Privacy and Security Flashcards
7 cards from real AHIC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Privacy and Security flashcards as text
Which HIPAA rule specifically requires covered entities to implement administrative, physical, and technical safeguards for ePHI?
Answer: HIPAA Security Rule
The HIPAA Security Rule mandates safeguards specifically for electronically protected health information (ePHI).
In a health information exchange (HIE), the 'opt-in' consent model means:
Answer: Patients must affirmatively agree before their data is shared through the HIE
An opt-in model requires explicit patient consent before their health information is shared, giving patients more control over their data.
A nurse accesses the medical records of a celebrity patient out of curiosity, with no clinical justification. This is an example of:
Answer: Insider threat and privacy violation
Accessing PHI without a legitimate need constitutes an insider threat and a HIPAA privacy violation, regardless of the employee's good intentions.
Which encryption standard is commonly recommended for protecting ePHI in transit in U.S. healthcare?
Answer: TLS (Transport Layer Security)
TLS is the standard protocol for encrypting data in transit, protecting ePHI from interception during transmission.
A patient requests an amendment to their medical record because they believe it contains an error. Under HIPAA, the covered entity may deny the request if:
Answer: The information was not created by the covered entity
A covered entity may deny an amendment request if the information was not created by that entity, as it may lack the context to assess accuracy.
What is the primary purpose of a HIPAA Security Risk Assessment?
Answer: To identify and evaluate potential vulnerabilities to ePHI confidentiality, integrity, and availability
A security risk assessment systematically identifies threats and vulnerabilities to ePHI to guide the implementation of appropriate safeguards.
Under the HIPAA Privacy Rule, which of the following does NOT require patient authorization for disclosure?
Answer: Disclosure for payment of healthcare services
HIPAA permits covered entities to use and disclose PHI for treatment, payment, and healthcare operations without patient authorization.