wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

6th Week Meeting

Total questions: 90

Worksheet time: 45mins

Name
Class
Date
1.

What standards are used to build the national "data superhighway" connecting healthcare facilities across Indonesia?

a)

HL7 V2 standards

b)

HL7 FHIR standards

c)

ISO 9001 standards

d)

TCP/IP standards

e)

IEEE 802.11 standards

2.

What is a major risk associated with the interconnected national data superhighway for healthcare in Indonesia?

a)

A security failure at one small facility could compromise the entire system

b)

Slow internet speeds across the network

c)

High cost of data storage

d)

Lack of healthcare professionals

e)

Data breaches due to inadequate encryption

3.

As future HIM professionals, what is a key responsibility to ensure the safety of the national data superhighway?

a)

Reducing the amount of data collected

b)

Implementing regular security audits

c)

Increasing the number of healthcare facilities

d)

Improving patient satisfaction surveys

e)

Building guardrails and security measures

4.

Which principles must be mastered to fulfill ethical and legal duties in managing the national data superhighway?

a)

Data privacy and security

b)

Financial management

c)

Patient care techniques

d)

Data governance

e)

Marketing strategies

5.

Given the risk of a security failure at a single Puskesmas, what strategic approach should be taken to prevent a national crisis?

a)

Focus only on large hospitals for security upgrades

b)

Increase the number of local incidents reported

c)

Limit data sharing between facilities

d)

Implement robust security measures and continuous monitoring across all facilities

e)

Conduct regular security audits at all facilities

6.

Which of the following is NOT a core principle of the CIA Triad in information security?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Authentication

e)

Accountability

7.

What is the ethical and legal duty of a Health Information Management (HIM) professional regarding patient information?

a)

To share patient information with all staff

b)

To protect patient information according to relevant legal provisions

c)

To disclose patient information to unauthorized individuals

d)

To store patient information without security measures

e)

To ignore patient privacy concerns

8.

Which regulation is cited as relevant for protecting patient information in Indonesian healthcare settings?

a)

ISO 27001

b)

PMK 24/2022

c)

HIPAA

d)

GDPR

e)

UU ITE (Information and Electronic Transactions Law)

9.

Which of the following is an example of an internal threat to health data in healthcare settings?

a)

An employee accessing patient data without authorization

b)

A hacker from outside the organization

c)

An employee sharing passwords with unauthorized personnel

d)

A natural disaster damaging servers

e)

A virus sent via email from an external source

10.

How do administrative, physical, and technical safeguards differ in healthcare data protection?

a)

Physical safeguards are more important than technical safeguards

b)

Technical safeguards are only about software solutions

c)

Administrative safeguards involve policies, physical safeguards involve facility security, and technical safeguards involve technology controls

d)

They all refer to the same type of security measure

e)

Administrative safeguards are only for IT staff, physical safeguards are for patients, and technical safeguards are for doctors

11.

When analyzing a basic data breach scenario in healthcare, which principles should be applied?

a)

Privacy and security principles

b)

Marketing principles

c)

Customer service principles

d)

Financial principles

e)

Compliance principles

12.

Which of the following is NOT a component of the CIA Triad in information security?

a)

Accountability

b)

Confidentiality

c)

Integrity

d)

Availability

e)

Authentication

13.

What does the 'Confidentiality' aspect of the CIA Triad focus on?

a)

Increasing system performance

b)

Ensuring timely access for users

c)

Protecting sensitive information from unauthorized access

d)

Maintaining accuracy and trustworthiness

e)

Preventing unauthorized disclosure

14.

How does 'Integrity' contribute to information security according to the CIA Triad?

a)

By allowing public access to data

b)

By maintaining accuracy and trustworthiness

c)

By encrypting all information

d)

By ensuring data is not altered or tampered with

e)

By keeping the patient's story secret

15.

Which scenario best illustrates the 'Availability' principle of the CIA Triad?

a)

A bank verifies the accuracy of transaction records.

b)

A company encrypts all its emails to prevent leaks.

c)

A school restricts access to student grades to only teachers.

d)

A hospital system ensures patient records are accessible to doctors whenever needed.

e)

A cloud service guarantees uptime for its users.

16.

The CIA Triad forms the foundation for regulations like HIPAA in the U.S. and data protection strategies in Indonesia by:

a)

Focusing solely on user authentication methods

b)

Providing guidelines for system performance optimization

c)

Establishing core principles for protecting information: confidentiality, integrity, and availability

d)

Ensuring data is accessible to authorized users only

e)

Promoting open access to all data

17.

What is the main purpose of the principle of confidentiality in healthcare?

a)

To ensure that patient information is kept private and secure

b)

To restrict data access so only authorized individuals can view or handle it

c)

To allow anyone in the hospital to access patient records

d)

To share patient information with family and friends

e)

To post patient stories on social media for awareness

18.

According to the Indonesian context example, what should a registration clerk at a Puskesmas NOT do?

a)

Share patient information with unauthorized individuals

b)

Look up a neighbor's medical record out of curiosity

c)

Register new patients

d)

Schedule appointments for patients

e)

File medical records properly

19.

Which of the following is considered a breach of confidentiality?

a)

Discussing a patient's diagnosis in a public hospital elevator where others can overhear

b)

Reviewing a patient's file in a private office

c)

Updating a patient's record in a secure system

d)

Sharing information with authorized medical staff

e)

Leaving patient files open on a desk in a shared workspace

20.

Why is it important to ensure that only the right people are able to see patient information?

a)

To allow for more open communication in public spaces

b)

To encourage curiosity among hospital staff

c)

To make hospital operations faster

d)

To protect patient privacy and prevent unauthorized access

e)

To maintain the confidentiality of sensitive health data

21.

A doctor is about to discuss a patient's diagnosis in a crowded hospital elevator. What should the doctor do to maintain confidentiality?

a)

Speak loudly so everyone can hear

b)

Share the diagnosis with anyone who asks

c)

Wait until in a private setting to discuss the diagnosis

d)

Ignore confidentiality rules in public spaces

e)

Discuss the diagnosis only with authorized personnel

22.

Which of the following best defines the principle of integrity in the context of patient data?

a)

Ensuring that only authorized personnel can access patient data.

b)

Encrypting patient data to prevent unauthorized access.

c)

Regularly auditing patient data to ensure its accuracy and consistency.

d)

Maintaining the accuracy, consistency, and trustworthiness of data throughout its entire lifecycle, protecting it from unauthorized alteration or destruction.

e)

Making patient data available at all times, even during system failures.

23.

In the Indonesian context, why must a patient's blood type or allergy information be protected after it is entered into the system?

a)

To make the information available to insurance companies.

b)

To ensure the information is not changed accidentally or maliciously.

c)

To maintain the confidentiality of the patient's medical history.

d)

To prevent unauthorized access to the patient's financial records.

e)

To allow doctors to update the information as needed.

24.

What is a possible consequence of a failure of integrity in an electronic health record (EHR) system?

a)

Increased data storage costs

b)

Improved patient privacy

c)

Severe patient harm or even death

d)

Faster access to patient data

e)

Loss of patient trust

25.

Suppose an attacker changes a patient's medication dosage in the EHR. Which core question should healthcare professionals ask to ensure patient safety?

a)

How quickly can this information be retrieved?

b)

Who has accessed this information?

c)

Is this information encrypted?

d)

Is this information accurate and can it be trusted?

e)

What is the source of this information?

26.

What does the principle of availability ensure in the context of systems, applications, and data?

a)

That systems are only available during business hours

b)

That data is always encrypted and never accessible

c)

That only unauthorized users can access data at any time

d)

That systems, applications, and data are accessible to authorized users when and where needed

e)

That data is accessible to users only during scheduled maintenance

27.

In the Indonesian context example, why is it important for a physician to access a patient's complete history from the SATUSEHAT platform during an emergency?

a)

To schedule a follow-up appointment

b)

To update the patient's insurance information

c)

To check the patient's billing status

d)

To ensure the physician can provide appropriate care without delay

e)

To review the patient's previous medical treatments

28.

Which of the following best describes a failure of availability in a hospital's EHR system?

a)

A system that provides real-time analytics

b)

A system that automatically updates patient records

c)

A system that allows unauthorized access to patient data

d)

A system that is down for maintenance during peak hours

e)

A ransomware attack that encrypts and locks the system, forcing cancellation of surgeries

29.

Why can a ransomware attack on a hospital's EHR system compromise patient safety?

a)

It increases the number of available doctors

b)

It leads to delays in patient treatment

c)

It enhances the security of patient data

d)

It forces the cancellation of surgeries and prevents access to critical information

e)

It improves the speed of data access

30.

Suppose a hospital's EHR system is unavailable during an emergency. What is the most likely consequence?

a)

Patient safety may be compromised due to lack of information

b)

Patients receive faster care

c)

Physicians can access all patient data without issues

d)

Emergency staff may have to rely on memory for patient history

e)

The hospital's internet speed increases

31.

Which article of PMK 24/2022 explicitly mandates that medical record content must be kept confidential?

a)

Article 10

b)

Article 7

c)

Article 29

d)

Article 15

e)

Article 42

32.

What does the "Legal Duty" represent for HIM professionals according to PMK 24/2022?

a)

The technical management of medical records

b)

The obligation to maintain patient confidentiality

c)

The financial responsibility of the HIM professional

d)

The daily execution of ethical duties

e)

The embodiment of the HIM professional's sacred trust with the patient

33.

How does the "Guardian Role" reinforce the responsibilities of HIM professionals?

a)

By training new staff members

b)

By managing financial records

c)

By safeguarding patient confidentiality

d)

By ensuring daily execution of tasks

e)

By entrusting them to protect the patient's personal property

34.

Which of the following best describes "Daily Execution" in the context of the CIA Triad and PMK 24/2022?

a)

The tangible, day-to-day execution of ethical and legal duty

b)

The routine monitoring of patient care standards

c)

The annual review of medical records

d)

The financial auditing of hospital expenses

e)

The creation of new patient files

35.

How are the principles of the CIA Triad integrated into legal mandates for HIM professionals under PMK 24/2022?

a)

They are used for training purposes only.

b)

They only apply to financial records, not medical records.

c)

They are optional guidelines for best practices.

d)

They are codified as law, requiring confidentiality and ethical management of medical records.

e)

They are enforced through regular audits and compliance checks.

36.

Which of the following is the leading cause of major healthcare data breaches today?

a)

Physical theft

b)

Insider threats

c)

Phishing

d)

Hacking & Ransomware

e)

Malware attacks

37.

Phishing is best described as:

a)

A way to physically steal patient records

b)

A direct attack on data availability

c)

A technique to deceive individuals into providing sensitive information

d)

A form of malware that encrypts files

e)

A method used by attackers to trick employees and gain initial access

38.

Explain why healthcare is considered a prime target for cyber threats, using evidence from the black market value of patient health records and the types of attacks described.

a)

Healthcare data is highly valuable and targeted by sophisticated external threats such as hacking, ransomware, and phishing.

b)

Healthcare organizations have the least amount of data compared to other industries.

c)

Healthcare data is rarely targeted by cyber criminals.

d)

Patient health records can be sold on the black market for significant amounts of money.

e)

Healthcare data is only valuable for research purposes.

39.

Which of the following is an example of an unintentional/careless insider threat?

a)

Sabotage

b)

Accidental data exposure

c)

Data theft

d)

Inadvertent sharing of sensitive information

e)

Unauthorized access

40.

What is a common motivation for a malicious insider?

a)

Financial gain

b)

Forgetfulness

c)

Lack of training

d)

Revenge against the company

e)

System malfunction

41.

Why are internal threats particularly dangerous in organizations?

a)

They only affect external networks

b)

They are easy to detect

c)

They always use advanced hacking tools

d)

Insiders already have legitimate access to systems

e)

Insiders can manipulate data without raising suspicion

42.

A hospital employee loses an unencrypted USB drive containing patient data. What type of internal threat does this scenario represent?

a)

Unintentional/Careless Insider

b)

Negligent Employee

c)

System Administrator

d)

Malicious Insider

e)

External Hacker

43.

Compare and contrast the actions of unintentional/careless insiders and malicious insiders in the context of data breaches. Provide one example for each.

a)

Unintentional/careless insiders might share sensitive information mistakenly, while malicious insiders could sell that information to competitors.

b)

Malicious insiders never have access to sensitive data, while unintentional/careless insiders always do.

c)

Both types always act intentionally to harm the organization.

d)

Unintentional/careless insiders only work outside the organization, while malicious insiders work inside.

e)

Unintentional/careless insiders may expose data accidentally, such as losing a device, while malicious insiders intentionally steal data for personal gain, such as unauthorized access.

44.

Which of the following is NOT one of the three distinct categories of safeguards in a multi-layered security strategy?

a)

Financial Safeguards

b)

Administrative Safeguards

c)

Physical Safeguards

d)

Technical Safeguards

e)

Operational Safeguards

45.

What is the main reason a multi-layered defense is required in a comprehensive security program?

a)

It is required only for small organizations

b)

It is easier to manage

c)

It provides redundancy in case of failure

d)

It is cheaper than a single defense

e)

No single defense is sufficient

46.

Why is the "defense-in-depth" approach considered a global best practice in security?

a)

It is the cheapest method available

b)

It is required by major regulations and provides comprehensive protection

c)

It only uses technology for defense

d)

It offers multiple layers of security to mitigate risks

e)

It eliminates the need for policies

47.

Which of the following best describes the purpose of administrative safeguards in an organization?

a)

To design the physical layout of the office.

b)

To install firewalls and antivirus software.

c)

To establish formal rules and structures for how the organization will protect data.

d)

To manage only the financial records of the organization.

e)

To ensure compliance with legal and regulatory requirements.

48.

What is the primary focus of the 'People & Policy' layer in administrative safeguards?

a)

Managing administrative actions, policies, and procedures to govern workforce conduct and security measures.

b)

Developing new software for the organization.

c)

Purchasing office equipment.

d)

Marketing the organization's services.

49.

Why are administrative safeguards considered a critical defense against human error?

a)

They provide rules and structures that guide workforce behavior and security practices.

b)

They prevent all types of cyberattacks automatically.

c)

They eliminate the need for employee training.

d)

They focus only on technical solutions.

50.

How does the role of a Health Information Management (HIM) professional come to life in the context of administrative safeguards?

a)

By acting as an educator and process designer for data protection policies.

b)

By repairing computer hardware.

c)

By handling only patient billing.

d)

By designing the organization's logo.

51.

Which of the following best describes Security Risk Analysis in the context of administrative safeguards?

a)

The formal process of identifying potential threats and vulnerabilities to patient data.

b)

The process of training employees on security policies.

c)

The enforcement of consequences for violating security policies.

d)

The development of data backup and disaster recovery plans.

52.

What is the primary purpose of Contingency Planning as an administrative safeguard?

a)

To develop and maintain data backup, disaster recovery, and emergency mode operation plans to ensure availability.

b)

To identify threats and vulnerabilities to patient data.

c)

To train employees on recognizing phishing threats.

d)

To enforce consequences for security policy violations.

53.

Why is Security Awareness and Training considered a key administrative safeguard?

a)

It provides mandatory, ongoing training for all employees on security policies and how to recognize threats like phishing.

b)

It ensures data backup and disaster recovery.

c)

It identifies vulnerabilities in patient data.

d)

It enforces consequences for policy violations.

54.

Which administrative safeguard involves establishing and enforcing documented consequences for employees who violate security policies?

a)

Sanction Policy

b)

Security Risk Analysis

c)

Contingency Planning

d)

Security Awareness and Training

55.

Imagine a healthcare organization experiences a ransomware attack that threatens the availability of patient data. Which administrative safeguard would be most directly involved in responding to this situation?

a)

Contingency Planning

b)

Security Awareness and Training

c)

Sanction Policy

d)

Security Risk Analysis

56.

An employee repeatedly ignores security policies and clicks on suspicious email links. Which administrative safeguard should be applied to address this behavior?

a)

Sanction Policy

b)

Security Risk Analysis

c)

Contingency Planning

d)

Security Awareness and Training

57.

A hospital wants to reduce the risk of phishing attacks among its staff. Which administrative safeguard should it focus on strengthening?

a)

Security Awareness and Training

b)

Contingency Planning

c)

Sanction Policy

d)

Security Risk Analysis

58.

If an organization wants to proactively identify weaknesses in its protection of patient data, which administrative safeguard should it prioritize?

a)

Security Risk Analysis

b)

Security Awareness and Training

c)

Contingency Planning

d)

Sanction Policy

59.

What is the primary purpose of physical safeguards in an information system facility?

a)

To protect against natural hazards and unauthorized physical intrusion.

b)

To increase internet speed.

c)

To improve software performance.

d)

To reduce electricity consumption.

60.

Which of the following best describes the function of access control in physical safeguards?

a)

It controls physical access to sensitive areas and equipment.

b)

It encrypts electronic data.

c)

It monitors network traffic.

d)

It manages user passwords.

61.

A company wants to prevent unauthorized individuals from entering rooms with sensitive equipment. Which physical safeguard should they focus on improving?

a)

Access control

b)

Data encryption

c)

Software updates

d)

Cloud storage

62.

Which of the following is an example of Facility Access Controls?

a)

Using locks and keycard systems to control access to sensitive areas

b)

Positioning computer screens away from public view

c)

Shredding old hard drives

d)

Encrypting emails sent to patients

63.

What is the main purpose of Workstation Security in a healthcare setting?

a)

To position computer screens away from public view and use automatic logoff features

b)

To install antivirus software on all computers

c)

To require employees to change passwords monthly

d)

To monitor internet usage of staff

64.

Which procedure is most closely associated with Device and Media Controls?

a)

Shredding or pulverizing old hard drives containing patient data

b)

Installing surveillance cameras in hallways

c)

Requiring two-factor authentication for logins

d)

Backing up data to cloud storage

65.

A hospital wants to prevent unauthorized individuals from entering the medical records department. Which physical safeguard should they prioritize?

a)

Facility Access Controls

b)

Workstation Security

c)

Device and Media Controls

d)

Data Encryption Policies

66.

A healthcare organization is updating its policies to ensure that patient data on old hardware is not recoverable after disposal. Which safeguard are they improving?

a)

Device and Media Controls

b)

Facility Access Controls

c)

Workstation Security

d)

Network Security

67.

Why is it important to position computer screens away from public view in a medical office?

a)

To prevent unauthorized individuals from viewing sensitive patient information

b)

To reduce glare on the screens

c)

To improve employee comfort

d)

To save energy

68.

Which category includes technology and associated policies and procedures to protect electronic health information and control access to it?

a)

Technical Safeguards

b)

Physical Safeguards

c)

Administrative Safeguards

d)

Financial Safeguards

69.

What is the key function of technical safeguards in the context of electronic health information?

a)

To use technology itself to enforce security rules

b)

To train staff on privacy policies

c)

To monitor physical access to buildings

d)

To manage financial transactions

70.

How do technical safeguards act as "guardrails" on the data superhighway?

a)

By providing digital tools that enforce security rules

b)

By hiring security personnel

c)

By installing physical barriers

d)

By creating paper-based records

71.

Which of the following best describes the purpose of Access Controls in information systems?

a)

Assigning a unique username and strong password to every user and enforcing the "Principle of Least Privilege."

b)

Converting electronic data into an unreadable format.

c)

Implementing firewalls and intrusion detection systems.

d)

Recording and examining activity in information systems.

72.

What is the main function of Audit Controls in technical safeguards?

a)

To record and examine activity in information systems, creating a digital trail of who accessed what information and when.

b)

To encrypt data so it cannot be read without a key.

c)

To assign usernames and passwords to users.

d)

To prevent unauthorized access to data during transmission.

73.

Encryption is best defined as:

a)

The process of converting electronic data into an unreadable, scrambled format that can only be unlocked with a specific key.

b)

The use of firewalls to block unauthorized access.

c)

Assigning strong passwords to users.

d)

Recording user activity in a digital log.

74.

Which technical safeguard involves implementing firewalls and intrusion detection systems to protect data during transmission?

a)

Transmission Security

b)

Audit Controls

c)

Encryption

d)

Access Controls

75.

Imagine a company failed to implement Audit Controls. What potential risk could arise from this omission?

a)

Unauthorized access to sensitive information may go undetected.

b)

Data may be encrypted and unreadable.

c)

Users may have strong passwords.

d)

Data transmission may be secure.

76.

A hospital wants to ensure that only authorized personnel can access patient records and that each access is tracked. Which two technical safeguards should they prioritize?

a)

Access Controls and Audit Controls

b)

Encryption and Transmission Security

c)

Audit Controls and Transmission Security

d)

Access Controls and Encryption

77.

Which principle(s) of the CIA Triad has been compromised in the scenario where a nurse loses an unencrypted USB drive containing patient information?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation

78.

Identify at least one failure in each of the three safeguard categories (Administrative, Physical, Technical) that contributed to the incident described in the scenario.

a)

Lack of encryption (Technical), lack of policy enforcement (Administrative), lack of secure storage (Physical)

b)

Proper encryption (Technical), strong password policy (Administrative), secure storage (Physical)

c)

Regular software updates (Technical), employee training (Administrative), locked doors (Physical)

d)

Multi-factor authentication (Technical), regular audits (Administrative), surveillance cameras (Physical)

79.

As the HIM professional, what are the first two steps you would take after learning about the loss of the unencrypted USB drive?

a)

Report the incident and begin an investigation

b)

Ignore the incident and hope it is not discovered

c)

Delete all patient records from the system

d)

Inform the media immediately

80.

What is the main responsibility described in the role of a "Data Guardian"?

a)

Protecting data through a multi-layered defense

b)

Allowing unrestricted access to data

c)

Ignoring data security protocols

d)

Focusing only on physical security

81.

According to the material, what can happen if there is a weakness in one layer of safeguards?

a)

The other layers can become ineffective

b)

The system becomes faster

c)

Data is automatically encrypted

d)

The weakness is ignored

82.

Why is your role considered more critical with the national SATUSEHAT platform?

a)

Because the platform increases the importance of data protection

b)

Because the platform eliminates the need for security

c)

Because the platform is only used locally

d)

Because the platform does not store any data

83.

What is the purpose of building safer workflows as a Process Designer?

a)

To protect patient data at every step

b)

To speed up data processing

c)

To reduce the number of employees

d)

To avoid using technology

84.

As a proactive educator, what is your main responsibility?

a)

Championing security training

b)

Ignoring security protocols

c)

Focusing only on technical skills

d)

Avoiding communication with others

85.

How do the concepts of interconnected safeguards, process design, national importance, and proactive education collectively contribute to data protection? (DoK Level 3)

a)

They create a comprehensive approach that addresses vulnerabilities, ensures critical roles, designs secure workflows, and promotes ongoing education.

b)

They focus only on technical solutions without considering human factors.

c)

They are unrelated concepts that do not impact data protection.

d)

They only apply to small organizations, not national platforms.

86.

Which of the following best describes the role of a "Guardian" in the context of patient trust?

a)

Managing only patient records

b)

Guardian of patient trust and a vital part of Indonesia's national security

c)

Only providing technical support

d)

Focusing solely on administrative tasks

87.

What are the three safeguard layers mentioned for protecting healthcare data?

a)

Administrative, Physical, and Technical defenses

b)

Financial, Legal, and Social defenses

c)

Digital, Manual, and Automated defenses

d)

Medical, Educational, and Technical defenses

88.

Which network is mentioned as connecting healthcare across Indonesia?

a)

SATUSEHAT

b)

INDONET

c)

HEALTHLINK

d)

MEDINET

89.

Why is mastery of data privacy and security principles important for healthcare professionals in Indonesia?

a)

It makes them essential protectors in Indonesia's healthcare transformation

b)

It helps them avoid paperwork

c)

It allows them to work in any country

d)

It reduces the need for patient interaction

90.

How do administrative, physical, and technical defenses contribute to healthcare data protection?

a)

By working together to safeguard patient information

b)

By focusing only on digital threats

c)

By eliminating the need for patient consent

d)

By reducing healthcare costs