CAS-003 · Question #351
Providers at a healthcare system with many geographically dispersed clinics have been fined five times this year after an auditor received notice of the following SMS messages: Which of the…
The correct answer is A. Implement a secure text-messaging application for mobile devices and workstations. Transmitting protected health information (PHI) via standard SMS violates HIPAA; implementing a secure, encrypted messaging application ensures compliant communication of sensitive patient data.
Question
Providers at a healthcare system with many geographically dispersed clinics have been fined five times this year after an auditor received notice of the following SMS messages:
Which of the following represents the BEST solution for preventing future files?
Exhibit
Options
- AImplement a secure text-messaging application for mobile devices and workstations.
- BWrite a policy requiring this information to be given over the phone only.
- CProvide a courier service to deliver sealed documents containing public health informatics.
- DImplement FTP services between clinics to transmit text documents with the information.
- EImplement a system that will tokenize patient numbers.
How the community answered
(32 responses)- A72% (23)
- B9% (3)
- C3% (1)
- D13% (4)
- E3% (1)
Why each option
Transmitting protected health information (PHI) via standard SMS violates HIPAA; implementing a secure, encrypted messaging application ensures compliant communication of sensitive patient data.
A secure text-messaging application provides end-to-end encryption, access controls, audit logging, and remote wipe capabilities, all of which are required safeguards under HIPAA's Security Rule for electronic PHI (ePHI). This solution addresses the exact violation channel (mobile messaging) while maintaining the clinical workflow that geographically dispersed providers require.
A policy requiring phone-only communication does not provide a technical control or audit trail, and verbal transmission of PHI still carries disclosure risks without encryption.
Physical courier services are impractical for time-sensitive clinical communication across many dispersed clinics and do not scale as a modern solution.
FTP transmits data in cleartext by default and is not an acceptable method for transmitting PHI under HIPAA without additional encryption layers.
Tokenizing patient numbers obscures identifiers but does not secure the messaging channel itself; PHI beyond the patient number would still be transmitted unprotected.
Concept tested: HIPAA-compliant secure messaging for ePHI transmission
Source: https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html
Topics
Community Discussion
No community discussion yet for this question.
