HCMT 3002 mod 6 and 7 questions
and answers graded A+
black box - correct answer ✔✔Because few CEOs or COOs have a background in HIT, the internal
workings of the HIT department have often been a "______" to mainstream healthcare
administrators
unplanned work - correct answer ✔✔A key indicator of the effectiveness of an HIT department
is the percentage of?
failed change, unauthorized change, no preventive work, configuration inconsistency, security
related patching and updating, too much access, and breach - correct answer ✔✔Examples of
unplanned work at low-performing HIT departments
Product failures, release failures, and human/user error - correct answer ✔✔Examples of
unplanned work at high-performing HIT departments:• Product failures• Release failures•
Human/user error
Unauthorized access• Data breaches• Malware and ransomware• Inside threats•
Manipulations• Vulnerabilities - correct answer ✔✔Threat of healthcare data
Big data breach - correct answer ✔✔Unintentional exposure of patient data due to inadequate
security measures or cyberattacks, leading to privacy violations and reputational damage
malware and ransomware - correct answer ✔✔can infect healthcare systems, encrypt data, and
demand a ransom for its release, disrupting patient care and compromising data integrity.
, Social engineering - correct answer ✔✔: Manipulation ofindividuals to divulge
sensitiveinformation, like passwords oraccess credentials, through tacticslike phishing or
pretexting
Data interception - correct answer ✔✔: unauthorized interception of data during transmission,
especially if not encrypted, can compromise patient confidentiality
Data Modification - correct answer ✔✔: Unauthorized alteration of patient records can lead
toincorrect treatment or diagnosis.
Third party vulnerability - correct answer ✔✔: Outsourcingservices to third-party vendors can
exposehealthcare data to risks if those vendorshave inadequate security measures
Lack of encryption - correct answer ✔✔: Failure toencrypt sensitive dataincreases the risk of
databreaches if devices are lostor stole
Lack of training and awareness - correct answer ✔✔:Healthcare staff unaware of
securityprotocols might inadvertently contributeto data breaches or other vulnerabilities
Scale, complexity, impact, and regulation - correct answer ✔✔4 factors to differentiate big and
conventional data breach
big: massive data volumes; conventional: compromise smaller datasets - correct answer
✔✔Differentiate scale of big and conventional data breach
big: use sophisticated methods; conventional: use common attack vendors - correct answer
✔✔Differentiate complexity of big and conventional data breach
big: organization, industries, and geopolitics; conventional: impacts the individual - correct
answer ✔✔Differentiate impact of big and conventional data breach
and answers graded A+
black box - correct answer ✔✔Because few CEOs or COOs have a background in HIT, the internal
workings of the HIT department have often been a "______" to mainstream healthcare
administrators
unplanned work - correct answer ✔✔A key indicator of the effectiveness of an HIT department
is the percentage of?
failed change, unauthorized change, no preventive work, configuration inconsistency, security
related patching and updating, too much access, and breach - correct answer ✔✔Examples of
unplanned work at low-performing HIT departments
Product failures, release failures, and human/user error - correct answer ✔✔Examples of
unplanned work at high-performing HIT departments:• Product failures• Release failures•
Human/user error
Unauthorized access• Data breaches• Malware and ransomware• Inside threats•
Manipulations• Vulnerabilities - correct answer ✔✔Threat of healthcare data
Big data breach - correct answer ✔✔Unintentional exposure of patient data due to inadequate
security measures or cyberattacks, leading to privacy violations and reputational damage
malware and ransomware - correct answer ✔✔can infect healthcare systems, encrypt data, and
demand a ransom for its release, disrupting patient care and compromising data integrity.
, Social engineering - correct answer ✔✔: Manipulation ofindividuals to divulge
sensitiveinformation, like passwords oraccess credentials, through tacticslike phishing or
pretexting
Data interception - correct answer ✔✔: unauthorized interception of data during transmission,
especially if not encrypted, can compromise patient confidentiality
Data Modification - correct answer ✔✔: Unauthorized alteration of patient records can lead
toincorrect treatment or diagnosis.
Third party vulnerability - correct answer ✔✔: Outsourcingservices to third-party vendors can
exposehealthcare data to risks if those vendorshave inadequate security measures
Lack of encryption - correct answer ✔✔: Failure toencrypt sensitive dataincreases the risk of
databreaches if devices are lostor stole
Lack of training and awareness - correct answer ✔✔:Healthcare staff unaware of
securityprotocols might inadvertently contributeto data breaches or other vulnerabilities
Scale, complexity, impact, and regulation - correct answer ✔✔4 factors to differentiate big and
conventional data breach
big: massive data volumes; conventional: compromise smaller datasets - correct answer
✔✔Differentiate scale of big and conventional data breach
big: use sophisticated methods; conventional: use common attack vendors - correct answer
✔✔Differentiate complexity of big and conventional data breach
big: organization, industries, and geopolitics; conventional: impacts the individual - correct
answer ✔✔Differentiate impact of big and conventional data breach