Courseiva
easyMultiple Select

CAS-004 Practice Question: A healthcare organization is implementing HIPAA…

A healthcare organization is implementing HIPAA Security Rule safeguards. Which TWO of the following are required administrative safeguards? (Choose TWO.)

⚠ Common exam trap

On the CASP+ exam, the trap is correctly distinguishing between administrative, physical, and technical safeguards under HIPAA. Candidates often mistake technical controls like encryption (ePHI at rest) or unique user identification for administrative safeguards, or think facility access controls are administrative instead of physical. The required administrative safeguards listed are security management process and assigned security responsibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security management process.

Option A, Security management process, is correct because 45 CFR 164.308(a)(1) requires it as an administrative safeguard: covered entities must conduct a risk analysis, implement risk management, have a sanction policy, and review information system activity. Option D, Assigned security responsibility, is correct because 45 CFR 164.308(a)(2) requires the covered entity to designate a security official responsible for developing and implementing the security policies and procedures. Option B, Encryption of ePHI at rest, is not a required administrative safeguard; under 45 CFR 164.312(a)(2)(iv) and 164.312(e)(2)(ii) encryption is an addressable implementation specification under Technical Safeguards. Option C, Unique user identification, is a Technical Safeguard under 45 CFR 164.312(a)(2)(i), not an administrative safeguard. Option E, Facility access controls, is a Physical Safeguard under 45 CFR 164.310(a)(1), not an administrative safeguard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Security management process.

    Why this is correct

    The HIPAA Security Rule names the security management process as a required administrative safeguard. It obliges covered entities to conduct risk analysis, risk management, sanction policy and information system activity review, forming the governance foundation the rule mandates.

  • ✗

    Encryption of ePHI at rest.

    Why it's wrong here

    Encryption of ePHI at rest belongs to the HIPAA Security Rule's Technical Safeguards as an addressable implementation specification, not the Administrative Safeguards category. It is tempting because encryption is a recognised safeguard and often mandated by breach-notification rules, but the stem restricts the answer to administrative safeguards.

  • ✗

    Unique user identification.

    Why it's wrong here

    Unique user identification is a required implementation specification under the HIPAA Security Rule's Access Control standard, but that standard sits within Technical Safeguards, not Administrative Safeguards. It is tempting because it genuinely is mandatory, yet the stem asks specifically for administrative safeguards such as risk analysis and workforce security.

  • ✓

    Assigned security responsibility.

    Why this is correct

    Assigned security responsibility is a required administrative safeguard under the HIPAA Security Rule. It requires naming a specific security official accountable for developing and implementing the policies and procedures that protect electronic protected health information.

  • ✗

    Facility access controls.

    Why it's wrong here

    Facility access controls are physical safeguards under the HIPAA Security Rule, not administrative ones. They are tempting because they are required, but they govern building and room access; administrative safeguards instead cover workforce training, risk analysis, and contingency planning.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.