HIPAA The HIPAA Security Rule 4 — Questions and Answers
Question 1: Under the HIPAA Security Rule, which safeguard category includes the requirement for 'device and media controls'?
- Administrative Safeguards
- Technical Safeguards
- Physical Safeguards (Correct answer)
- Organizational Safeguards
Correct answer: Physical Safeguards
Device and Media Controls is a standard under Physical Safeguards governing the receipt, removal, and disposal of hardware and media containing ePHI.
Question 2: A practice must reassign a user's ePHI access rights when that user changes roles. Which specification addresses this?
- Access Establishment and Modification (Correct answer)
- Unique User Identification
- Authorization and Supervision
- Security Reminders
Correct answer: Access Establishment and Modification
Access Establishment and Modification is an addressable specification requiring policies to grant, change, and revoke access rights based on an employee's role.
Question 3: What is the difference between a 'threat' and a 'vulnerability' in the context of a HIPAA Security Rule risk analysis?
- Threats are internal; vulnerabilities are external
- A threat is a potential danger to ePHI; a vulnerability is a weakness that could be exploited by a threat (Correct answer)
- Threats relate to technical systems; vulnerabilities relate to people
- There is no meaningful distinction under the Security Rule
Correct answer: A threat is a potential danger to ePHI; a vulnerability is a weakness that could be exploited by a threat
In risk analysis, a threat is a potential occurrence that could negatively impact ePHI, while a vulnerability is a flaw or weakness that increases the likelihood of that threat causing harm.
Question 4: A clinic stores backup tapes of ePHI in an unlocked supply closet. Which Security Rule standard is most directly violated?
- Contingency Plan
- Device and Media Controls (Correct answer)
- Workstation Security
- Audit Controls
Correct answer: Device and Media Controls
Device and Media Controls requires covered entities to implement policies for the secure storage and handling of media containing ePHI.
Question 5: Which of the following must be documented and retained for at least six years under the HIPAA Security Rule?
- Patient medical records
- Security Rule policies, procedures, and actions (Correct answer)
- Business associate contracts only
- Employee training attendance sheets only
Correct answer: Security Rule policies, procedures, and actions
The Security Rule requires covered entities to retain documentation of their policies, procedures, and required actions for a minimum of six years from creation or last effective date.
Question 6: An organization assigns each workforce member a unique username to track ePHI access. This satisfies which Security Rule requirement?
- Automatic Logoff
- Unique User Identification (Correct answer)
- Audit Controls
- Person or Entity Authentication
Correct answer: Unique User Identification
Unique User Identification is a required implementation specification under Access Control that assigns each user a unique name or number to track individual activity.
Question 7: Under the Security Rule, which standard specifically requires mechanisms to record and examine activity in information systems containing ePHI?
- Integrity
- Audit Controls (Correct answer)
- Access Control
- Transmission Security
Correct answer: Audit Controls
Audit Controls is a required standard under Technical Safeguards that mandates hardware, software, or procedural mechanisms to record and examine access to ePHI systems.
Under the HIPAA Security Rule, which safeguard category includes the requirement for 'device and media controls'?