.308(a)(7) requires covered entities to establish policies for responding to emergencies damaging systems containing ePHI. Required specifications include: data backup plan (retrievable exact copies of ePHI), disaster recovery plan (restoring lost data), and emergency mode operation plan (maintaining PHI access during emergencies). Addressable specifications include testing/revision procedures and application and data criticality analysis. All healthcare organizations using EHRs must comply regardless of size.
Question 14: A patient requests access to their EHR records. Under HIPAA, what is the covered entity's obligation?
- Patients have no right to EHR records, only paper records
- The covered entity must provide access within 30 days, with a possible 30-day extension (Correct answer)
- Records must be provided within 72 hours regardless of format
- Access can be denied if records are stored electronically
Correct answer: The covered entity must provide access within 30 days, with a possible 30-day extension
HIPAA's Privacy Rule gives patients the right to access their PHI, including electronic records, within 30 days with a permitted 30-day extension.
Under 45 CFR §164.524, individuals have the right to access and receive copies of their PHI in designated record sets, including EHRs. Covered entities must act on requests within 30 days; if unable to meet this deadline, one 30-day extension is permitted with written notice. Under the 2020 updates (21st Century Cures Act interoperability rules), covered entities must provide electronic PHI in the format requested if readily producible, and fees must be reasonable and cost-based.
Question 15: Which of the following is NOT a required element of a HIPAA Security Rule risk management implementation?
- Implementing security measures to reduce risks to a reasonable and appropriate level
- Regular review of security measures
- Eliminating all identified risks completely (Correct answer)
- Documenting the risk management process
Correct answer: Eliminating all identified risks completely
HIPAA requires reducing risks to a reasonable and appropriate level, not eliminating all risks — complete risk elimination is not feasible or required.
45 CFR §164.308(a)(1)(ii)(B) requires implementation of security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level. HIPAA recognizes that no system is perfectly secure; the standard is whether risks have been adequately managed given the organization's size, complexity, capabilities, and the nature of the threats. Required elements include implementing controls, regular review, and documentation — but complete risk elimination is neither required nor achievable.
Question 16: An EHR vendor uses a subcontractor to provide data storage. Under HIPAA, what is required?
- The covered entity must directly contract with the subcontractor
- The business associate (EHR vendor) must obtain a BAA from the subcontractor (Correct answer)
- No BAA is needed if the subcontractor is located in the same country
- Subcontractors handling ePHI are exempt from HIPAA
Correct answer: The business associate (EHR vendor) must obtain a BAA from the subcontractor
Under HITECH and HIPAA, business associates must obtain BAAs from their subcontractors who create, receive, maintain, or transmit PHI on their behalf.
The HITECH Act established that business associates' subcontractors who create, receive, maintain, or transmit PHI on behalf of the business associate are themselves business associates subject to HIPAA. Under 45 CFR §164.308(b)(2), business associates must ensure that subcontractors agree to the same restrictions and conditions through a BAA. This extends the chain of HIPAA accountability through all levels of the service delivery chain.
Question 17: What is the significance of 'meaningful use' as it relates to HIPAA and EHR compliance?
- It is a HIPAA Privacy Rule requirement for all covered entities
- It is a Medicare/Medicaid incentive program promoting certified EHR adoption with specific security criteria (Correct answer)
- It requires all providers to use the same EHR software platform
- Meaningful use is a state-level program with no federal connection
Correct answer: It is a Medicare/Medicaid incentive program promoting certified EHR adoption with specific security criteria
Meaningful use (now 'Promoting Interoperability') was a CMS incentive program under HITECH that required use of certified EHR technology meeting specific security and interoperability criteria.
The HITECH Act authorized CMS to create the Medicare and Medicaid EHR Incentive Programs (Meaningful Use). To qualify for incentive payments, providers must use certified EHR technology, meet security risk analysis requirements, and demonstrate use of EHR features that improve care quality. While not directly a HIPAA program, Meaningful Use/Promoting Interoperability reinforces HIPAA Security Rule compliance as a condition for incentive payments and avoids downward payment adjustments.
Question 18: Under HIPAA, which practice regarding EHR passwords is explicitly prohibited?
- Using complex passwords with uppercase, numbers, and symbols
- Sharing login credentials among colleagues to allow coverage during absences (Correct answer)
- Requiring password changes every 90 days
- Using a password manager for complex passwords
Correct answer: Sharing login credentials among colleagues to allow coverage during absences
Sharing login credentials violates HIPAA's requirement for unique user identification, which is essential for accountability and audit trail integrity.
45 CFR §164.312(a)(2)(i) requires unique user identification as a Required implementation specification under the Access Controls standard. Each user must have a unique identifier (user ID) so their activity in EHR systems can be tracked individually. Sharing credentials makes it impossible to determine which individual accessed PHI, destroying audit trail validity, undermining accountability, and making breach investigations impossible. This is one of the most commonly cited HIPAA violations.
Question 19: A covered entity wants to interface their EHR with a health information exchange (HIE). What HIPAA consideration applies?
- HIPAA prohibits participation in health information exchanges
- A BAA must be executed with the HIE, and the interface must maintain ePHI security (Correct answer)
- Patient authorization is always required for HIE participation
- HIEs are exempt from HIPAA as they are non-profit organizations
Correct answer: A BAA must be executed with the HIE, and the interface must maintain ePHI security
HIEs that handle PHI on behalf of covered entities are business associates requiring BAAs, and all ePHI transmitted to/from the HIE must be secured.
Health Information Exchanges are business associates under HIPAA when they create, receive, maintain, or transmit PHI on behalf of covered entities. A BAA must be executed before connecting any EHR system to an HIE. The interface must use encrypted, authenticated connections. While HIPAA permits sharing PHI for treatment purposes (45 CFR §164.506) without individual authorization in most cases, the technical and contractual safeguards must still be in place. Some states have additional consent requirements for HIE participation.
Question 20: What is the HIPAA requirement for workforce training on EHR security?
- Training is only required for IT staff
- All workforce members with access to EHR systems must receive security awareness training (Correct answer)
- Training is required once at hire and never again
- HIPAA does not address workforce training
Correct answer: All workforce members with access to EHR systems must receive security awareness training
HIPAA's Security Rule requires security awareness and training for all workforce members, including periodic updates and reminders.
45 CFR §164.308(a)(5) requires covered entities to implement a security awareness and training program for all workforce members. This includes periodic security reminders, training on malicious software protection (phishing, ransomware), log-in monitoring, and password management. The training requirement applies to everyone with EHR access — from physicians and nurses to administrative staff. Training must be documented and should be updated when new threats emerge or when system changes occur.
Question 21: Which of the following EHR scenarios constitutes a potential HIPAA Security Rule violation?
- Encrypting all ePHI at rest and in transit
- Allowing a terminated employee's credentials to remain active for two weeks post-termination (Correct answer)
- Conducting quarterly security risk reviews
- Requiring multi-factor authentication for remote EHR access
Correct answer: Allowing a terminated employee's credentials to remain active for two weeks post-termination
Allowing terminated employees to retain active EHR access violates the Workforce Clearance procedure requirement and creates unauthorized access risk.
45 CFR §164.308(a)(3)(ii)(C) requires procedures for terminating access to ePHI when employment ends. Active credentials for terminated employees represent a serious security risk — the individual no longer has a business need for PHI access, may have grievances against the organization, and their continued access creates an unauthorized access condition. HIPAA audits routinely check for timely deactivation of user accounts upon termination. This is a Required implementation specification.
Question 22: When implementing role-based access control (RBAC) in an EHR under HIPAA, what principle should govern access assignments?
- Assign maximum access to minimize workflow disruption
- Grant access based on minimum necessary requirements for each role (Correct answer)
- All clinical staff should share a single role with full access
- Access levels should be determined by seniority
Correct answer: Grant access based on minimum necessary requirements for each role
RBAC should be designed around the minimum necessary standard — each role gets access only to the PHI required to perform its functions.
The minimum necessary standard (45 CFR §164.514(d)) requires covered entities to make reasonable efforts to limit PHI access to what is needed for specific roles or tasks. In RBAC implementation, this means defining each role's access based on actual job functions: billing staff need demographic and insurance data; clinical staff need clinical notes; pharmacists need medication lists; administrators may need aggregate data. Assigning maximum access 'just in case' violates both the spirit and letter of HIPAA.
Question 23: A covered entity's EHR is hosted by a SaaS vendor that stores data in multiple international data centers. What HIPAA implication does this create?
- International data storage is automatically HIPAA-compliant
- The BAA must address data stored internationally, as HIPAA applies regardless of where PHI is stored (Correct answer)
- International storage is prohibited under HIPAA
- Only data stored in EU-compliant data centers requires a BAA
Correct answer: The BAA must address data stored internationally, as HIPAA applies regardless of where PHI is stored
HIPAA applies to covered entities and business associates regardless of where PHI is stored; the BAA must address international storage and ensure equivalent protections.
HIPAA does not prohibit international data storage, but it also does not stop applying when data crosses borders. The covered entity remains responsible for ensuring HIPAA compliance for all PHI, wherever it resides. The BAA with the SaaS vendor must explicitly address international storage, requiring that data protection standards meet or exceed HIPAA requirements in all jurisdictions where data is stored. International breaches still trigger HIPAA's breach notification requirements. This is an increasingly common consideration with cloud EHR adoption.
Question 24: Under HIPAA, what must be included in an EHR system's incident response plan?
- Procedures for identifying, responding to, and mitigating security incidents involving ePHI (Correct answer)
- Only procedures for natural disaster recovery
- Incident response is only required for organizations with over 500 employees
- A plan to notify the media within 24 hours of any incident
Correct answer: Procedures for identifying, responding to, and mitigating security incidents involving ePHI
HIPAA's Security Rule requires documented incident response procedures covering identification, containment, eradication, recovery, and reporting of security incidents.
45 CFR §164.308(a)(6) requires implementation of policies and procedures to address security incidents — defined as attempted or successful unauthorized access, use, disclosure, modification, or destruction of ePHI. The incident response plan must include procedures for identifying incidents, documenting them, mitigating harmful effects, and reporting to appropriate parties. A breach (as defined under 45 CFR §164.402) triggers additional notification requirements. All incidents, even those not meeting breach thresholds, must be documented.
Question 25: What HIPAA requirement applies when an EHR system undergoes a significant software update or patch?
- No HIPAA review is needed for vendor-provided updates
- The covered entity should assess whether the update affects ePHI security and update risk analysis accordingly (Correct answer)
- System updates must be reported to HHS within 30 days
- Only security patches require HIPAA review; feature updates do not
Correct answer: The covered entity should assess whether the update affects ePHI security and update risk analysis accordingly
Material changes to EHR systems can affect ePHI security; HIPAA requires review and updating of risk analysis and security policies when significant changes occur.
HIPAA's risk analysis requirement (45 CFR §164.308(a)(1)) is not a one-time event but an ongoing process. When significant changes occur — such as major software updates, new interfaces, infrastructure changes, or security patches — the covered entity must reassess how these changes affect ePHI risks. A new feature might introduce new vulnerabilities; a patch might close critical ones. Risk analyses must be updated to reflect current system states, and security policies and procedures updated accordingly.
Question 26: Which type of EHR access log review is considered a best practice for HIPAA compliance?
- Review logs only when a patient complains
- Regularly reviewing audit logs proactively to identify unusual access patterns or potential breaches (Correct answer)
- Delegate all log review to the EHR vendor
- Logs only need review during annual HIPAA audits
Correct answer: Regularly reviewing audit logs proactively to identify unusual access patterns or potential breaches
Proactive regular review of EHR audit logs helps detect unauthorized access, snooping, and potential breaches before they escalate.
45 CFR §164.308(a)(1)(ii)(D) requires an information system activity review — regular review of logs of information system activity such as audit logs, access reports, and security incident tracking. While HIPAA does not specify review frequency, HHS and industry guidance recommends periodic automated monitoring supplemented by manual review for anomalous patterns (e.g., a staff member accessing records of family members, VIP patients, or high volumes of unrelated patients). Celebrity snooping cases have resulted in multi-million-dollar settlements.
Question 27: A provider wants to use voice recognition software with their EHR for documentation. What HIPAA consideration applies?
- Voice recognition tools are exempt from HIPAA as they are input devices
- The voice recognition vendor must execute a BAA and the software must meet Security Rule requirements (Correct answer)
- Only written documentation requires HIPAA protection
- Voice data is not PHI because it does not include direct patient records
Correct answer: The voice recognition vendor must execute a BAA and the software must meet Security Rule requirements
Voice recognition software that processes PHI-containing dictation is a business associate, requiring a BAA and adherence to Security Rule requirements.
Voice recognition software used for clinical documentation processes PHI (patient names, diagnoses, treatment information) on behalf of the covered entity, making the vendor a business associate. A BAA is required. The software must also meet Security Rule standards: audio data containing PHI must be transmitted securely and stored with appropriate access controls. Cloud-based voice recognition that transmits audio to remote servers requires encryption in transit. Local processing solutions must still be assessed for data storage security.
Question 28: What is required under HIPAA when an EHR system is taken out of service or decommissioned?
- Simply powering off the system fulfills HIPAA requirements
- All PHI must be securely disposed of or transferred to a compliant system before decommissioning (Correct answer)
- Decommissioning requires advance notice to all patients
- The decommissioned system must be donated to a non-profit
Correct answer: All PHI must be securely disposed of or transferred to a compliant system before decommissioning
HIPAA requires secure disposal of PHI when decommissioning systems, ensuring patient data cannot be recovered from retired hardware or software.
45 CFR §164.310(d)(2)(i) requires policies and procedures to address the final disposition of ePHI and the hardware or electronic media on which it is stored. For decommissioned EHR systems, covered entities must either: transfer PHI to a new compliant system, or permanently destroy PHI on the old system using NIST-approved methods (overwriting, degaussing, physical destruction). Proper decommissioning procedures should be documented. Failure to properly dispose of PHI on old hardware has led to significant HIPAA enforcement actions.
Question 29: Under HIPAA, which of the following best describes the responsibility for EHR security in a small physician practice using a third-party EHR?
- The EHR vendor assumes all HIPAA responsibility once a contract is signed
- The physician practice remains the covered entity and retains HIPAA responsibility for PHI regardless of the EHR vendor used (Correct answer)
- Small practices with under 10 physicians are exempt from EHR security requirements
- Responsibility transfers entirely to the EHR vendor upon data upload
Correct answer: The physician practice remains the covered entity and retains HIPAA responsibility for PHI regardless of the EHR vendor used
Covered entity status and HIPAA responsibility remain with the physician practice; vendors are business associates who share compliance obligations but cannot relieve the practice of its duties.
Covered entity status is determined by the nature of the organization (healthcare provider, health plan, healthcare clearinghouse), not by whether they outsource IT functions. A physician practice remains a covered entity and bears primary HIPAA responsibility for PHI in their designated record sets. While EHR vendors as business associates take on contractual and direct HIPAA obligations, the covered entity cannot delegate away its own compliance duties. This includes ensuring the BAA is in place, monitoring vendor performance, and conducting its own risk analysis.
Question 30: What is the purpose of the HIPAA Security Rule's 'addressable' implementation specification designation for EHR systems?
- Addressable specifications are optional and may be ignored
- Organizations must either implement the specification or document why an alternative measure achieves the same security objective (Correct answer)
- Addressable means the specification addresses only small organizations
- Only IT-certified staff may determine whether addressable specifications apply
Correct answer: Organizations must either implement the specification or document why an alternative measure achieves the same security objective
Addressable specifications require organizations to either implement them or document a reasonable alternative that achieves the equivalent security objective.
HIPAA Security Rule implementation specifications are categorized as Required or Addressable. Required specifications must be implemented as stated. Addressable specifications (45 CFR §164.306(d)(3)) require the covered entity to assess whether the specification is reasonable and appropriate given their environment; if so, implement it; if not, document why and implement an equivalent alternative. For EHRs, addressable specifications include automatic logoff, encryption in transit, and certain audit functions. The documentation of reasoning is itself a compliance requirement.
Question 31: A hospital EHR system is hit by ransomware. Under HIPAA, what is this event presumed to be?
- A minor technical incident not requiring notification
- A breach of unsecured PHI unless the organization can demonstrate a low probability that PHI was compromised (Correct answer)
- Only a breach if patient data was actually exported
- An internal security incident not covered by HIPAA's breach notification rule
Correct answer: A breach of unsecured PHI unless the organization can demonstrate a low probability that PHI was compromised
HHS guidance states that ransomware involving ePHI is presumed to be a breach, requiring notification unless a four-factor risk assessment shows low probability of PHI compromise.
In 2016, HHS OCR issued guidance stating that a ransomware attack is generally a security incident under HIPAA and is presumed to be a breach of unsecured PHI unless the covered entity or business associate can demonstrate through a documented four-factor risk assessment that there is a low probability that PHI was compromised. The four factors are: nature and extent of PHI involved, who accessed or could have accessed it, whether PHI was actually acquired or viewed, and extent to which risk has been mitigated. If low probability cannot be demonstrated, breach notification is required.
Question 32: Which HIPAA requirement addresses the physical security of workstations used to access EHR systems?
- Physical Safeguards — Workstation Use and Workstation Security (Correct answer)
- Administrative Safeguards — Workforce Security
- Technical Safeguards — Access Controls
- Privacy Rule — Minimum Necessary Standard
Correct answer: Physical Safeguards — Workstation Use and Workstation Security
HIPAA's Physical Safeguards include Workstation Use and Workstation Security standards governing the physical positioning and protection of EHR access devices.
45 CFR §164.310(b) (Workstation Use) and §164.310(c) (Workstation Security) require covered entities to implement physical safeguards for workstations accessing ePHI. This includes positioning screens away from public view, using privacy screens, restricting physical access to workstations to authorized personnel, and implementing physical locks. Workstation policies must specify authorized functions and manner of use. These physical safeguards complement technical controls like automatic logoff and session timeouts.
Question 33: Under HIPAA, who bears compliance responsibility when a covered entity uses a cloud EHR service and the cloud provider subcontracts storage to another company?
- Only the original EHR vendor bears responsibility
- The covered entity, EHR vendor (BA), and storage subcontractor (sub-BA) each bear HIPAA compliance responsibilities (Correct answer)
- The subcontractor is exempt as a utility provider
- Compliance responsibility lies solely with the covered entity
Correct answer: The covered entity, EHR vendor (BA), and storage subcontractor (sub-BA) each bear HIPAA compliance responsibilities
Under HITECH, the chain of HIPAA compliance extends through subcontractors — each entity handling PHI bears its own compliance responsibilities.
Following the HITECH Act and the 2013 Omnibus Rule, HIPAA compliance responsibilities extend through the entire subcontracting chain. The covered entity must have a BAA with the EHR vendor (BA). The EHR vendor must have a BAA with the storage subcontractor (sub-BA). Each entity in the chain bears direct HIPAA obligations — OCR can audit and penalize business associates and their subcontractors directly, not just covered entities. All entities must implement Security Rule safeguards, regardless of whether they have direct patient relationships.
Question 34: What HIPAA safeguard addresses the process of verifying that ePHI has not been altered without authorization in an EHR?
- Availability controls
- Integrity controls including checksums and hash verification (Correct answer)
- Confidentiality agreements
- Access log monitoring
Correct answer: Integrity controls including checksums and hash verification
HIPAA's integrity controls verify that ePHI has not been improperly altered or destroyed through mechanisms like checksums, digital signatures, and hash verification.
45 CFR §164.312(c)(2) addresses integrity controls as an addressable implementation specification, requiring electronic mechanisms to corroborate that ePHI has not been altered or destroyed in an unauthorized manner. In EHR systems, this is implemented through: cryptographic hash functions applied to record sets, digital signatures on documents, database integrity checks, and version control/audit trails showing all modifications. These controls are critical for legal defensibility of EHR records — a medical record whose integrity cannot be verified may be challenged in litigation.
Question 35: A covered entity discovers their EHR vendor experienced a data breach affecting 550 patients. What are ALL the required notification steps?
- Notify affected patients only
- Notify affected patients, HHS, and (due to exceeding 500 in a state) potentially local media within required timeframes (Correct answer)
- Notify HHS only, as the vendor is responsible for patient notification
- No notification is required unless more than 1,000 patients are affected
Correct answer: Notify affected patients, HHS, and (due to exceeding 500 in a state) potentially local media within required timeframes
Breaches affecting 500+ individuals require notification to affected patients, HHS (within 60 days), and prominent media outlets in affected states.
Under 45 CFR §164.406, when a breach affects 500 or more residents of a state or jurisdiction, the covered entity must notify prominent media outlets serving that area (in addition to individual notification). Under 45 CFR §164.408, HHS must be notified without unreasonable delay and no later than 60 days after discovery for breaches affecting 500+ individuals (versus annual reporting for smaller breaches). The covered entity (not the vendor) is responsible for all notifications, though the vendor's breach triggers the covered entity's obligations.
Question 36: Which of the following best describes a 'designated record set' in the context of EHR systems and HIPAA patient access rights?
- Only records created by the treating physician
- Medical and billing records used to make decisions about individuals, including EHR data (Correct answer)
- Administrative records such as staff scheduling
- Records held by insurance companies only
Correct answer: Medical and billing records used to make decisions about individuals, including EHR data
A designated record set includes medical records, billing records, and any other records used to make decisions about an individual, including EHR data.
45 CFR §164.501 defines a designated record set as: medical records and billing records about individuals maintained by a covered healthcare provider; enrollment, payment, claims adjudication, and case/medical management records maintained by a health plan; or other records used to make decisions about individuals. For EHR purposes, this includes clinical documentation, test results, medication lists, encounter notes, and billing information. Patients have the right to access and request amendment of their designated record set. Administrative records like staff notes about a patient used for operational purposes (not treatment decisions) may be excluded.
Under HIPAA, which of the following is a primary requirement for electronic health record systems handling Protected Health Information (PHI)?