nerdexam
CompTIA

CAS-003 · Question #351

Providers at a healthcare system with many geographically dispersed clinics have been fined five times this year after an auditor received notice of the following SMS messages: Which of the…

The correct answer is A. Implement a secure text-messaging application for mobile devices and workstations. Transmitting protected health information (PHI) via standard SMS violates HIPAA; implementing a secure, encrypted messaging application ensures compliant communication of sensitive patient data.

Technical Integration of Enterprise Security

Question

Providers at a healthcare system with many geographically dispersed clinics have been fined five times this year after an auditor received notice of the following SMS messages:

Which of the following represents the BEST solution for preventing future files?

Exhibit

CAS-003 question #351 exhibit

Options

  • AImplement a secure text-messaging application for mobile devices and workstations.
  • BWrite a policy requiring this information to be given over the phone only.
  • CProvide a courier service to deliver sealed documents containing public health informatics.
  • DImplement FTP services between clinics to transmit text documents with the information.
  • EImplement a system that will tokenize patient numbers.

How the community answered

(32 responses)
  • A
    72% (23)
  • B
    9% (3)
  • C
    3% (1)
  • D
    13% (4)
  • E
    3% (1)

Why each option

Transmitting protected health information (PHI) via standard SMS violates HIPAA; implementing a secure, encrypted messaging application ensures compliant communication of sensitive patient data.

AImplement a secure text-messaging application for mobile devices and workstations.Correct

A secure text-messaging application provides end-to-end encryption, access controls, audit logging, and remote wipe capabilities, all of which are required safeguards under HIPAA's Security Rule for electronic PHI (ePHI). This solution addresses the exact violation channel (mobile messaging) while maintaining the clinical workflow that geographically dispersed providers require.

BWrite a policy requiring this information to be given over the phone only.

A policy requiring phone-only communication does not provide a technical control or audit trail, and verbal transmission of PHI still carries disclosure risks without encryption.

CProvide a courier service to deliver sealed documents containing public health informatics.

Physical courier services are impractical for time-sensitive clinical communication across many dispersed clinics and do not scale as a modern solution.

DImplement FTP services between clinics to transmit text documents with the information.

FTP transmits data in cleartext by default and is not an acceptable method for transmitting PHI under HIPAA without additional encryption layers.

EImplement a system that will tokenize patient numbers.

Tokenizing patient numbers obscures identifiers but does not secure the messaging channel itself; PHI beyond the patient number would still be transmitted unprotected.

Concept tested: HIPAA-compliant secure messaging for ePHI transmission

Source: https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html

Topics

#HIPAA compliance#secure messaging#PHI protection#mobile security

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice