A compliance officer at a covered clinic is structuring the clinic's protections for electronic protected health information so that they map cleanly onto the categories of safeguards the HIPAA Security Rule requires. Which three categories of safeguards does the Security Rule require the clinic to implement for electronic PHI? (Select THREE.)
- AAdministrative safeguards, such as a security management process, workforce training, and assignment of a security official. Correct
- BPhysical safeguards, such as facility access controls and rules for workstation use and device and media disposal. Correct
- CTechnical safeguards, such as access controls, audit controls, integrity controls, and transmission security. Correct
- DFinancial safeguards, such as cyber-insurance coverage and a funded reserve sized to the cost of a notifiable breach.
- EContractual safeguards, such as business associate agreements that by themselves satisfy the Rule's safeguard obligations for the clinic.
Why A is correct: Administrative safeguards are one of the three required categories and cover the policies, risk management, and personnel measures that govern security.
Why B is correct: Physical safeguards are a required category covering protection of facilities, workstations, and the devices and media that hold electronic PHI.
Why C is correct: Technical safeguards are a required category governing the technology that controls and monitors access to electronic PHI.
Why D is wrong: The Security Rule defines administrative, physical, and technical safeguards; it does not establish a financial safeguards category or mandate insurance reserves.
Why E is wrong: Business associate agreements are required where applicable but are not one of the Security Rule's three safeguard categories and do not discharge the clinic's own safeguard duties.