Correct Answers 2025-2026 Updated.
A hospital has provided physicians with electronic mobile devices so they can access patients'
health records easily.
Which security measure must also be put into place? - Answer Device encryption with
password requirements
**The Office of the National Coordinator for Health Information Technology (ONC) recommends
installing and enabling encryption to protect health information stored or sent by mobile
devices (Ch 12, Solution and Recommendations).
A hospital experiences a breach involving a stolen laptop. The laptop was unencrypted and
contained the electronic health records of 517 patients.
Which action must the administrator take in response to this breach, according to the Health
Information Technology for Economic and Clinical Health Act (HITECH)? - Answer The
administrator must report the breach to the Secretary of HHS immediately and notify affected
patients through prominent media outlets.
An often-overlooked asset in an enterprise when looking at security is the multifunction printer
(MFP). An unsecured MFP is a prime target for hacking into the enterprise.
Which key regulation requires manufacturers to eliminate exposure to the network and the
organization's data to hacking or data compromise? - Answer Health Insurance Portability
and Accountability Act (HIPAA)
** he 1996 HIPAA Rules require manufacturers to eliminate exposure to the network and the
organization's data. (Ch 12 of Adaptive Health Management Information Systems: Concepts,
Cases, and Practical Applications (4th ed.): 1996 HIPAA Rules)
A healthcare organization wants to establish an IT security program and is fully aware of the
basic framework requirements. They will begin by addressing key risk management goals.