HIPAA Privacy and Security Flashcards
7 cards from real AHIMA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 HIPAA Privacy and Security flashcards as text
Which of the following scenarios qualifies as a 'use' of PHI under HIPAA (rather than a 'disclosure')?
Answer: A nurse reviewing a patient's chart within the same covered entity
A 'use' occurs when PHI is shared, employed, or applied within the same covered entity; a 'disclosure' involves sharing outside the entity.
Which of the following is an example of a physical safeguard required by the HIPAA Security Rule?
Answer: Facility access controls such as badge readers
Physical safeguards are the physical measures, policies, and procedures used to protect electronic information systems and related buildings from unauthorized intrusion.
Under HIPAA, a patient's authorization for use or disclosure of PHI must include which of the following elements?
Answer: An expiration date or event
A valid HIPAA authorization must include an expiration date or expiration event after which the authorization is no longer valid.
What is the 'Safe Harbor' method of de-identification under HIPAA?
Answer: Removing all 18 specific identifiers and having no actual knowledge that the remaining information could identify an individual
The Safe Harbor method requires removal of all 18 types of identifiers listed in the HIPAA Privacy Rule and no actual knowledge that the residual data could re-identify individuals.
HIPAA's 'Minimum Necessary' standard does NOT apply to disclosures made:
Answer: To the individual who is the subject of the PHI
The minimum necessary standard does not apply when disclosures are made to the individual who is the subject of the PHI, for treatment purposes, or pursuant to an authorization.
Which of the following is an addressable implementation specification under the HIPAA Security Rule?
Answer: Encryption and decryption of ePHI at rest
Encryption of ePHI at rest is an addressable specification, meaning covered entities must implement it or document why an equivalent alternative measure is sufficient.
A covered entity discovers a laptop containing unencrypted ePHI was stolen. Under the Breach Notification Rule, this event is:
Answer: Presumed to be a breach unless the covered entity demonstrates a low probability of compromise
Under the 2013 Omnibus Rule, an impermissible use or disclosure is presumed to be a breach unless a four-factor risk assessment demonstrates a low probability that PHI was compromised.