Documentation & Record Management Flashcards
7 cards from real SAC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Documentation & Record Management flashcards as text
Under HIPAA, how long must covered entities generally retain medical record documentation related to their security policies?
Answer: 6 years
HIPAA requires covered entities to retain documentation of security policies and procedures for a minimum of six years from creation or last effective date.
What does 'document version control' prevent in a team environment?
Answer: Conflicting edits and loss of historical changes
Version control prevents multiple team members from overwriting each other's changes and preserves a history of all previous versions.
Which documentation artifact is MOST useful for troubleshooting a recurring intermittent network issue?
Answer: Network baseline performance report
A baseline performance report establishes normal behavior, making it easier to identify deviations that indicate when and where intermittent issues occur.
A company's IT policy requires that all documentation changes go through a formal review before publication. This is an example of which process?
Answer: Document lifecycle management
Document lifecycle management includes formal review and approval gates before changes are published, ensuring accuracy and accountability.
What is the risk of maintaining documentation only in one employee's personal notes or local drive?
Answer: Knowledge is lost if that employee leaves or is unavailable
Storing documentation in personal silos creates a single point of failure; critical knowledge becomes inaccessible when that individual is unavailable.
When creating a network diagram for regulatory compliance purposes, which additional element is typically required beyond standard diagrams?
Answer: Data classification labels indicating where sensitive data flows
Compliance frameworks such as PCI-DSS require network diagrams to show where cardholder or sensitive data flows, including across trust boundaries.
What distinguishes a 'procedure' from a 'policy' in IT documentation?
Answer: A policy states what must be done; a procedure describes how to do it step by step
A policy defines requirements and rules (the 'what' and 'why'), while a procedure provides the specific step-by-step instructions for fulfilling those requirements.