#1
What is a common method to ensure healthcare information privacy?
Encrypting sensitive data
ExplanationEncrypting data prevents unauthorized access, ensuring privacy.
#2
What does HIPAA stand for?
Health Insurance Portability and Accountability Act
ExplanationHIPAA ensures portability of health insurance and maintains accountability for healthcare data.
#3
What is a potential consequence of a healthcare data breach?
Financial penalties
ExplanationBreach repercussions may include fines, impacting an organization financially.
#4
Which organization enforces the rules and regulations outlined in HIPAA?
Office for Civil Rights (OCR)
ExplanationOCR ensures compliance and enforces regulations specified in HIPAA.
#5
What is a potential consequence of non-compliance with healthcare information security regulations?
Legal penalties and fines
ExplanationNon-compliance can result in legal repercussions and financial penalties.
#6
Which of the following is NOT considered protected health information (PHI) under HIPAA?
Social security number
ExplanationSocial security numbers are not typically classified as PHI under HIPAA.
#7
What is the main goal of a security risk assessment in healthcare?
To identify potential security vulnerabilities
ExplanationRisk assessments help pinpoint vulnerabilities to prevent security breaches.
#8
What is the principle of least privilege in healthcare information security?
Granting access based on necessity for job duties
ExplanationLimiting access to necessary functions reduces the risk of unauthorized access.
#9
Which of the following is an example of a physical safeguard for healthcare information security?
Installing security cameras in data centers
ExplanationPhysical safeguards like cameras enhance physical security measures.
#10
What is the purpose of the Health Information Technology for Economic and Clinical Health (HITECH) Act?
To promote the adoption and meaningful use of health information technology
ExplanationHITECH encourages the effective utilization of health IT for economic and clinical benefits.
#11
Which of the following is NOT a component of the CIA triad in information security?
Accessibility
ExplanationAccessibility is not a component of the CIA triad, which comprises confidentiality, integrity, and availability.
#12
Which of the following is NOT a best practice for securing mobile devices in healthcare?
Disabling authentication measures
ExplanationDisabling authentication undermines mobile device security, which should be strengthened.