← All CHAA Flashcard Decks

HIPAA Privacy and Security 5 Flashcards

6 cards from real CHAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 HIPAA Privacy and Security 5 flashcards as text
  1. Which of the following is NOT considered a covered entity under HIPAA?

    Answer: Medical equipment manufacturers with no patient data access

    Medical equipment manufacturers that do not access, transmit, or maintain PHI are not covered entities under HIPAA. Covered entities are limited to health plans, healthcare clearinghouses, and healthcare providers who conduct covered electronic transactions.

  2. Under HIPAA, a patient's right to access their own medical records must generally be fulfilled within how many days?

    Answer: 30 days

    HIPAA requires covered entities to provide patients access to their PHI within 30 days of the request. A one-time 30-day extension is allowed if the entity notifies the patient of the delay and the reason.

  3. What is a Business Associate Agreement (BAA) under HIPAA?

    Answer: A written contract requiring vendors who handle PHI to protect it according to HIPAA standards

    A BAA is a legally required written contract between a covered entity and a business associate (a vendor or third party that handles PHI on its behalf). It outlines the permitted uses of PHI and the business associate's obligation to safeguard it.

  4. Which of the following best describes the 'minimum necessary' standard under the HIPAA Privacy Rule?

    Answer: Only the minimum amount of PHI needed to accomplish the intended purpose should be used or disclosed

    The minimum necessary standard requires that covered entities make reasonable efforts to limit the use, disclosure, and requests for PHI to only what is needed to accomplish the specific purpose, reducing unnecessary exposure of patient information.

  5. Under the HIPAA Breach Notification Rule, if a breach affects 500 or more individuals in a state, the covered entity must notify which of the following within 60 days of discovery?

    Answer: HHS and prominent media outlets in the affected area, in addition to affected individuals

    For breaches affecting 500 or more individuals in a state or jurisdiction, covered entities must notify: the affected individuals, the Secretary of HHS (immediately), and prominent media outlets serving that state — all within 60 days of discovering the breach.

  6. Which HIPAA safeguard category requires covered entities to implement policies such as workstation use policies, device disposal procedures, and media re-use controls?

    Answer: Physical safeguards

    Physical safeguards under the HIPAA Security Rule govern the physical access to and protection of electronic PHI and the equipment that stores it. This includes workstation use policies, device and media controls, and facility access controls.