EO 001.03 - CFHIS Flashcards

1
Q

Describe CFHS compliance with federal privacy legislation and policies

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Describe CFHS confidentiality rules

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Describe compliance with federal and DND physical and electronic security policies

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Describe rules for CFHIS access

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the purpose of audit logs

A

The purpose of audit logs is for system administration, maintenance, security, and to ensure compliance with Treasury Board Secretariat, DND/CAF orders, policies, instructions, directives and standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Describe investigation processes and infraction penalties

A

Infraction penalties can include temporary suspension, revocation, or permanent termination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Define Security techniques

A

Security techniques refers to the procedures and tools we use to protect information entrusted to us

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the three types of security levels?

A
  1. Public (Unclassified)
  2. Classified (Confidential, Secret, or Top Secret)
  3. Designated (PROTECTED A, B, C)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Define the Need-To-Know principle

A

Only persons who have a requirement to perform their official duties shall access PHI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Define Disclosure

A

The release or transfer of personal information by any to any body or person

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are three rules that must comply with “PROTECTED B” information?

A
  1. Clearly label (on every header, footer, and envelope side)
  2. Destroy in approved shredders/burn bags
  3. Encrypt when electronically stored or sent
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define Personal Information

A

Information about an identifiable individual

(i.e. race, national/ethnic origin, religion, educational/medical history, identifying numbers/symbols)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Define Personal Health Information (PHI)

A

Personal information that relates to an individual’s diagnostic, treatment, or care information

(i.e. medical/dental/psychosocial information collected during care

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What type of information is NOT applicable to PHI?

A
  • A CAF member’s medical employment limitations
  • Anticipated absences from the workplace
  • Prognosis
  • General severity of an acute health condition
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or false, all CAF health records are property of the crown

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

List acceptable reasons to disclose PHI

A
  • Patient authorized disclosure
  • Printing/copying a CAF health record where required in the performance of official duties
  • Release outlined on a court order, warrant, writ, summons, or other process issued by a court
  • MELs, anticipated absences, prognosis/severity of a health condition to the CoC of the member
17
Q

CAF members are;

a) Have the right to access of their own information

b) Are only entitled to request access to their information

A

Correct answer: B

Members are only entitled to request access to their own information

18
Q

Access to CFHIS will require what?

A
  • DWAN account
  • CFHIS account
  • Public key infrastructure card
  • CFHIS equipped treatment bay (computer)
19
Q

All suspected breaches MUST be reported to:

A
  • Your manager/supervisor
  • CH H Svcs Gp Privacy Office
  • Local ISSO
  • CFHIS Local and/or National ISSO
20
Q

What are the nine responsibilities of the CFHIS user?

A
  1. Only use PHI to perform official duties
  2. Use and disclose PHI if needed by adhering to the Privacy Act
  3. Disclose the nature of any conflict of duties to CO, immediate supervisor
  4. Only request access to your own PHI as per DAOSs 1002-1 & 1002-2
  5. Only use your own CFHIS user account and PKI card when electronically accessing PHI
  6. Ensure terminals or workstations in use are logged off or unlocked when unattended or not in use
  7. Inform the helpdesk and CFHIS local ISSO if your CFHIS user account is no longer required
  8. Promptly report all known or suspected losses or compromises of PHI to your CO, immediate supervisor or ISSO
  9. Read, understand and observe the directives, orders, instructions and policies in the CFHIS e-learning modules
21
Q

Audit logs record every transaction users make in CFHIS, true or false?

A

True, every transaction is recorded including the following information:

  • User name
  • Folder opened
  • Document/record which was viewed/modified/printed
  • Patient name or record assessed
  • Date and time of access
22
Q

What does CFHIS stand for?

A

Canadian Forces Health Information System

23
Q

What does DAIP stand for?

A

Directorate of Access to Information and Privacy

24
Q

What does DAOD stand for?

A

Defense Administrative Orders and Directives

25
Q

What does DHSD stand for?

A

Director Health Services Delivery

26
Q

What does EHR stand for?

A

Electronic Health Record

27
Q

What does ISSO stand for?

A

Information System Security Officer

28
Q

What does PHI stand for?

A

Personal Health Information

29
Q

What does PKI stand for?

A

Public Key Infrastructure

30
Q

True or false, patients may request to see who has accessed their CFHIS records?

A

True.

The Audit log will be supplied to the Local ISSO and the patient will be provided with verbal guidance from the CFHIS Local ISSO or the CFHIS National ISSO on how to read the log.

31
Q

What is CFHIS used for?

A
  • Booking and management of patient appointments
  • Recording and reviewing patient history (i.e. attached documents, imaging reports, lab results, etc)
  • Management of the recall list and waiting list