Font size
Worksheets6th Week Meeting
Total questions: 90
Worksheet time: 45mins
What standards are used to build the national "data superhighway" connecting healthcare facilities across Indonesia?
HL7 V2 standards
HL7 FHIR standards
ISO 9001 standards
TCP/IP standards
IEEE 802.11 standards
What is a major risk associated with the interconnected national data superhighway for healthcare in Indonesia?
A security failure at one small facility could compromise the entire system
Slow internet speeds across the network
High cost of data storage
Lack of healthcare professionals
Data breaches due to inadequate encryption
As future HIM professionals, what is a key responsibility to ensure the safety of the national data superhighway?
Reducing the amount of data collected
Implementing regular security audits
Increasing the number of healthcare facilities
Improving patient satisfaction surveys
Building guardrails and security measures
Which principles must be mastered to fulfill ethical and legal duties in managing the national data superhighway?
Data privacy and security
Financial management
Patient care techniques
Data governance
Marketing strategies
Given the risk of a security failure at a single Puskesmas, what strategic approach should be taken to prevent a national crisis?
Focus only on large hospitals for security upgrades
Increase the number of local incidents reported
Limit data sharing between facilities
Implement robust security measures and continuous monitoring across all facilities
Conduct regular security audits at all facilities
Which of the following is NOT a core principle of the CIA Triad in information security?
Integrity
Availability
Confidentiality
Authentication
Accountability
What is the ethical and legal duty of a Health Information Management (HIM) professional regarding patient information?
To share patient information with all staff
To protect patient information according to relevant legal provisions
To disclose patient information to unauthorized individuals
To store patient information without security measures
To ignore patient privacy concerns
Which regulation is cited as relevant for protecting patient information in Indonesian healthcare settings?
ISO 27001
PMK 24/2022
HIPAA
GDPR
UU ITE (Information and Electronic Transactions Law)
Which of the following is an example of an internal threat to health data in healthcare settings?
An employee accessing patient data without authorization
A hacker from outside the organization
An employee sharing passwords with unauthorized personnel
A natural disaster damaging servers
A virus sent via email from an external source
How do administrative, physical, and technical safeguards differ in healthcare data protection?
Physical safeguards are more important than technical safeguards
Technical safeguards are only about software solutions
Administrative safeguards involve policies, physical safeguards involve facility security, and technical safeguards involve technology controls
They all refer to the same type of security measure
Administrative safeguards are only for IT staff, physical safeguards are for patients, and technical safeguards are for doctors
When analyzing a basic data breach scenario in healthcare, which principles should be applied?
Privacy and security principles
Marketing principles
Customer service principles
Financial principles
Compliance principles
Which of the following is NOT a component of the CIA Triad in information security?
Accountability
Confidentiality
Integrity
Availability
Authentication
What does the 'Confidentiality' aspect of the CIA Triad focus on?
Increasing system performance
Ensuring timely access for users
Protecting sensitive information from unauthorized access
Maintaining accuracy and trustworthiness
Preventing unauthorized disclosure
How does 'Integrity' contribute to information security according to the CIA Triad?
By allowing public access to data
By maintaining accuracy and trustworthiness
By encrypting all information
By ensuring data is not altered or tampered with
By keeping the patient's story secret
Which scenario best illustrates the 'Availability' principle of the CIA Triad?
A bank verifies the accuracy of transaction records.
A company encrypts all its emails to prevent leaks.
A school restricts access to student grades to only teachers.
A hospital system ensures patient records are accessible to doctors whenever needed.
A cloud service guarantees uptime for its users.
The CIA Triad forms the foundation for regulations like HIPAA in the U.S. and data protection strategies in Indonesia by:
Focusing solely on user authentication methods
Providing guidelines for system performance optimization
Establishing core principles for protecting information: confidentiality, integrity, and availability
Ensuring data is accessible to authorized users only
Promoting open access to all data
What is the main purpose of the principle of confidentiality in healthcare?
To ensure that patient information is kept private and secure
To restrict data access so only authorized individuals can view or handle it
To allow anyone in the hospital to access patient records
To share patient information with family and friends
To post patient stories on social media for awareness
According to the Indonesian context example, what should a registration clerk at a Puskesmas NOT do?
Share patient information with unauthorized individuals
Look up a neighbor's medical record out of curiosity
Register new patients
Schedule appointments for patients
File medical records properly
Which of the following is considered a breach of confidentiality?
Discussing a patient's diagnosis in a public hospital elevator where others can overhear
Reviewing a patient's file in a private office
Updating a patient's record in a secure system
Sharing information with authorized medical staff
Leaving patient files open on a desk in a shared workspace
Why is it important to ensure that only the right people are able to see patient information?
To allow for more open communication in public spaces
To encourage curiosity among hospital staff
To make hospital operations faster
To protect patient privacy and prevent unauthorized access
To maintain the confidentiality of sensitive health data
A doctor is about to discuss a patient's diagnosis in a crowded hospital elevator. What should the doctor do to maintain confidentiality?
Speak loudly so everyone can hear
Share the diagnosis with anyone who asks
Wait until in a private setting to discuss the diagnosis
Ignore confidentiality rules in public spaces
Discuss the diagnosis only with authorized personnel
Which of the following best defines the principle of integrity in the context of patient data?
Ensuring that only authorized personnel can access patient data.
Encrypting patient data to prevent unauthorized access.
Regularly auditing patient data to ensure its accuracy and consistency.
Maintaining the accuracy, consistency, and trustworthiness of data throughout its entire lifecycle, protecting it from unauthorized alteration or destruction.
Making patient data available at all times, even during system failures.
In the Indonesian context, why must a patient's blood type or allergy information be protected after it is entered into the system?
To make the information available to insurance companies.
To ensure the information is not changed accidentally or maliciously.
To maintain the confidentiality of the patient's medical history.
To prevent unauthorized access to the patient's financial records.
To allow doctors to update the information as needed.
What is a possible consequence of a failure of integrity in an electronic health record (EHR) system?
Increased data storage costs
Improved patient privacy
Severe patient harm or even death
Faster access to patient data
Loss of patient trust
Suppose an attacker changes a patient's medication dosage in the EHR. Which core question should healthcare professionals ask to ensure patient safety?
How quickly can this information be retrieved?
Who has accessed this information?
Is this information encrypted?
Is this information accurate and can it be trusted?
What is the source of this information?
What does the principle of availability ensure in the context of systems, applications, and data?
That systems are only available during business hours
That data is always encrypted and never accessible
That only unauthorized users can access data at any time
That systems, applications, and data are accessible to authorized users when and where needed
That data is accessible to users only during scheduled maintenance
In the Indonesian context example, why is it important for a physician to access a patient's complete history from the SATUSEHAT platform during an emergency?
To schedule a follow-up appointment
To update the patient's insurance information
To check the patient's billing status
To ensure the physician can provide appropriate care without delay
To review the patient's previous medical treatments
Which of the following best describes a failure of availability in a hospital's EHR system?
A system that provides real-time analytics
A system that automatically updates patient records
A system that allows unauthorized access to patient data
A system that is down for maintenance during peak hours
A ransomware attack that encrypts and locks the system, forcing cancellation of surgeries
Why can a ransomware attack on a hospital's EHR system compromise patient safety?
It increases the number of available doctors
It leads to delays in patient treatment
It enhances the security of patient data
It forces the cancellation of surgeries and prevents access to critical information
It improves the speed of data access
Suppose a hospital's EHR system is unavailable during an emergency. What is the most likely consequence?
Patient safety may be compromised due to lack of information
Patients receive faster care
Physicians can access all patient data without issues
Emergency staff may have to rely on memory for patient history
The hospital's internet speed increases
Which article of PMK 24/2022 explicitly mandates that medical record content must be kept confidential?
Article 10
Article 7
Article 29
Article 15
Article 42
What does the "Legal Duty" represent for HIM professionals according to PMK 24/2022?
The technical management of medical records
The obligation to maintain patient confidentiality
The financial responsibility of the HIM professional
The daily execution of ethical duties
The embodiment of the HIM professional's sacred trust with the patient
How does the "Guardian Role" reinforce the responsibilities of HIM professionals?
By training new staff members
By managing financial records
By safeguarding patient confidentiality
By ensuring daily execution of tasks
By entrusting them to protect the patient's personal property
Which of the following best describes "Daily Execution" in the context of the CIA Triad and PMK 24/2022?
The tangible, day-to-day execution of ethical and legal duty
The routine monitoring of patient care standards
The annual review of medical records
The financial auditing of hospital expenses
The creation of new patient files
How are the principles of the CIA Triad integrated into legal mandates for HIM professionals under PMK 24/2022?
They are used for training purposes only.
They only apply to financial records, not medical records.
They are optional guidelines for best practices.
They are codified as law, requiring confidentiality and ethical management of medical records.
They are enforced through regular audits and compliance checks.
Which of the following is the leading cause of major healthcare data breaches today?
Physical theft
Insider threats
Phishing
Hacking & Ransomware
Malware attacks
Phishing is best described as:
A way to physically steal patient records
A direct attack on data availability
A technique to deceive individuals into providing sensitive information
A form of malware that encrypts files
A method used by attackers to trick employees and gain initial access
Explain why healthcare is considered a prime target for cyber threats, using evidence from the black market value of patient health records and the types of attacks described.
Healthcare data is highly valuable and targeted by sophisticated external threats such as hacking, ransomware, and phishing.
Healthcare organizations have the least amount of data compared to other industries.
Healthcare data is rarely targeted by cyber criminals.
Patient health records can be sold on the black market for significant amounts of money.
Healthcare data is only valuable for research purposes.
Which of the following is an example of an unintentional/careless insider threat?
Sabotage
Accidental data exposure
Data theft
Inadvertent sharing of sensitive information
Unauthorized access
What is a common motivation for a malicious insider?
Financial gain
Forgetfulness
Lack of training
Revenge against the company
System malfunction
Why are internal threats particularly dangerous in organizations?
They only affect external networks
They are easy to detect
They always use advanced hacking tools
Insiders already have legitimate access to systems
Insiders can manipulate data without raising suspicion
A hospital employee loses an unencrypted USB drive containing patient data. What type of internal threat does this scenario represent?
Unintentional/Careless Insider
Negligent Employee
System Administrator
Malicious Insider
External Hacker
Compare and contrast the actions of unintentional/careless insiders and malicious insiders in the context of data breaches. Provide one example for each.
Unintentional/careless insiders might share sensitive information mistakenly, while malicious insiders could sell that information to competitors.
Malicious insiders never have access to sensitive data, while unintentional/careless insiders always do.
Both types always act intentionally to harm the organization.
Unintentional/careless insiders only work outside the organization, while malicious insiders work inside.
Unintentional/careless insiders may expose data accidentally, such as losing a device, while malicious insiders intentionally steal data for personal gain, such as unauthorized access.
Which of the following is NOT one of the three distinct categories of safeguards in a multi-layered security strategy?
Financial Safeguards
Administrative Safeguards
Physical Safeguards
Technical Safeguards
Operational Safeguards
What is the main reason a multi-layered defense is required in a comprehensive security program?
It is required only for small organizations
It is easier to manage
It provides redundancy in case of failure
It is cheaper than a single defense
No single defense is sufficient
Why is the "defense-in-depth" approach considered a global best practice in security?
It is the cheapest method available
It is required by major regulations and provides comprehensive protection
It only uses technology for defense
It offers multiple layers of security to mitigate risks
It eliminates the need for policies
Which of the following best describes the purpose of administrative safeguards in an organization?
To design the physical layout of the office.
To install firewalls and antivirus software.
To establish formal rules and structures for how the organization will protect data.
To manage only the financial records of the organization.
To ensure compliance with legal and regulatory requirements.
What is the primary focus of the 'People & Policy' layer in administrative safeguards?
Managing administrative actions, policies, and procedures to govern workforce conduct and security measures.
Developing new software for the organization.
Purchasing office equipment.
Marketing the organization's services.
Why are administrative safeguards considered a critical defense against human error?
They provide rules and structures that guide workforce behavior and security practices.
They prevent all types of cyberattacks automatically.
They eliminate the need for employee training.
They focus only on technical solutions.
How does the role of a Health Information Management (HIM) professional come to life in the context of administrative safeguards?
By acting as an educator and process designer for data protection policies.
By repairing computer hardware.
By handling only patient billing.
By designing the organization's logo.
Which of the following best describes Security Risk Analysis in the context of administrative safeguards?
The formal process of identifying potential threats and vulnerabilities to patient data.
The process of training employees on security policies.
The enforcement of consequences for violating security policies.
The development of data backup and disaster recovery plans.
What is the primary purpose of Contingency Planning as an administrative safeguard?
To develop and maintain data backup, disaster recovery, and emergency mode operation plans to ensure availability.
To identify threats and vulnerabilities to patient data.
To train employees on recognizing phishing threats.
To enforce consequences for security policy violations.
Why is Security Awareness and Training considered a key administrative safeguard?
It provides mandatory, ongoing training for all employees on security policies and how to recognize threats like phishing.
It ensures data backup and disaster recovery.
It identifies vulnerabilities in patient data.
It enforces consequences for policy violations.
Which administrative safeguard involves establishing and enforcing documented consequences for employees who violate security policies?
Sanction Policy
Security Risk Analysis
Contingency Planning
Security Awareness and Training
Imagine a healthcare organization experiences a ransomware attack that threatens the availability of patient data. Which administrative safeguard would be most directly involved in responding to this situation?
Contingency Planning
Security Awareness and Training
Sanction Policy
Security Risk Analysis
An employee repeatedly ignores security policies and clicks on suspicious email links. Which administrative safeguard should be applied to address this behavior?
Sanction Policy
Security Risk Analysis
Contingency Planning
Security Awareness and Training
A hospital wants to reduce the risk of phishing attacks among its staff. Which administrative safeguard should it focus on strengthening?
Security Awareness and Training
Contingency Planning
Sanction Policy
Security Risk Analysis
If an organization wants to proactively identify weaknesses in its protection of patient data, which administrative safeguard should it prioritize?
Security Risk Analysis
Security Awareness and Training
Contingency Planning
Sanction Policy
What is the primary purpose of physical safeguards in an information system facility?
To protect against natural hazards and unauthorized physical intrusion.
To increase internet speed.
To improve software performance.
To reduce electricity consumption.
Which of the following best describes the function of access control in physical safeguards?
It controls physical access to sensitive areas and equipment.
It encrypts electronic data.
It monitors network traffic.
It manages user passwords.
A company wants to prevent unauthorized individuals from entering rooms with sensitive equipment. Which physical safeguard should they focus on improving?
Access control
Data encryption
Software updates
Cloud storage
Which of the following is an example of Facility Access Controls?
Using locks and keycard systems to control access to sensitive areas
Positioning computer screens away from public view
Shredding old hard drives
Encrypting emails sent to patients
What is the main purpose of Workstation Security in a healthcare setting?
To position computer screens away from public view and use automatic logoff features
To install antivirus software on all computers
To require employees to change passwords monthly
To monitor internet usage of staff
Which procedure is most closely associated with Device and Media Controls?
Shredding or pulverizing old hard drives containing patient data
Installing surveillance cameras in hallways
Requiring two-factor authentication for logins
Backing up data to cloud storage
A hospital wants to prevent unauthorized individuals from entering the medical records department. Which physical safeguard should they prioritize?
Facility Access Controls
Workstation Security
Device and Media Controls
Data Encryption Policies
A healthcare organization is updating its policies to ensure that patient data on old hardware is not recoverable after disposal. Which safeguard are they improving?
Device and Media Controls
Facility Access Controls
Workstation Security
Network Security
Why is it important to position computer screens away from public view in a medical office?
To prevent unauthorized individuals from viewing sensitive patient information
To reduce glare on the screens
To improve employee comfort
To save energy
Which category includes technology and associated policies and procedures to protect electronic health information and control access to it?
Technical Safeguards
Physical Safeguards
Administrative Safeguards
Financial Safeguards
What is the key function of technical safeguards in the context of electronic health information?
To use technology itself to enforce security rules
To train staff on privacy policies
To monitor physical access to buildings
To manage financial transactions
How do technical safeguards act as "guardrails" on the data superhighway?
By providing digital tools that enforce security rules
By hiring security personnel
By installing physical barriers
By creating paper-based records
Which of the following best describes the purpose of Access Controls in information systems?
Assigning a unique username and strong password to every user and enforcing the "Principle of Least Privilege."
Converting electronic data into an unreadable format.
Implementing firewalls and intrusion detection systems.
Recording and examining activity in information systems.
What is the main function of Audit Controls in technical safeguards?
To record and examine activity in information systems, creating a digital trail of who accessed what information and when.
To encrypt data so it cannot be read without a key.
To assign usernames and passwords to users.
To prevent unauthorized access to data during transmission.
Encryption is best defined as:
The process of converting electronic data into an unreadable, scrambled format that can only be unlocked with a specific key.
The use of firewalls to block unauthorized access.
Assigning strong passwords to users.
Recording user activity in a digital log.
Which technical safeguard involves implementing firewalls and intrusion detection systems to protect data during transmission?
Transmission Security
Audit Controls
Encryption
Access Controls
Imagine a company failed to implement Audit Controls. What potential risk could arise from this omission?
Unauthorized access to sensitive information may go undetected.
Data may be encrypted and unreadable.
Users may have strong passwords.
Data transmission may be secure.
A hospital wants to ensure that only authorized personnel can access patient records and that each access is tracked. Which two technical safeguards should they prioritize?
Access Controls and Audit Controls
Encryption and Transmission Security
Audit Controls and Transmission Security
Access Controls and Encryption
Which principle(s) of the CIA Triad has been compromised in the scenario where a nurse loses an unencrypted USB drive containing patient information?
Confidentiality
Integrity
Availability
Non-repudiation
Identify at least one failure in each of the three safeguard categories (Administrative, Physical, Technical) that contributed to the incident described in the scenario.
Lack of encryption (Technical), lack of policy enforcement (Administrative), lack of secure storage (Physical)
Proper encryption (Technical), strong password policy (Administrative), secure storage (Physical)
Regular software updates (Technical), employee training (Administrative), locked doors (Physical)
Multi-factor authentication (Technical), regular audits (Administrative), surveillance cameras (Physical)
As the HIM professional, what are the first two steps you would take after learning about the loss of the unencrypted USB drive?
Report the incident and begin an investigation
Ignore the incident and hope it is not discovered
Delete all patient records from the system
Inform the media immediately
What is the main responsibility described in the role of a "Data Guardian"?
Protecting data through a multi-layered defense
Allowing unrestricted access to data
Ignoring data security protocols
Focusing only on physical security
According to the material, what can happen if there is a weakness in one layer of safeguards?
The other layers can become ineffective
The system becomes faster
Data is automatically encrypted
The weakness is ignored
Why is your role considered more critical with the national SATUSEHAT platform?
Because the platform increases the importance of data protection
Because the platform eliminates the need for security
Because the platform is only used locally
Because the platform does not store any data
What is the purpose of building safer workflows as a Process Designer?
To protect patient data at every step
To speed up data processing
To reduce the number of employees
To avoid using technology
As a proactive educator, what is your main responsibility?
Championing security training
Ignoring security protocols
Focusing only on technical skills
Avoiding communication with others
How do the concepts of interconnected safeguards, process design, national importance, and proactive education collectively contribute to data protection? (DoK Level 3)
They create a comprehensive approach that addresses vulnerabilities, ensures critical roles, designs secure workflows, and promotes ongoing education.
They focus only on technical solutions without considering human factors.
They are unrelated concepts that do not impact data protection.
They only apply to small organizations, not national platforms.
Which of the following best describes the role of a "Guardian" in the context of patient trust?
Managing only patient records
Guardian of patient trust and a vital part of Indonesia's national security
Only providing technical support
Focusing solely on administrative tasks
What are the three safeguard layers mentioned for protecting healthcare data?
Administrative, Physical, and Technical defenses
Financial, Legal, and Social defenses
Digital, Manual, and Automated defenses
Medical, Educational, and Technical defenses
Which network is mentioned as connecting healthcare across Indonesia?
SATUSEHAT
INDONET
HEALTHLINK
MEDINET
Why is mastery of data privacy and security principles important for healthcare professionals in Indonesia?
It makes them essential protectors in Indonesia's healthcare transformation
It helps them avoid paperwork
It allows them to work in any country
It reduces the need for patient interaction
How do administrative, physical, and technical defenses contribute to healthcare data protection?
By working together to safeguard patient information
By focusing only on digital threats
By eliminating the need for patient consent
By reducing healthcare costs
