01. Payers are classified by whether the money that ultimately pays a claim comes from a public or a private source. For a payer that is a public source, where do those funds originate?
a) Public health agency
b) Government entity
c) Health maintenance organization
d) Employer group
02. A sanction policy tells the workforce what happens when the organization's information security and privacy rules are broken. Which two basic components must such a policy contain?
a) Amount of fines allowed by law and criminal penalties prescribed
b) Alternative punishments considered and precedents
c) Type of offense and the type of punishment
d) Names of the person responsible and the person reporting
03. Which of the following would best help a healthcare organization confirm that a third party has met an independent external attestation for information security or privacy?
a) An ISO 27001 certificate or a SOC 2 report from an independent auditor
b) The vendor's financial soundness
c) Length of time the vendor has been in business
d) Past performance reviews collected from the vendor's other healthcare clients
04. An organization decides it must carry out an activity that increases its risk exposure, and it responds by implementing administrative, physical, and technical controls to reduce the likelihood and the impact of an incident. Which risk response does this describe?
a) Transfer
b) Mitigate
c) Accept
d) Avoid
05. You are provided a network vulnerability scan of the hospital network. There are numerous critical unpatched vulnerabilities on many of the devices. You work with the person who runs the centralized vulnerability patching team to develop a remediation approach that includes automated security patching of systems.
Which of these steps is MOST important to complete before the automated patching runs?
a) Exclude medical devices from the updates.
b) Quarantine vulnerable systems per policy.
c) Contact system owners to advise them of the updates.
d) Schedule the remediation patching after clinical hours.
06. A covered entity runs a security management process: risk analysis, risk management, a sanction policy and regular review of information system activity. That process is BEST described as which set of controls?
a) Operational and physical safeguards
b) Technical safeguards
c) Detective and corrective controls
d) Administrative safeguards
07. Two healthcare organizations each hold their own records for an overlapping patient population and agree to exchange a defined set of data elements for a joint quality-improvement study. Neither organization is acting on the other’s behalf.
The formal, written instrument stating which elements may be exchanged, for what purpose, and under what safeguards is a ________ agreement.
a) Liability limit
b) Data sharing
c) Business partner
d) Service level
08. How do the HIPAA Privacy Rule and the HIPAA Security Rule differ in the information they cover?
a) No difference exists; the two rules impose the same requirements on covered entities
b) The Privacy Rule covers electronic transmissions only, while the Security Rule covers paper records, spoken disclosures and the physical handling of charts in the facility
c) The Security Rule covers electronic protected health information only, while the Privacy Rule covers protected health information in any form that it takes
d) The Privacy Rule and the Security Rule impose contradictory requirements on electronic health records
09. Which standards development organization was created to enable electronic health record systems to exchange information with one another?
a) HL7
b) LOINC
c) DICOM
d) ICD-10
10. PIPEDA requires an organization to make information about its personal information policies and practices readily available to individuals, in a form that is generally understandable, so that an individual can make an informed decision about what he or she is acknowledging and signing.
This requirement is an element of which principle?
a) Identifying purpose
b) Consent
c) Accounting of disclosures
d) Openness