100-160 · Question #15
You work for a hospital that stores electronic protected health information (ePHI) in an online portal. Authorized employees can use their mobile devices to access patient ePHI. You need to ensure…
The correct answer is D. A policy to govern how ePHI is removed from mobile devices. HIPAA requires procedures for the removal of electronic protected health information (ePHI) from devices before disposal, reuse, or reassignment.
Question
You work for a hospital that stores electronic protected health information (ePHI) in an online portal. Authorized employees can use their mobile devices to access patient ePHI. You need to ensure that employees' mobile devices comply with HIPAA regulations. Which safeguard should you develop and implement?
Options
- AAn ownership policy for employees' mobile devices
- BA contingency plan
- CA policy that requires multi-factor authentication to use the mobile device
- DA policy to govern how ePHI is removed from mobile devices
How the community answered
(53 responses)- A8% (4)
- B17% (9)
- C4% (2)
- D72% (38)
Explanation
HIPAA requires procedures for the removal of electronic protected health information (ePHI) from devices before disposal, reuse, or reassignment.
Topics
Community Discussion
8The one that trips people up here is C, because requiring MFA to unlock a device sounds very HIPAA-ish, and it is a reasonable security control, but it does not specifically address the HIPAA requirement that keeps mobile devices in scope for ePHI compliance. The answer is D, a policy governing how ePHI is removed from mobile devices. HIPAA's device and media controls standard directly requires covered entities to address the final disposition of ePHI and the hardware or media it lives on, and mobile devices are explicitly included in that. Without a formal policy covering how patient data gets wiped, transferred, or sanitized when a device is lost, retired, or reassigned, you have an open compliance gap that auditors will flag every time. The other options touch on good practices but none of them map to a specific HIPAA safeguard requirement the way media disposal and removal does.
Device and media controls is the right call, and worth adding that the sanitization piece bites hardest when a device is reassigned internally rather than retired, because those cases get skipped in informal programs all the time and show command on the MDM still shows the old user profile sitting there.
MFA locks the door but HIPAA sweats the moving truck, D.
WIPE beats WHO, removal policy wins, D every time. I nearly bubbled A on my actual exam because ownership sounds so official, then I pictured a traveling nurse leaving her phone in a rideshare and it clicked, you cannot HIPAA-comply your way out of unsanitized hardware, only D handles the real exit risk.
The traveling nurse scenario is perfect for locking that in, and I would add that the same logic covers BYOD situations, because the org's PHI lives on the hardware regardless of who bought the device, so sanitization policy has to travel with the data, not with the owner.
C bites you, but HIPAA device controls means data removal, pick D.
Honestly, C tripped me up because MFA feels so obvious for protecting ePHI access, but the question says employees are already authorized and the devices already have access, so the gap it is pointing to is what happens when a device is lost, stolen, or an employee leaves, and that is a device sanitization or remote wipe policy, which is why D is the right pick for HIPAA's device and media controls under the Physical Safeguards.
Nina nailed the Physical Safeguards angle, but tuck this hook in your brain so you never mix them up again: think "MFA guards the DOOR, wipe policy guards the DEVICE," because HIPAA splits those two worries into separate safeguard buckets on purpose.