← All CHAA Flashcard Decks

HIPAA Privacy and Security 4 Flashcards

6 cards from real CHAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 HIPAA Privacy and Security 4 flashcards as text
  1. Under HIPAA's 'minimum necessary' standard, when a healthcare access associate requests patient information, they should:

    Answer: Access only the information needed to accomplish the intended purpose

    The minimum necessary standard requires that covered entities limit PHI access and disclosure to the least amount needed to accomplish the intended purpose, reducing unnecessary exposure of patient information.

  2. A patient requests a copy of their medical records. Under the HIPAA Privacy Rule, a covered entity must provide access within:

    Answer: 30 days, with one possible 30-day extension

    HIPAA requires covered entities to provide patients access to their PHI within 30 days of the request, with a single 30-day extension allowed if the entity notifies the patient in writing of the delay and reason.

  3. Which of the following is an example of a Business Associate under HIPAA?

    Answer: A billing company that processes claims containing PHI on behalf of a covered entity

    A Business Associate is a person or entity that performs functions or services for a covered entity involving the use or disclosure of PHI. A billing company handling claims data on the covered entity's behalf meets this definition and must sign a Business Associate Agreement (BAA).

  4. Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals of a breach of unsecured PHI within:

    Answer: 60 calendar days of discovery

    The Breach Notification Rule requires covered entities to notify affected individuals within 60 calendar days of discovering a breach of unsecured PHI. For breaches affecting 500 or more individuals, prominent media notification and HHS notification are also required within the same timeframe.

  5. Which of the following safeguard categories is required under the HIPAA Security Rule to protect electronic PHI (ePHI)?

    Answer: Administrative, Physical, and Technical safeguards

    The HIPAA Security Rule organizes its protections into three categories: Administrative safeguards (policies and procedures), Physical safeguards (facility and device controls), and Technical safeguards (technology controls like encryption and access controls) — all three are required.

  6. A healthcare access associate may disclose a patient's PHI without obtaining prior authorization for which of the following purposes?

    Answer: Treatment, payment, and healthcare operations (TPO)

    HIPAA permits covered entities to use and disclose PHI without patient authorization for treatment, payment, and healthcare operations (TPO). These are considered essential functions of healthcare delivery and do not require prior written consent, though the patient must be informed via the Notice of Privacy Practices.