SECURITY ASSESSMENT | 2026/2027
UPDATE WITH COMPLETE SOLUTIONS
180 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
WGU D828 TELEMEDICA HIPAA & NIST SECURITY ASSESSMENT | 2026/2027 UPDATE WITH COMPLETE
SOLUTIONS. It contains 180 carefully selected questions that reflect the most current exam content and testing
strategies. Each question is accompanied by a correct answer and a detailed rationale that explains the
underlying pathophysiology, pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 180 Questions
Foundations - Application - WGU D828 Telemedica Hipaa & NIST Security Assessment 2026/2027 Update
WITH Complete Solutions Health Information Security & Compliance Graduate
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Hipaa Privacy RULE 1-30 Telemedica, Hipaa, Security, Breach, Access
Hipaa Security RULE 31-60 Hipaa, Security, Telemedica S, Covered, Entity
NIST Cybersecurity 61-90 Hipaa, Security, Telemedica, Control, System
Framework
RISK Assessment AND 91-120 Hipaa, Security, Covered, Entity, Organization
Management
Security Controls AND 121-150 Hipaa, Security, Telemedica S, Breach, Covered
Safeguards
Incident Response AND 151-180 Hipaa, Covered, Security, Breach, Business Associate
Breach Notification
TOTAL 180 All questions include answers and detailed rationales
,Section A - Hipaa Privacy RULE
Q1.
TeleMedica's risk assessment identified a high-likelihood, high-impact threat of
unauthorized access to PHI via compromised telehealth credentials. Which NIST CSF
function and category best aligns with implementing mandatory MFA and device posture
checks?
A. Protect - Access Control (PR.AC) B. Detect - Security Continuous Monitoring
(DE.CM)
C. Respond - Communications (RS.CO) D. Recover - Recovery Planning (RC.RP)
Correct: A - Protect - Access Control (PR.AC)
Rationale:PR.AC focuses on access control, including identity and authentication measures
like MFA. DE.CM is about monitoring, RS.CO is communication during response, and RC.RP
is recovery planning. Thus, A is correct.
Q2.
TeleMedica's incident response team discovered that a breach involved 500+ individuals.
Under HIPAA Breach Notification Rule, which of the following must be reported to the HHS
Secretary within 60 days?
A. Any breach of unsecured PHI, regardless B. Only breaches affecting more than 500
of risk of harm individuals in a single state
C. All breaches, but the 60-day timeline D. Breaches where the covered entity
applies only to larger breaches determines a high probability of compromise
Correct: C - All breaches, but the 60-day timeline applies only to larger breaches
Rationale:HIPAA requires all breaches of unsecured PHI to be reported, but the timeline
varies: breaches affecting 500+ individuals must be reported to HHS within 60 days; smaller
breaches can be reported annually. Option A is incorrect because risk assessment is used to
determine breach notification obligations; B is wrong because it's not about state limits; D is
wrong because notification is required regardless of risk level unless a low probability of
compromise is demonstrated.
Q3.
In a NIST-based risk assessment, TeleMedica calculated the Annualized Rate of
Occurrence (ARO) for a ransomware attack as 0.2 and the Single Loss Expectancy (SLE)
as $250,000. What is the Annualized Loss Expectancy (ALE) and how should this inform
risk treatment?
Page 3
, Section A - Hipaa Privacy RULE
A. ALE = $50,000; implement cost-effective B. ALE = $1,250,000; accept the risk as it
controls up to $50,000 annually exceeds the control budget
C. ALE = $50,000; transfer the risk via cyber D. ALE = $1,250,000; avoid the risk by
insurance regardless of cost discontinuing telemedicine services
Correct: A - ALE = $50,000; implement cost-effective controls up to $50,000 annually
Rationale:ALE = ARO × SLE = 0.2 × $250,000 = $50,000. A rational risk treatment decision
is to implement controls costing less than the ALE, as this reduces expected loss. Option B
miscalculates ALE and suggests acceptance without justification; C and D also have incorrect
ALE values or irrational strategies.
Q4.
TeleMedica's business associate (BA) is a cloud storage provider that experiences a
breach. Under HIPAA, which of the following is the correct responsibility of the BA?
A. The BA is not required to notify B. The BA must notify TeleMedica within 60
TeleMedica unless TeleMedica requests it days of discovering the breach
C. The BA must notify affected individuals D. The BA is only responsible for reporting
directly if TeleMedica fails to do so to HHS, not to TeleMedica
Correct: B - The BA must notify TeleMedica within 60 days of discovering the breach
Rationale:Under the HIPAA Breach Notification Rule, a business associate must notify the
covered entity (TeleMedica) without unreasonable delay and within 60 days of discovery. The
covered entity is then responsible for notifying individuals and HHS. Option A is false; C is
incorrect because the BA's obligation is to notify the covered entity, not individuals (though the
BA may do so if the covered entity fails and the BA has the information); D is wrong because
the BA must notify the covered entity, not HHS directly (unless required by contract).
Q5.
TeleMedica is implementing a new patient portal that will allow secure messaging. Which
NIST 800-53 control family is most directly relevant to ensuring that patient data is not
altered during transmission?
A. Access Control (AC) B. System and Communications Protection
(SC)
C. Audit and Accountability (AU) D. Contingency Planning (CP)
Correct: B - System and Communications Protection (SC)
Page 4