HIPAA The HIPAA Security Rule 5 — Questions and Answers
Question 1: A hospital's Security Officer wants to verify that ePHI received from a partner has not been corrupted in transit. Which Security Rule standard applies?
- Access Control
- Integrity Controls within Transmission Security (Correct answer)
- Person or Entity Authentication
- Contingency Plan
Correct answer: Integrity Controls within Transmission Security
Transmission Security includes an addressable implementation specification for integrity controls to ensure ePHI is not improperly modified during transmission.
Question 2: Which of the following is NOT a standard under the Administrative Safeguards of the HIPAA Security Rule?
- Security Management Process
- Contingency Plan
- Workstation Use (Correct answer)
- Security Awareness and Training
Correct answer: Workstation Use
Workstation Use is a standard under Physical Safeguards, not Administrative Safeguards.
Question 3: A covered entity contracts with a software vendor to process claims containing ePHI. What must be in place before sharing ePHI with the vendor?
- A Notice of Privacy Practices
- A Business Associate Agreement (BAA) (Correct answer)
- A Patient Authorization Form
- An NDA under state law
Correct answer: A Business Associate Agreement (BAA)
Before sharing ePHI with a business associate, the covered entity must have a signed Business Associate Agreement specifying permitted uses and security obligations.
Question 4: Under the HIPAA Security Rule, which of the following best describes 'ePHI'?
- Any health information held by an employer for HR purposes
- Individually identifiable health information created, received, maintained, or transmitted in electronic form (Correct answer)
- Health data stored only on internet-connected devices
- Anonymized health data stored digitally
Correct answer: Individually identifiable health information created, received, maintained, or transmitted in electronic form
ePHI is individually identifiable health information that is created, received, maintained, or transmitted in any electronic format by a covered entity or business associate.
Question 5: Which Security Rule standard requires training programs to educate workforce members about potential threats to ePHI security?
- Workforce Security
- Security Management Process
- Security Awareness and Training (Correct answer)
- Evaluation
Correct answer: Security Awareness and Training
Security Awareness and Training is an Administrative Safeguards standard requiring covered entities to train all workforce members on security policies and procedures.
Question 6: A covered entity periodically reviews whether its security measures are still sufficient against evolving threats. This activity corresponds to which Administrative Safeguard standard?
- Risk Management
- Evaluation (Correct answer)
- Security Management Process
- Contingency Plan
Correct answer: Evaluation
The Evaluation standard requires covered entities to perform periodic technical and nontechnical assessments of whether security policies and procedures meet Security Rule requirements.
Question 7: Which of the following scenarios would most likely constitute a violation of the HIPAA Security Rule's Workforce Security standard?
- A nurse accesses a patient's record in the EHR without logging off afterward
- A new employee is given broad ePHI system access without any role-based authorization review (Correct answer)
- A covered entity fails to encrypt ePHI sent over the internet
- A physician loses an unencrypted laptop containing ePHI
Correct answer: A new employee is given broad ePHI system access without any role-based authorization review
Granting ePHI access without assessing whether access is appropriate for the employee's role violates the Workforce Security standard's clearance procedures.
A hospital's Security Officer wants to verify that ePHI received from a partner has not been corrupted in transit.
Which Security Rule standard applies?