Deck 22: Continuity Planning and Management Disaster Recovery
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/29
Play
Full screen (f)
Deck 22: Continuity Planning and Management Disaster Recovery
1
Which of the following statements is not true about continuity planning?
A)A good continuity plan is intentionally ambiguous to prevent hacking.
B)Wait time decreases satisfaction and can diminish quality of care.
C)Health care organizations are catching up with other industries in understanding the business case for continuity of operations.
D)Health care organizations must be able to effectively deal with crises.
A)A good continuity plan is intentionally ambiguous to prevent hacking.
B)Wait time decreases satisfaction and can diminish quality of care.
C)Health care organizations are catching up with other industries in understanding the business case for continuity of operations.
D)Health care organizations must be able to effectively deal with crises.
A good continuity plan is intentionally ambiguous to prevent hacking.
2
A continuity plan is a critical aspect of an organization's risk management strategy and is instrumental to its survival in the aftermath of a disaster. Tolerance for IT downtime is rapidly declining; a recent survey set the figure at how many hours or less?
A)5 hours
B)10 hours
C)18 hours
D)24 hours
A)5 hours
B)10 hours
C)18 hours
D)24 hours
5 hours
3
Which of the following authorized the development of a national, near real-time information network to coordinate federal and state response to public health emergencies?
A)Health Insurance Portability and Accountability Act
B)Pandemic and All-Hazards Preparedness Act
C)Sarbanes-Oxley Act
D)Federal Information Privacy and Security Act
A)Health Insurance Portability and Accountability Act
B)Pandemic and All-Hazards Preparedness Act
C)Sarbanes-Oxley Act
D)Federal Information Privacy and Security Act
Pandemic and All-Hazards Preparedness Act
4
The 24-hour-a-day, 7-days-a-week operations of health care providers make continuity of services essential. What is the first line of defense in providing the continuous systems availability that is required in a health care setting?
A)Adequate firewall protection
B)Software redundancy
C)Installing anti-virus software
D)Hardware redundancy
A)Adequate firewall protection
B)Software redundancy
C)Installing anti-virus software
D)Hardware redundancy
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
5
The second step in continuity planning is the development of the plan itself. This step determines the probabilities of all types of disasters, their impact on critical functions, and which of the following other concerns?
A)Business impact analysis
B)Systematic evaluation
C)Factors necessary to restore services
D)Policies, procedures and vendor contracts
A)Business impact analysis
B)Systematic evaluation
C)Factors necessary to restore services
D)Policies, procedures and vendor contracts
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
6
Together the Joint Commission and HIPAA require that health care providers perform a business impact analysis, employ crisis management, conduct employee training, implement ongoing continuity plan reviews, plan for information technology disasters and recovery, and audit their continuity plan processes. There are other groups that demonstrate interest in business continuity management. Which of the following are included in those other groups?
A)National Institute of Standards and Technology (NIST)
B)Disaster Recovery Institute International
C)Federal Emergency Management Agency (FEMA)
D)Food and Drug Administration (FDA)
E)Bioterrorism Working Group, Centers for Disease Control and Prevention (CDC)
A)National Institute of Standards and Technology (NIST)
B)Disaster Recovery Institute International
C)Federal Emergency Management Agency (FEMA)
D)Food and Drug Administration (FDA)
E)Bioterrorism Working Group, Centers for Disease Control and Prevention (CDC)
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
7
In 2001, the Joint Commission introduced new emergency management standards for hospitals, long-term care facilities, and behavioral health and ambulatory care that focus on the concept of community involvement in the management process. What event was recently added by the Joint Commission to the list of events that organizations must consider in their plans?
A)Disaster preparedness
B)Bioterrorism
C)Information security
D)Recovery planning
A)Disaster preparedness
B)Bioterrorism
C)Information security
D)Recovery planning
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
8
A good continuity plan can anticipate problems and minimize losses incurred by damage. Which of the following are advantages associated with continuity planning?
A)Strategies for correction of organization vulnerabilities
B)Allowing time for restoration of equipment, facility, and services
C)Means to capture information needed for regulatory and accrediting bodies
D)Providing continuity of client records and delivery of care
E)Complete protection against interruption in services
A)Strategies for correction of organization vulnerabilities
B)Allowing time for restoration of equipment, facility, and services
C)Means to capture information needed for regulatory and accrediting bodies
D)Providing continuity of client records and delivery of care
E)Complete protection against interruption in services
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
9
Many health care agencies lack the infrastructure to accommodate and support information systems (IS) during an environmental disaster. Which of the following can threaten IS during an environmental disaster?
A)A 10-day supply of fuel to power generators
B)Presence of excessive heat
C)Underground power lines
D)Housing IS in areas above the first floor
A)A 10-day supply of fuel to power generators
B)Presence of excessive heat
C)Underground power lines
D)Housing IS in areas above the first floor
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
10
Which of the following occurrences may not qualify as a disaster?
A)A virus infects a walk-in clinic's electronic medical record (EMR) system and randomly deletes data on Friday afternoon.The IT staff is on vacation.
B)The rheumatology department of a multi-specialty clinic is without analog telephone access for two hours (computer network connections remain intact).
C)The health department is wiped out after a fire.
D)A hospital is without electrical power for 48 hours due to a hurricane and flooding.
A)A virus infects a walk-in clinic's electronic medical record (EMR) system and randomly deletes data on Friday afternoon.The IT staff is on vacation.
B)The rheumatology department of a multi-specialty clinic is without analog telephone access for two hours (computer network connections remain intact).
C)The health department is wiped out after a fire.
D)A hospital is without electrical power for 48 hours due to a hurricane and flooding.
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
11
Which of the following statements are accurate about emergency and backup plans?
A)An emergency plan outlines steps to ensure the availability of resources for ongoing business and information system processing operations whereas a backup plan provides direction during and immediately after an incident.
B)An emergency plan is tested routinely whereas a backup plan is only used if the emergency plan fails.
C)Emergency and backup plans are the same.
D)A backup plan outlines steps to ensure the availability of resources for ongoing business and information system processing operations whereas an emergency plan provides direction during and immediately after an incident.
A)An emergency plan outlines steps to ensure the availability of resources for ongoing business and information system processing operations whereas a backup plan provides direction during and immediately after an incident.
B)An emergency plan is tested routinely whereas a backup plan is only used if the emergency plan fails.
C)Emergency and backup plans are the same.
D)A backup plan outlines steps to ensure the availability of resources for ongoing business and information system processing operations whereas an emergency plan provides direction during and immediately after an incident.
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
12
Each organization must select its criteria for business disaster recovery timeframes based upon its own perspective. Data flowcharts help to ensure which of the following?
A)The timeframes are appropriate
B)Integrity of the information is maintained
C)All critical processes are documented
D)No personnel are left out of the process
A)The timeframes are appropriate
B)Integrity of the information is maintained
C)All critical processes are documented
D)No personnel are left out of the process
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
13
In continuity planning, which of the following is a component of the business impact assessment (BIA)?
A)Secure top management support
B)Establish continuity maintenance policies and procedures
C)Assess continuity plan for weaknesses
D)Determine critical functions of the organization
A)Secure top management support
B)Establish continuity maintenance policies and procedures
C)Assess continuity plan for weaknesses
D)Determine critical functions of the organization
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
14
The two primary sources of data loss are ____ ____ and mechanical failure.
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
15
Lost or damaged data have a negative impact on business processes, impede the delivery of safe care, reduce productivity, and undermine public confidence. It is estimated that somewhere between what percentage of organizations that have incurred a significant downtime with data loss will go out of business within five years?
A)40 to 90%
B)20 to 70%
C)10 to 50%
D)30 to 80%
A)40 to 90%
B)20 to 70%
C)10 to 50%
D)30 to 80%
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
16
Health care agencies incorporate a continuity plan to ensure business continuity and successful recovery after a disaster. Which of the following is the most effective way to emphasize the importance of disaster preparedness?
A)Conduct staff reviews of continuity and recovery plans
B)Test the emergency staff notification system
C)Incorporate mock disaster situations into staff training
D)Display continuity plans in conspicuous places
A)Conduct staff reviews of continuity and recovery plans
B)Test the emergency staff notification system
C)Incorporate mock disaster situations into staff training
D)Display continuity plans in conspicuous places
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
17
The Joint Commission suggests that organizations conduct at least how many emergency drill(s) per year?
A)One
B)Two
C)Three
D)Four
A)One
B)Two
C)Three
D)Four
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
18
The focus of disaster planning in electronic health care information should be on which of the following?
A)Ensuring that all patient care information is available in hardcopy
B)Safeguarding business continuity by protection of health care data
C)Supporting patient care by providing continual access to patient information
D)Recovery and restoration of health care data and information
E)Stopping all patient care until the disaster is over
A)Ensuring that all patient care information is available in hardcopy
B)Safeguarding business continuity by protection of health care data
C)Supporting patient care by providing continual access to patient information
D)Recovery and restoration of health care data and information
E)Stopping all patient care until the disaster is over
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
19
The HIPAA security rule requires continuity planning and disaster recovery processes for protected health information. Which of the following activities are required in order to safeguard protected patient information?
A)Lowering security requirements during a disaster
B)Development of disaster recovery processes
C)Establishment of a continuity plan
D)Creation, access, storage, and destruction of manual records
E)Give access codes and usernames to emergency personnel
A)Lowering security requirements during a disaster
B)Development of disaster recovery processes
C)Establishment of a continuity plan
D)Creation, access, storage, and destruction of manual records
E)Give access codes and usernames to emergency personnel
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
20
What is metadata?
A)Data stored off site in a cold storage facility
B)A set of data that provides information about how, when, and by whom data are collected, formatted, and stored
C)A backup copy of all data within an organization
D)A set of data that is transferred electronically over high-speed telephone lines to another site and set to expire at the correct time
A)Data stored off site in a cold storage facility
B)A set of data that provides information about how, when, and by whom data are collected, formatted, and stored
C)A backup copy of all data within an organization
D)A set of data that is transferred electronically over high-speed telephone lines to another site and set to expire at the correct time
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
21
Which of the following are advantages of continuity planning?
A)Identifies strategies for correction of vulnerabilities within the organization
B)Provides a reasonable amount of protection against interruption in services, downtime, and data loss
C)Allows time for restoration of equipment, the facility, and services
D)Helps to ensure compliance with HIPAA legislation and requirements of the Joint Commission
E)Expedites reporting of diagnostic tests
A)Identifies strategies for correction of vulnerabilities within the organization
B)Provides a reasonable amount of protection against interruption in services, downtime, and data loss
C)Allows time for restoration of equipment, the facility, and services
D)Helps to ensure compliance with HIPAA legislation and requirements of the Joint Commission
E)Expedites reporting of diagnostic tests
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
22
Post-disaster feedback is crucial to the design and implementation of a better continuity plan for future health care agency use. Which of the following supports this statement?
A)The feedback should be used to identify what worked and what did not.Plans that looked good before a disaster may not look so good after one.
B)Feedback collected after disasters (or mock disasters) is not useful since the staff had no other options during the disaster.
C)Feedback collected after disasters (or mock disasters) is not necessarily accurate.
D)Feedback collected after disasters (or mock disasters) provides data for change in a limited number of areas.
A)The feedback should be used to identify what worked and what did not.Plans that looked good before a disaster may not look so good after one.
B)Feedback collected after disasters (or mock disasters) is not useful since the staff had no other options during the disaster.
C)Feedback collected after disasters (or mock disasters) is not necessarily accurate.
D)Feedback collected after disasters (or mock disasters) provides data for change in a limited number of areas.
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
23
Which law authorized development of a national, near-real-time information network to coordinate federal and state response to public health emergencies?
A)HIPAA
B)The Pandemic and All-Hazards Preparedness Act (PAHPA)
C)Sarbanes-Oxley Act of 2002
D)The Federal Information Privacy and Security Act of 2002
A)HIPAA
B)The Pandemic and All-Hazards Preparedness Act (PAHPA)
C)Sarbanes-Oxley Act of 2002
D)The Federal Information Privacy and Security Act of 2002
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
24
Business continuity planning (BCP) is not a one-step or one-time activity but is a set of successive stages that are repeated periodically. It is best characterized as a life cycle. Which of the following supports continuity planning?
A)Lost or corrupted data are costly to re-create and threaten the survival of a business or health care delivery system in a highly competitive environment.
B)Business continuity planning is done after the implementation process.
C)Business continuity planning is associated with the cost incurred by vendors.
D)Located data after a disaster is generally corrupted.
A)Lost or corrupted data are costly to re-create and threaten the survival of a business or health care delivery system in a highly competitive environment.
B)Business continuity planning is done after the implementation process.
C)Business continuity planning is associated with the cost incurred by vendors.
D)Located data after a disaster is generally corrupted.
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
25
Post-disaster recovery expenses usually exceed anticipated costs, leading to changes in recovery strategies that can be used for future disasters. What can planners do to minimize the budget variations?
A)Hold mock disasters.
B)Increase the budget line in anticipation of a disaster.
C)Set aside funds to supplement the budget.
D)Complete the grant writing process to supplement the existing budget.
A)Hold mock disasters.
B)Increase the budget line in anticipation of a disaster.
C)Set aside funds to supplement the budget.
D)Complete the grant writing process to supplement the existing budget.
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
26
Which of the following are stages of the continuity life cycle?
A)Organizational structure and objectives
B)Analysis
C)Implementation
D)Solution design
E)Testing and acceptance
A)Organizational structure and objectives
B)Analysis
C)Implementation
D)Solution design
E)Testing and acceptance
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
27
Which of the following is not a benefit of an effective disaster plan?
A)Limits the loss of data
B)Increase in the budget line to prepare for future disasters
C)Limits loss of equipment
D)Offers a logical system to employ during an unforeseen disaster
A)Limits the loss of data
B)Increase in the budget line to prepare for future disasters
C)Limits loss of equipment
D)Offers a logical system to employ during an unforeseen disaster
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
28
The HIPAA security rule requires continuity planning and disaster recovery processes. In response, all health care organizations must have which of the following?
A)A data backup and a recovery plan
B)A data backup plan, a recovery plan, an emergency mode of operation plan, and testing and evaluation procedures
C)An emergency mode of operation plan and testing and evaluation procedures
D)A data backup plan
A)A data backup and a recovery plan
B)A data backup plan, a recovery plan, an emergency mode of operation plan, and testing and evaluation procedures
C)An emergency mode of operation plan and testing and evaluation procedures
D)A data backup plan
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck
29
____________________________ is broadly defined as the process that seeks to ensure organizations are capable of withstanding any disruption to normal functioning
Unlock Deck
Unlock for access to all 29 flashcards in this deck.
Unlock Deck
k this deck