HIPAA The HIPAA Security Rule 3 — Questions and Answers
Question 1: A cloud storage vendor holds ePHI on behalf of a covered hospital. Under the HIPAA Security Rule, this vendor is best classified as a:
- Covered entity
- Business associate (Correct answer)
- Workforce member
- Hybrid entity
Correct answer: Business associate
A vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a business associate subject to the Security Rule.
Question 2: Under the Security Rule's Integrity standard, what must covered entities implement to ensure ePHI has not been improperly altered or destroyed?
- Encryption algorithms
- Mechanisms to authenticate ePHI (Correct answer)
- Physical locks on servers
- Workforce background checks
Correct answer: Mechanisms to authenticate ePHI
The Integrity standard requires technical security mechanisms, such as checksums or hashing, to confirm that ePHI has not been improperly altered or destroyed.
Question 3: Which of the following is a required implementation specification under the Security Rule's Contingency Plan standard?
- Encryption of ePHI at rest
- Emergency mode operation plan (Correct answer)
- Automatic logoff
- Unique user identification
Correct answer: Emergency mode operation plan
Emergency Mode Operation Plan is one of five required specifications under the Contingency Plan, ensuring critical business processes continue during a disaster.
Question 4: The HIPAA Security Rule requires covered entities to conduct a Risk Analysis. How often must this analysis be performed?
- Annually, without exception
- Only at initial implementation
- Periodically and when environmental or operational changes occur (Correct answer)
- Every three years as required by NIST
Correct answer: Periodically and when environmental or operational changes occur
The Security Rule requires periodic risk analyses and reassessment whenever significant changes to operations or the environment occur.
Question 5: Which Security Rule standard requires covered entities to implement policies ensuring only authorized personnel have access to ePHI?
- Audit Controls
- Access Control (Correct answer)
- Transmission Security
- Workforce Security
Correct answer: Access Control
The Access Control standard under Technical Safeguards requires unique user identification, emergency access procedures, and role-based access to ePHI systems.
Question 6: A security officer discovers that ePHI is being sent via unencrypted email to external providers. What Security Rule standard is most directly implicated?
- Physical Safeguards — Workstation Use
- Technical Safeguards — Transmission Security (Correct answer)
- Administrative Safeguards — Sanction Policy
- Administrative Safeguards — Information Access Management
Correct answer: Technical Safeguards — Transmission Security
The Transmission Security standard requires technical measures to guard against unauthorized access to ePHI transmitted over electronic networks.
Question 7: Which of the following Security Rule requirements addresses what happens when an employee is terminated?
- Contingency Plan
- Workforce Clearance Procedure
- Termination Procedures (Correct answer)
- Information Access Management
Correct answer: Termination Procedures
Termination Procedures is an addressable implementation specification under Workforce Security that requires revoking system access for terminated employees.
A cloud storage vendor holds ePHI on behalf of a covered hospital.
Under the HIPAA Security Rule, this vendor is best classified as a: