HIPAA Technical & Physical Safeguards 4 — Questions and Answers
Question 1: Under HIPAA's Facility Access Controls standard, the 'maintenance records' specification requires covered entities to document:
- Software patches applied to ePHI systems
- Repairs and modifications to physical security components of a facility (Correct answer)
- Annual physical security risk assessments
- Fire suppression system inspections
Correct answer: Repairs and modifications to physical security components of a facility
Maintenance records capture repairs and modifications to physical security components — such as locks, doors, or alarms — that protect facilities housing ePHI.
Question 2: A covered entity uses badge readers, security cameras, and security guards to protect its data center. Together, these controls satisfy which HIPAA safeguard standard?
- Workstation Security
- Facility Access Controls (Correct answer)
- Device and Media Controls
- Audit Controls
Correct answer: Facility Access Controls
Facility Access Controls include physical and procedural measures — such as badge readers, cameras, and guards — that limit access to facilities housing ePHI systems.
Question 3: Which HIPAA Technical Safeguard standard requires that covered entities implement hardware, software, or procedural mechanisms to record and examine activity in systems containing ePHI?
- Access Control
- Transmission Security
- Audit Controls (Correct answer)
- Integrity
Correct answer: Audit Controls
Audit Controls require mechanisms to record and examine access and other activity in systems that create, maintain, or transmit ePHI.
Question 4: A hospital disposes of old hard drives by destroying them physically. This practice is required under which HIPAA specification?
- Data Backup Plan
- Disposal — Device and Media Controls (Correct answer)
- Facility Access Controls — Contingency Operations
- Workstation Security
Correct answer: Disposal — Device and Media Controls
The Disposal specification under Device and Media Controls requires that ePHI be removed from electronic media before disposal, through destruction or other approved methods.
Question 5: An organization allows employees to access ePHI through a VPN with TLS encryption. Which technical safeguard standard does this most directly satisfy?
- Person or Entity Authentication
- Access Control
- Transmission Security (Correct answer)
- Integrity
Correct answer: Transmission Security
Transmission Security requires guarding ePHI from unauthorized access during electronic transmission; encrypted VPN tunnels satisfy this standard.
Question 6: Under the Workstation Security specification, covered entities must implement physical safeguards for all workstations that access ePHI. What does this primarily involve?
- Installing antivirus software on each workstation
- Restricting physical access to workstations to authorized users only (Correct answer)
- Encrypting data at rest on each workstation
- Requiring strong passwords on all workstations
Correct answer: Restricting physical access to workstations to authorized users only
Workstation Security focuses on physical safeguards — such as cable locks, privacy screens, and restricted areas — to prevent unauthorized physical access to workstations.
Question 7: Which HIPAA implementation specification supports emergency access to ePHI when normal access controls are unavailable?
- Unique User Identification
- Emergency Access Procedure (Correct answer)
- Automatic Logoff
- Contingency Operations
Correct answer: Emergency Access Procedure
Emergency Access Procedure is a required implementation specification under the Access Control standard that establishes how to access ePHI during emergency situations.
Under HIPAA's Facility Access Controls standard, the 'maintenance records' specification requires covered entities to document: