HIPAA Technical & Physical Safeguards 5 — Questions and Answers
Question 1: Under HIPAA, which of the following best distinguishes 'required' from 'addressable' implementation specifications?
- Required specs must be implemented; addressable specs must be assessed and either implemented or documented as to why they are not reasonable (Correct answer)
- Required specs apply to covered entities; addressable specs apply only to business associates
- Required specs relate to technical safeguards; addressable specs relate to physical safeguards
- Required specs are mandatory for hospitals; addressable specs are mandatory for health plans
Correct answer: Required specs must be implemented; addressable specs must be assessed and either implemented or documented as to why they are not reasonable
Required specifications must be implemented as stated; addressable specifications require a risk-based assessment and either implementation or documented justification for an alternative measure.
Question 2: A covered entity's access control policy assigns each employee a role (e.g., nurse, biller) and grants ePHI access based on that role. This implements which type of access control model?
- Discretionary Access Control (DAC)
- Role-Based Access Control (RBAC) (Correct answer)
- Mandatory Access Control (MAC)
- Attribute-Based Access Control (ABAC)
Correct answer: Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) restricts system access based on a user's organizational role, which aligns with HIPAA's minimum necessary principle.
Question 3: A health system's security officer discovers that a former employee's access credentials were not disabled after termination. Which HIPAA technical safeguard was violated?
- Transmission Security
- Audit Controls
- Access Control — Unique User Identification (Correct answer)
- Person or Entity Authentication
Correct answer: Access Control — Unique User Identification
Unique User Identification requires that access credentials are managed per individual, including timely revocation when employment ends.
Question 4: A covered entity needs to move a server containing ePHI to a new facility. Which physical safeguard specification is most relevant to documenting this move?
- Workstation Use
- Facility Access Controls — Maintenance Records
- Device and Media Controls — Accountability (Correct answer)
- Contingency Operations
Correct answer: Device and Media Controls — Accountability
The Accountability specification under Device and Media Controls requires documenting the movement of hardware and electronic media and the individuals responsible.
Question 5: Which of the following is NOT a technical safeguard standard under the HIPAA Security Rule?
- Audit Controls
- Integrity
- Workstation Security (Correct answer)
- Person or Entity Authentication
Correct answer: Workstation Security
Workstation Security is a Physical Safeguard standard, not a Technical Safeguard; the Technical Safeguard standards are Access Control, Audit Controls, Integrity, Person or Entity Authentication, and Transmission Security.
Question 6: After a risk analysis, a small clinic determines that encrypting ePHI transmissions over its internal network is not reasonable given its current infrastructure. What must the clinic do?
- Apply for an HHS waiver from the encryption requirement
- Document the rationale and implement an equivalent alternative measure (Correct answer)
- Ensure all ePHI is stored only on local servers, never transmitted
- Immediately upgrade the network to support encryption
Correct answer: Document the rationale and implement an equivalent alternative measure
Because transmission encryption is an addressable specification, the clinic must document its reasoning and implement a reasonable alternative that achieves the same protection.
Question 7: A covered entity implements biometric fingerprint scanners to verify the identity of users accessing ePHI. This satisfies which HIPAA Technical Safeguard standard?
- Integrity
- Audit Controls
- Transmission Security
- Person or Entity Authentication (Correct answer)
Correct answer: Person or Entity Authentication
Person or Entity Authentication requires procedures to verify identity before granting access to ePHI; biometric scanners are an accepted authentication mechanism.
Under HIPAA, which of the following best distinguishes 'required' from 'addressable' implementation specifications?