← All CHAA Flashcard Decks

HIPAA Privacy and Security 3 Flashcards

6 cards from real CHAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 HIPAA Privacy and Security 3 flashcards as text
  1. Under HIPAA's 'minimum necessary' standard, what must a healthcare access associate consider when requesting or using patient information?

    Answer: Use only the minimum amount of PHI reasonably needed to accomplish the intended purpose

    The minimum necessary standard requires that covered entities limit access and disclosure of PHI to only what is needed for the specific task at hand. Staff should not routinely access or share more patient information than necessary for their role.

  2. What is the primary purpose of a Business Associate Agreement (BAA) under HIPAA?

    Answer: To legally obligate a third-party vendor handling PHI to protect it according to HIPAA standards

    A BAA is a required contract between a covered entity and a business associate (any vendor or third party that handles PHI on behalf of the covered entity). It ensures the business associate will appropriately safeguard the PHI they access or process.

  3. Under the HIPAA Breach Notification Rule, within how many days must a covered entity notify affected individuals following discovery of a breach of unsecured PHI?

    Answer: 60 days

    The HIPAA Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI. If the breach affects more than 500 residents of a state, prominent media outlets must also be notified.

  4. Which of the following is NOT one of the 18 identifiers that make health information 'individually identifiable' under HIPAA?

    Answer: Blood type

    Blood type is not among the 18 HIPAA identifiers. The 18 identifiers include names, geographic data, specific dates, SSNs, phone/fax numbers, email addresses, medical record numbers, biometric identifiers, and others — but not clinical values like blood type or diagnosis codes on their own.

  5. A patient's right to an 'accounting of disclosures' under the HIPAA Privacy Rule entitles them to:

    Answer: A log of disclosures of their PHI made without their authorization over the past six years

    The right to an accounting of disclosures allows patients to request a record of when and to whom their PHI was disclosed without their authorization (e.g., for public health reporting or law enforcement). It does not cover disclosures made for treatment, payment, or healthcare operations.

  6. Which category of safeguards under the HIPAA Security Rule covers physical measures such as facility access controls, workstation security policies, and device and media controls?

    Answer: Physical safeguards

    Physical safeguards address the tangible, real-world protections for systems containing electronic PHI — things like locked server rooms, badge access to workstations, and policies for disposing of hardware. Technical safeguards cover software/encryption controls, while administrative safeguards cover policies and workforce training.