HIPAA Electronic Health Records (EHR) Compliance 2 — Questions and Answers
Question 1: Under HIPAA, which technical safeguard must EHR systems implement to prevent unauthorized access to ePHI during transmission?
- End-to-end encryption (Correct answer)
- Password complexity requirements
- Audit logging
- Automatic logoff
Correct answer: End-to-end encryption
HIPAA requires encryption of ePHI during transmission to prevent interception by unauthorized parties.
Question 2: A covered entity discovers that a business associate's EHR integration has been exposing ePHI for 60 days. What is the first required action?
- Terminate the BAA immediately
- Conduct a risk assessment to determine breach scope (Correct answer)
- Notify HHS within 24 hours
- Notify all affected patients within 24 hours
Correct answer: Conduct a risk assessment to determine breach scope
The first step after discovering a potential breach is conducting a risk assessment to determine whether a reportable breach occurred.
Question 3: Which HIPAA rule specifically governs the electronic transmission of health information between covered entities?
- Privacy Rule
- Security Rule
- Transactions and Code Sets Rule (Correct answer)
- Enforcement Rule
Correct answer: Transactions and Code Sets Rule
The Transactions and Code Sets Rule requires covered entities to use standard formats (ASC X12) when exchanging health information electronically.
Question 4: An EHR vendor patches a known vulnerability in their software. Under HIPAA, what must a covered entity do before deploying the patch in a production environment?
- Notify HHS of the vulnerability
- Test the patch and document the risk analysis (Correct answer)
- Obtain patient consent for the update
- Update the Notice of Privacy Practices
Correct answer: Test the patch and document the risk analysis
HIPAA's Security Rule requires covered entities to evaluate and document security patches as part of their risk management process before deployment.
Question 5: What is the HIPAA requirement regarding minimum necessary access to EHR data for workforce members?
- All staff must have full access to treat patients effectively
- Access should be limited to the minimum necessary to perform job functions (Correct answer)
- Access levels are set by the EHR vendor, not the covered entity
- Only physicians may access complete patient records
Correct answer: Access should be limited to the minimum necessary to perform job functions
The minimum necessary standard requires covered entities to limit ePHI access to only what is needed for each workforce member's role.
Question 6: Under the HIPAA Security Rule, how long must audit logs from an EHR system be retained?
- 1 year
- 3 years
- 6 years (Correct answer)
- 10 years
Correct answer: 6 years
HIPAA requires that security documentation, including audit logs, be retained for at least 6 years from the date of creation or last effective date.
Question 7: A hospital's EHR system allows patients to download their records via a patient portal. Under HIPAA, within what timeframe must the hospital fulfill a patient's electronic access request?
- 24 hours
- 15 days
- 30 days (Correct answer)
- 60 days
Correct answer: 30 days
HIPAA requires covered entities to provide access to ePHI within 30 days of a patient request, with one possible 30-day extension.
Under HIPAA, which technical safeguard must EHR systems implement to prevent unauthorized access to ePHI during transmission?