โ† All AHIMA Flashcard Decks

HIPAA Privacy and Security Flashcards

7 cards from real AHIMA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 HIPAA Privacy and Security flashcards as text
  1. Under the HIPAA Breach Notification Rule, a covered entity must notify affected individuals of a breach within:

    Answer: 60 days of discovery

    Covered entities must provide breach notifications to affected individuals without unreasonable delay and no later than 60 days following discovery of the breach.

  2. A 'small breach' affecting fewer than 500 individuals in a state must be reported to HHS:

    Answer: Annually, no later than 60 days after the end of the calendar year

    Breaches affecting fewer than 500 individuals must be logged and reported to HHS annually, within 60 days of the end of the calendar year.

  3. Which of the following is a required implementation specification under the HIPAA Security Rule's Administrative Safeguards?

    Answer: Security management process

    The security management process is a required administrative safeguard that includes risk analysis, risk management, sanction policy, and information system activity review.

  4. Which of the following best describes 'workforce' under HIPAA?

    Answer: Employees, volunteers, trainees, and others under the direct control of the covered entity

    HIPAA defines workforce broadly to include all persons whose conduct is under the direct control of the covered entity, whether or not they are paid.

  5. Which right does HIPAA give patients regarding their health records?

    Answer: The right to access and obtain a copy of their PHI

    HIPAA's Privacy Rule grants individuals the right to access, inspect, and receive copies of their PHI held by a covered entity.

  6. What is the purpose of a HIPAA Risk Analysis?

    Answer: To assess potential threats and vulnerabilities to the confidentiality, integrity, and availability of ePHI

    A risk analysis identifies and evaluates potential threats and vulnerabilities to ePHI to determine the likelihood and impact of potential risks.

  7. Under HIPAA, which entity is primarily responsible for enforcement and imposing civil money penalties?

    Answer: Office for Civil Rights (OCR) within HHS

    The HHS Office for Civil Rights (OCR) is the primary federal agency responsible for enforcing HIPAA's Privacy, Security, and Breach Notification Rules.