Health Information Compliance Alert

Security Quiz:

Can You Control Your Users' Access?

Test your access control smarts!

1. Who should be able to see your patients' PHI?
a. All of your employees.
b. Only those people who have been identified as needing the information.
c. No one -- PHI is secret!

2. Identification refers to:
a. How users prove who they are.
b. Who is allowed to use the network.
c. Who a user claims to be.

3. Authentication refers to:
a. How users prove who they are.
b. Who is allowed to use the network.
c. Who a user claims to be.

4. Which of the following combinations follows the best practices approach for allowing access to your patients' information?
a. Username and password.
b. Username, password and badge.
c. Username only.