nerdexam
(ISC)2

HCISPP · Question #236

Which of the following are some common features designed to protect confidentiality of health information contained in patient medical records?

The correct answer is D. All of the above. Physical locks, access passwords, and need-to-know policies are all standard safeguards required to protect the confidentiality of patient medical records.

Privacy and Security in Healthcare

Question

Which of the following are some common features designed to protect confidentiality of health information contained in patient medical records?

Options

  • ALocks on medical records rooms
  • BPasswords to access computerized records
  • CRules that prohibit employees from looking at records unless they have a need to know
  • DAll of the above

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    9% (3)
  • D
    88% (29)

Why each option

Physical locks, access passwords, and need-to-know policies are all standard safeguards required to protect the confidentiality of patient medical records.

ALocks on medical records rooms

Locks on medical records rooms alone are only one of three required safeguard categories and do not represent a complete confidentiality protection program.

BPasswords to access computerized records

Passwords alone address only the technical safeguard requirement and are insufficient without physical and administrative controls.

CRules that prohibit employees from looking at records unless they have a need to know

Need-to-know rules alone address only the administrative safeguard requirement and must be combined with physical and technical controls.

DAll of the aboveCorrect

HIPAA's Security Rule requires covered entities to implement administrative, physical, and technical safeguards to protect PHI. Physical safeguards include securing facilities and workstations (locks on records rooms), technical safeguards include access controls like passwords, and administrative safeguards include workforce access management policies (need-to-know rules). All three categories work together as a layered defense to ensure only authorized individuals access patient information.

Concept tested: HIPAA administrative, physical, and technical safeguards

Source: https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html

Topics

#Confidentiality protection#Physical security#Technical security#Administrative security

Community Discussion

No community discussion yet for this question.

Full HCISPP Practice