โ† All AHIMA Flashcard Decks

HIPAA Privacy and Security Flashcards

7 cards from real AHIMA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 HIPAA Privacy and Security flashcards as text
  1. Under HIPAA, which of the following is the minimum necessary standard designed to protect?

    Answer: PHI disclosed to only the minimum amount needed to accomplish the purpose

    The minimum necessary standard requires covered entities to limit PHI disclosures to only what is reasonably necessary to accomplish the intended purpose.

  2. A Business Associate Agreement (BAA) is required when a vendor:

    Answer: Creates, receives, maintains, or transmits PHI on behalf of a covered entity

    A BAA is legally required whenever a vendor performs functions or activities on behalf of a covered entity that involve PHI.

  3. Which HIPAA rule specifically governs the administrative, physical, and technical safeguards for ePHI?

    Answer: Security Rule

    The HIPAA Security Rule establishes national standards for protecting electronic protected health information through administrative, physical, and technical safeguards.

  4. Which of the following represents a permissible disclosure of PHI without patient authorization under HIPAA?

    Answer: Reporting communicable disease information to a public health authority

    HIPAA permits disclosure of PHI to public health authorities for disease surveillance and reporting without patient authorization.

  5. When a patient requests an amendment to their health record and the covered entity denies it, the entity must:

    Answer: Allow the patient to submit a statement of disagreement

    If a covered entity denies an amendment request, the patient has the right to submit a statement of disagreement that must be appended to their record.

  6. Which of the following is NOT considered Protected Health Information (PHI) under HIPAA?

    Answer: De-identified statistical health data

    De-identified health information that has had all 18 identifying elements removed does not meet the definition of PHI and is not protected under HIPAA.

  7. Under the HIPAA Privacy Rule, a covered entity's Notice of Privacy Practices (NPP) must be provided to patients:

    Answer: At first service delivery and upon request thereafter

    Covered entities must provide the NPP to patients at the first point of service delivery and make it available upon request at any time.