CompTIA
HIT-001 · Question #47
You are the privacy officer in charge of setting up the policies and procedures for protecting patient information within your covered entity. You have studied HIPAA's requirements and are now faced…
The correct answer is A. A policy limiting staff members from naming the covered entity for which they work outside the office. See the full explanation below for the reasoning.
Question
You are the privacy officer in charge of setting up the policies and procedures for protecting patient information within your covered entity. You have studied HIPAA's requirements and are now faced with determining what kinds of policies you need to implement. Which of the follow do you NOT need to implement?
Options
- AA policy limiting staff members from naming the covered entity for which they work outside the office.
- BA policy governing the ongoing training of how to handle PHI for employees.
- CA policy outlining which employees have access to electronic protected health information (EPHI).
- DA policy defining what role management will play in the oversight and compliance for security controls.
How the community answered
(34 responses)- A74% (25)
- B9% (3)
- C3% (1)
- D15% (5)
Community Discussion
No community discussion yet for this question.