HCISPP · Question #307
The HIPPA task force must inventory the organization's systems, processes, policies, procedures and data to determine which elements are critical to patient care and central to the organizations…
The correct answer is D. by priority as well as availability, reliability, access and use. The person responsible for criticality. HIPAA's Security Rule requires organizations to conduct a thorough risk analysis and inventory of all systems and assets that handle Protected Health Information (PHI). The inventory must be organized by priority and must capture key operational dimensions: availability (can it…
Question
The HIPPA task force must inventory the organization's systems, processes, policies, procedures and data to determine which elements are critical to patient care and central to the organizations business. All must be inventoried and listed by
Options
- Aby priority as well as encryption levels, authenticity, storage-devices, availability, reliability, access
- Bby priority and cost as well as availability, reliability, access and use. The person responsible for
- Cby priority as well availability, reliability, access and use. The person responsible for criticality
- Dby priority as well as availability, reliability, access and use. The person responsible for criticality
How the community answered
(50 responses)- A2% (1)
- B6% (3)
- C2% (1)
- D90% (45)
Explanation
HIPAA's Security Rule requires organizations to conduct a thorough risk analysis and inventory of all systems and assets that handle Protected Health Information (PHI). The inventory must be organized by priority and must capture key operational dimensions: availability (can it be accessed when needed?), reliability (does it function consistently?), access (who can use it?), and use (how is it being used?). Additionally, each inventoried item must have a designated person responsible for assessing and maintaining its criticality level. Answer D is the only option that correctly and completely captures all these required dimensions without introducing inaccurate additions (like 'encryption levels' in answer A).
Topics
Community Discussion
No community discussion yet for this question.