Certified In Cybersecurity CC · Free Practice Question Easy
Question 9
Which of the following is NOT a requirement for HIPAA (Health Insurance Portability and Accountability Act) compliance?
- A Implementing appropriate physical safeguards
- B Ensuring unauthorized access to health information
- C Providing regular training to employees
- D Encrypting electronic health records
Reveal correct answer
Correct answer: B
Explanation
The correct answer: Ensuring unauthorized access to health information is NOT a requirement for HIPAA compliance. In fact, HIPAA (Health Insurance Portability and Accountability Act) mandates that organizations protect patient health information from unauthorized access. The other three options are indeed requirements for HIPAA compliance: The incorrect answers: Encrypting electronic health records: HIPAA requires organizations to implement technical safeguards to ensure the confidentiality, integrity, and availability of electronic protected health information (ePHI). This includes encrypting ePHI whenever it is stored or transmitted. Implementing appropriate physical safeguards: HIPAA's Security Rule requires organizations to have physical safeguards in place to protect against unauthorized access to ePHI. This can include facility access controls, workstation use and security policies, and device and media controls. Providing regular training to employees: HIPAA mandates that organizations provide regular training to all workforce members who have access to protected health information (PHI) to ensure they understand the policies and procedures necessary to maintain HIPAA compliance.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
