HIPAA Electronic Health Records (EHR) Compliance 3 — Questions and Answers
Question 1: Which of the following is an example of an addressable implementation specification under the HIPAA Security Rule for EHR systems?
- Unique user identification
- Encryption of ePHI at rest (Correct answer)
- Emergency access procedure
- Audit controls
Correct answer: Encryption of ePHI at rest
Encryption of ePHI at rest is an addressable specification, meaning covered entities must implement it or document why an equivalent alternative is used.
Question 2: A medical practice uses a cloud-based EHR. Which document must exist between the practice and the cloud provider before ePHI is stored?
- Notice of Privacy Practices
- Business Associate Agreement (Correct answer)
- Data Sharing Protocol
- End User License Agreement
Correct answer: Business Associate Agreement
A Business Associate Agreement (BAA) is required before a covered entity shares ePHI with any third-party vendor, including cloud EHR providers.
Question 3: Under HIPAA, what constitutes a breach involving an EHR when an employee accesses the record of a celebrity patient out of curiosity?
- It is not a breach if no data was copied or shared
- It is a breach only if the employee tells someone
- It is a presumed breach unless the covered entity can show low probability of compromise (Correct answer)
- It is only a breach if the patient files a complaint
Correct answer: It is a presumed breach unless the covered entity can show low probability of compromise
Any unauthorized access to ePHI is presumed a breach under HIPAA unless the covered entity performs a four-factor risk assessment showing low probability of compromise.
Question 4: Which federal agency is responsible for enforcing HIPAA compliance related to EHR security?
- Centers for Medicare & Medicaid Services (CMS)
- Office for Civil Rights (OCR) (Correct answer)
- Food and Drug Administration (FDA)
- Office of the National Coordinator for Health IT (ONC)
Correct answer: Office for Civil Rights (OCR)
The HHS Office for Civil Rights (OCR) is the primary enforcement agency for HIPAA Privacy and Security Rule violations.
Question 5: A nurse logs into an EHR workstation and steps away without logging out. Which HIPAA technical safeguard addresses this risk?
- Unique user identification
- Automatic logoff (Correct answer)
- Emergency access procedure
- Encryption
Correct answer: Automatic logoff
Automatic logoff is a HIPAA-required technical safeguard that terminates an EHR session after a period of inactivity to prevent unauthorized access.
Question 6: A covered entity migrates from one EHR system to another. What must happen to the ePHI stored in the legacy system?
- It must be deleted immediately after migration
- It must be retained according to applicable law and HIPAA requirements (Correct answer)
- It must be archived in unencrypted format for easy access
- It must be transferred to patients before decommissioning
Correct answer: It must be retained according to applicable law and HIPAA requirements
ePHI in a legacy EHR must be retained per applicable state law and HIPAA's 6-year documentation requirement, not simply deleted after migration.
Question 7: Which type of EHR access control ensures that a pharmacist can view medication records but not mental health notes?
- Two-factor authentication
- Role-based access control (Correct answer)
- Biometric identification
- Single sign-on
Correct answer: Role-based access control
Role-based access control (RBAC) restricts access to specific EHR data types based on a user's defined role, implementing HIPAA's minimum necessary standard.
Which of the following is an example of an addressable implementation specification under the HIPAA Security Rule for EHR systems?