HIPAA Privacy and Security Flashcards
6 cards from real AHIMA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 HIPAA Privacy and Security flashcards as text
What is HIPAA?
Answer: The Health Insurance Portability and Accountability Act — federal law protecting patient health information privacy
HIPAA establishes national standards for protecting sensitive patient health information from being disclosed without consent.
What is Protected Health Information (PHI)?
Answer: Any individually identifiable health information including demographics, diagnoses, and treatment records
PHI includes any information that can identify an individual and relates to their health condition, care, or payment, in any form (paper, electronic, oral).
What is the minimum necessary standard?
Answer: Access to PHI should be limited to the minimum amount needed to accomplish the intended purpose
The minimum necessary principle requires that access to and disclosure of PHI be limited to what is reasonably necessary for the specific purpose.
What are the penalties for HIPAA violations?
Answer: Civil fines from $100 to $50,000 per violation, criminal penalties up to $250,000 and imprisonment
HIPAA penalties range from civil monetary penalties to criminal prosecution with imprisonment, depending on the nature and severity of the violation.
What is a Business Associate Agreement (BAA)?
Answer: A contract between a covered entity and a vendor that ensures PHI protection when shared
BAAs legally require business associates (vendors handling PHI) to implement appropriate safeguards and comply with HIPAA regulations.
What is a HIPAA breach notification?
Answer: Required notification to affected individuals and HHS when unsecured PHI is improperly accessed or disclosed
Breach notification rules require covered entities to notify affected individuals, HHS, and sometimes media when a breach of unsecured PHI occurs.