CGEIT · Question #47
Which of the following aspects of the transition from X-rays to digital images would be BEST addressed by implementing information security policy and procedures?
The correct answer is D. Protecting personal health information. When transitioning from X-rays to digital images, the aspect best addressed by implementing information security policy and procedures is protecting personal health information.
Question
Which of the following aspects of the transition from X-rays to digital images would be BEST addressed by implementing information security policy and procedures?
Options
- AEstablishing data retention procedures
- BTraining technicians on acceptable use policy
- CMinimizing the impact of hospital operation disruptions on patient care
- DProtecting personal health information
How the community answered
(29 responses)- A3% (1)
- B10% (3)
- C14% (4)
- D72% (21)
Why each option
When transitioning from X-rays to digital images, the aspect best addressed by implementing information security policy and procedures is protecting personal health information.
Establishing data retention procedures is an important aspect of data governance, but the broader protection of PHI encompasses more than just retention, covering its entire lifecycle under security policies.
Training technicians on acceptable use policy is an implementation of security policy, not the policy itself addressing the aspect of protection.
Minimizing hospital operation disruptions relates more to business continuity and disaster recovery, which are separate from information security policies focused on data protection.
Information security policies and procedures are specifically designed to establish rules and controls for safeguarding sensitive data, such as Personal Health Information (PHI). In the context of digital images, these policies are crucial for ensuring confidentiality, integrity, and availability of patient data in compliance with healthcare regulations like HIPAA, preventing unauthorized access, modification, or disclosure.
Concept tested: Information security policy for PHI
Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/hipaa-compliance-overview
Topics
Community Discussion
No community discussion yet for this question.