RHIT Domain 2 (Latest
UPDATE) Questions & Answers 100%
Correct
The HIPAA Security Awareness and Training administrative safeguard requires all of
the following addressable implementation programs for an entity's workforce except:
a. Disaster recovery plan
b. Log-in monitoring
c. Password management
d. Security reminders - correct answer a
Another administrative safeguard specification requires that a covered entity
implement a security awareness and training program for all members of its
workforce. Special protections must be taken to ensure information is not
inappropriately released or accessed. These protections include log-in monitoring,
password management, and security reminders (Reynolds and Brodnik 2017, 274).
A home health agency plans to implement a computer system whereby its nurses
document home care services on a laptop computer taken to the patient's home. The
,laptops will connect to the agency's computer network. The agency is in the process of
identifying strategies to minimize the risks associated with the practice. Which of the
following would be the best practice to protect laptop and network data from a virus
introduced from an external device?
a. Biometrics
b. Encryption
c. Personal firewall software
d. Session terminations - correct answer c
A firewall is a part of a computer system or network that is designed to block
unauthorized access while permitting authorized communications. It is a software
program or device that filters information between two networks, usually between a
private network like an intranet and a public network like the Internet (Rinehart-
Thompson 2016c, 265).
The function used to provide access controls, authentication, and audit logging in an
HIE is:
a. Patient identification
,b. Record location service
c. Identity management
d. Consent management - correct answer c
Identity management provides security functionality, including determining who (or
what information system) is authorized to access information, authentication services,
audit logging, encryption, and transmission controls (Amatayakul 2016, 307).
Community Hospital is planning implementation of various elements of the EHR in the
next six months. Physicians have requested the ability to access the EHR from their
offices and from home. What advice should the HIM director provide?
a. HIPAA regulations do not allow this type of access.
b. This access would be covered under the release of PHI for treatment purposes and
poses no security or confidentiality threats.
c. Access can be permitted providing that appropriate safeguards are put in place to
protect against threats to security.
d. Access can be permitted because the physicians are on the medical staff of the
hospital and are covered by HIPAA as employees. - correct answer c
, The HIPAA Privacy Rule permits healthcare providers to access protected health
information for treatment purposes. However, there is also a requirement that the
covered entity provide reasonable safeguards to protect the information. These
requirements are not easy to meet when the access is from an unsecured location,
although policies, medical staff bylaws, confidentiality or other agreements, and a
careful use of new technology can mitigate some risks (Thomason 2013, 46).
The director of health information services is allowed access to the health record
tracking system when providing the proper log-in and password. What is this access
security mechanism called?
a. Context based
b. Role based
c. Situation based
d. User-based - correct answer d
User-based access is a security mechanism that grants users of a system access
based on their identity (Rinehart-Thompson 2016c, 262).
UPDATE) Questions & Answers 100%
Correct
The HIPAA Security Awareness and Training administrative safeguard requires all of
the following addressable implementation programs for an entity's workforce except:
a. Disaster recovery plan
b. Log-in monitoring
c. Password management
d. Security reminders - correct answer a
Another administrative safeguard specification requires that a covered entity
implement a security awareness and training program for all members of its
workforce. Special protections must be taken to ensure information is not
inappropriately released or accessed. These protections include log-in monitoring,
password management, and security reminders (Reynolds and Brodnik 2017, 274).
A home health agency plans to implement a computer system whereby its nurses
document home care services on a laptop computer taken to the patient's home. The
,laptops will connect to the agency's computer network. The agency is in the process of
identifying strategies to minimize the risks associated with the practice. Which of the
following would be the best practice to protect laptop and network data from a virus
introduced from an external device?
a. Biometrics
b. Encryption
c. Personal firewall software
d. Session terminations - correct answer c
A firewall is a part of a computer system or network that is designed to block
unauthorized access while permitting authorized communications. It is a software
program or device that filters information between two networks, usually between a
private network like an intranet and a public network like the Internet (Rinehart-
Thompson 2016c, 265).
The function used to provide access controls, authentication, and audit logging in an
HIE is:
a. Patient identification
,b. Record location service
c. Identity management
d. Consent management - correct answer c
Identity management provides security functionality, including determining who (or
what information system) is authorized to access information, authentication services,
audit logging, encryption, and transmission controls (Amatayakul 2016, 307).
Community Hospital is planning implementation of various elements of the EHR in the
next six months. Physicians have requested the ability to access the EHR from their
offices and from home. What advice should the HIM director provide?
a. HIPAA regulations do not allow this type of access.
b. This access would be covered under the release of PHI for treatment purposes and
poses no security or confidentiality threats.
c. Access can be permitted providing that appropriate safeguards are put in place to
protect against threats to security.
d. Access can be permitted because the physicians are on the medical staff of the
hospital and are covered by HIPAA as employees. - correct answer c
, The HIPAA Privacy Rule permits healthcare providers to access protected health
information for treatment purposes. However, there is also a requirement that the
covered entity provide reasonable safeguards to protect the information. These
requirements are not easy to meet when the access is from an unsecured location,
although policies, medical staff bylaws, confidentiality or other agreements, and a
careful use of new technology can mitigate some risks (Thomason 2013, 46).
The director of health information services is allowed access to the health record
tracking system when providing the proper log-in and password. What is this access
security mechanism called?
a. Context based
b. Role based
c. Situation based
d. User-based - correct answer d
User-based access is a security mechanism that grants users of a system access
based on their identity (Rinehart-Thompson 2016c, 262).