Labour Day Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

HCISPP Exam Dumps - HealthCare Information Security and Privacy Practitioner

Question # 4

A risk assessment report recommends upgrading all perimeter firewalls to mitigate a particular finding. Which of the following BEST supports this recommendation?

A.

The inherent risk is greater than the residual risk.

B.

The Annualized Loss Expectancy (ALE) approaches zero.

C.

The expected loss from the risk exceeds mitigation costs.

D.

The infrastructure budget can easily cover the upgrade costs.

Full Access
Question # 5

The U.S. healthcare system can best be described as:

A.

Expensive

B.

Fragmented

C.

Market-oriented

D.

All of the above

Full Access
Question # 6

When assessing an organization’s security policy according to standards established by the International Organization for Standardization (ISO) 27001 and 27002, when can management responsibilities be defined?

A.

Only when assets are clearly defined

B.

Only when standards are defined

C.

Only when controls are put in place

D.

Only procedures are defined

Full Access
Question # 7

Excessive health care is a concern because it is.

A.

Wasteful

B.

Costly

C.

Potentially harmful

D.

All of the above

Full Access
Question # 8

In a free market who would pay for the delivery of health care services?

A.

numerous health insurance companies

B.

patients

C.

government

D.

multiple payers

Full Access
Question # 9

A medical intervention lying on a steeper portion of the aggregate cost-benefit curve indicates a major benefit for a relatively modest cost. An example of such an intervention would be:

A.

childhood immunizations.

B.

lung transplants.

C.

care for an anencephalic infant.

D.

purchasing MRI scanners to supplement CT scanners.

Full Access
Question # 10

____________ is a accrediting community bases health care organization (home health, Hospice). It has received deeming authority from CMS for home health, hospice and home medical equipment agencies.

A.

The Joint Commission

B.

American Osteopathic Association

C.

Community Health Accreditation Program ( CHAP)

Full Access
Question # 11

The inclusion of network-model HMOs in the Health Maintenance Act of 1973 ensured.

A.

the HMO movement would not create rapid change to the mode of health care delivery

B.

universal coverage

C.

no economic risk among both physicians and HMOs

D.

All of the above.

Full Access
Question # 12

Regulatory strategies for health insurance financing seek to control public expenditures for health care by.

A.

Implementing tax-financed health insurance or limiting premiums

B.

Limiting the annual use of services among patients

C.

Increasing competition among health insurance plans

D.

Only A and C

Full Access
Question # 13

The continuous quality improvement model (CQI) seeks to.

A.

improve access to care

B.

develop formalized standards of care

C.

separate financial and clinical decisions

D.

focus on individual caregivers

Full Access
Question # 14

Vertical integration refers to an organization model that under one ownership.

A.

Contains all levels of care, from primary to tertiary

B.

Provides the necessary staff for this full spectrum of care

C.

Provides the necessary facility for all levels of care

D.

All of the above.

Full Access
Question # 15

Which of the following is true of experience rating?

A.

High risk patients pay relatively low premiums.

B.

It provides affordable coverage to the chronically ill.

C.

Young, healthier groups have cheaper premiums.

D.

The elderly have among the lowest premiums.

Full Access
Question # 16

___________ includes highly qualified pracitioners availble as consultants when needed.

A.

Active

B.

Honorary

C.

Consulting

Full Access
Question # 17

Which of the following types of business continuity tests includes assessment of resilience to internal and external risks without endangering live operations?

A.

Walkthrough

B.

Simulation

C.

Parallel

D.

White box

Full Access
Question # 18

The malpractice liability system negatively impacts quality of care because.

A.

The fear and stress of malpractice litigation creates an "I didn't do it" response from the physician, rather than working on improvement

B.

The system is economically wasteful and takes dollars away from improving care

C.

It wreaks unnecessary stress on often innocent and talented physicians

D.

All of the above

Full Access
Question # 19

If a state or federal law or regulation grants the client greater access to their PHI, then it will preempt HIPAA.

A.

True

B.

False

Full Access
Question # 20

An organization is outsourcing its payroll system and is requesting to conduct a full audit on the third-party information technology (IT) systems. During the due diligence process, the third party provides previous audit report on its IT system.

Which of the following MUST be considered by the organization in order for the audit reports to be acceptable?

A.

The audit assessment has been conducted by an independent assessor.

B.

The audit reports have been signed by the third-party senior management.

C.

The audit reports have been issued in the last six months.

D.

The audit assessment has been conducted by an international audit firm.

Full Access
Question # 21

Which of the following is the MOST significant benefit to implementing a third-party federated identity architecture?

A.

Attribute assertions as agencies can request a larger set of attributes to fulfill service delivery

B.

Data decrease related to storing personal information

C.

Reduction in operational costs to the agency

D.

Enable business objectives so departments can focus on mission rather than the business of identity management

Full Access
Question # 22

Privacy and security includes which of the following best practices?

A.

Talking about consumers in public areas or where you can be overheard

B.

Sharing your computer password with a new staff that does not have their own

C.

Including PHI in an unecypted email via a public system

D.

Keeping computer screens out of sight of others

E.

None of the above

Full Access
Question # 23

Which of the following methods MOST efficiently manages user accounts when using a third-party cloud-based application and directory solution?

A.

Cloud directory

B.

Directory synchronization

C.

Assurance framework

D.

Lightweight Directory Access Protocol (LDAP)

Full Access
Question # 24

Which racial/ethnic group is most likely to drink alcohol?

A.

White

B.

Black or African American

C.

Asian or Pacific Islander

D.

Hispanic

Full Access
Question # 25

Intellectual property rights are PRIMARY concerned with which of the following?

A.

Owner’s ability to realize financial gain

B.

Owner’s ability to maintain copyright

C.

Right of the owner to enjoy their creation

D.

Right of the owner to control delivery method

Full Access
Question # 26

Critics of the United States health care system find fault with all of the following EXCEPT:

A.

its lack of organizational coherence

B.

its tertiary care organization

C.

its over reliance on primary care

D.

its specialist orientation

Full Access
Question # 27

Surgeons usually receive a single payment for the surgery and postoperative care. This bundling, or payment per episode, gives surgeons an economic incentive to.

A.

Limit both the number of surgeries they perform and the number of post operative visits they make.

B.

Increase both the number of surgeries and the number of post operative visits.

C.

Limit the number of surgeries and increase the number of post operative visits.

D.

Increase the number of surgeries and limit the number of post operative visits.

Full Access
Question # 28

Covered entities (certain health care providers, health plans, and health care clearinghouses) are not required to comply with the HIPPA Privacy Rule until the compliance date. Covered entities may, of course, decide to:

A.

unvoluntarily protect patient health information before this date

B.

voluntarily protect patient health information before this date

C.

after taking permission, voluntarily protect patient health information before this date

D.

compulsorily protect patient health information before this date

Full Access
Question # 29

Handled the first bioterrorism attack in the mail. Also replaced Health Care Financing Administration.

A.

Joint Commission

B.

CMS

C.

HIPPA

Full Access
Question # 30

Private health insurance coverage has decreased over the past decades because of.

A.

The rising cost of health care.

B.

An increase in non-unionized jobs

C.

A shift from manufacturing jobs to service industry jobs

D.

All of the above

Full Access
Question # 31

During the risk assessment phase of the project the CISO discovered that a college within the University is collecting Protected Health Information (PHI) data via an application that was developed in-house. The college collecting this data is fully aware of the regulations for Health Insurance Portability and Accountability Act (HIPAA) and is fully compliant.

What is the best approach for the CISO?

During the risk assessment phase of the project the CISO discovered that a college within the University is collecting Protected Health Information (PHI) data via an application that was developed in-house. The college collecting this data is fully aware of the regulations for Health Insurance Portability and Accountability Act (HIPAA) and is fully compliant.

What is the best approach for the CISO?

A.

Document the system as high risk

B.

Perform a vulnerability assessment

C.

Perform a quantitative threat assessment

D.

Notate the information and move on

Full Access
Question # 32

In general, servers that are facing the Internet should be placed in a demilitarized zone (DMZ). What is MAIN purpose of the DMZ?

A.

Reduced risk to internal systems.

B.

Prepare the server for potential attacks.

C.

Mitigate the risk associated with the exposed server.

D.

Bypass the need for a firewall.

Full Access
Question # 33

Is a voluntary process that a health care facility or organization undergoes to demonstrate that is has met standards.

A.

Joint Commission

B.

Regulations

C.

Accreditation

Full Access
Question # 34

What does "MUA" stand for?

A.

Metropolitan Utilization Area

B.

Medically Underserved Area

C.

Metropolitan Underserved Area

D.

Medical Utilization Area

Full Access
Question # 35

Which is not an underlying assumption of a theoretical model of costs and health outcomes?

A.

The relevant outcome is the overall health of a population rather than of an individual.

B.

It is possible to quantify health at a population level.

C.

It is necessary to focus on health outcomes, those aspects of health status directly under the influence of health care.

D.

It is impossible to reduce cost without also reducing health outcomes.

Full Access
Question # 36

In addition to first contact care, the key task(s) of primary care include.

A.

Longitudinality, or following a patient over time

B.

Comprehensiveness

C.

Coordination

D.

All of the above

Full Access
Question # 37

Which central agency manages the health care delivery system in the United States?

A.

Centers for Disease Control and Prevention

B.

Department of Health and Human Services

C.

Department of Commerce

D.

NONE

Full Access
Question # 38

Lack of health insurance has become a middle class phenomenon among all except.

A.

Those who are self employed

B.

Those working in small businesses

C.

Those with traditional jobs in manufacturing

D.

Those with part time jobs

Full Access
Question # 39

The HIPPA task force must first

A.

inventory the organization's systems, processes, policies, procedures and data to determine which elements are critical to patient care and central to the organization's business

B.

inventory the organization's systems, processes, policies, procedures and data to determine which elements are non critical to patient care and central to the organization's business

C.

inventory the organization's systems, processes, policies, procedures and data to determine which elements are critical to patient complaints and central to the organization's peripheral businesses

D.

modify the organization's systems, processes, policies, procedures and data to determine which elements are critical to patient care and central to the organization's business

Full Access
Question # 40

A release of information must include which of the following?

A.

Clients name

B.

A description of information to be disclosed

C.

An expiration date

D.

A description of the purpose of disclosure

E.

All of the above

Full Access
Question # 41

Results of tests/procedures can be made available to the clients family if the client is unable to communicate well.

A.

True

B.

False

Full Access
Question # 42

Which of the following is the BEST reason for the use of security metrics?

A.

They ensure that the organization meets its security objectives.

B.

They provide an appropriate framework for Information Technology (IT) governance.

C.

They speed up the process of quantitative risk assessment.

D.

They quantify the effectiveness of security processes.

Full Access
Question # 43

A company whose Information Technology (IT) services are being delivered from a Tier 4 data center, is preparing a companywide Business Continuity Planning (BCP). Which of the following failures should the IT manager be concerned with?

A.

Application

B.

Storage

C.

Power

D.

Network

Full Access
Question # 44

The adequacy of the health profession workforce (ie. supply and demand) can be determined by.

A.

Market demand of health professions

B.

Population need of health professions

C.

Neither A nor B are determinants

D.

Both A and B are determinants

Full Access
Question # 45

Hospitals in the United States evolved from

A.

alms houses

B.

sick homes

C.

pest houses

D.

inns

Full Access