← All CHAA Flashcard Decks

HIPAA Privacy and Security 6 Flashcards

6 cards from real CHAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 HIPAA Privacy and Security 6 flashcards as text
  1. Under HIPAA's Minimum Necessary Standard, what principle must covered entities follow when using or disclosing PHI?

    Answer: Disclose only the amount of PHI reasonably needed to accomplish the intended purpose

    The Minimum Necessary Standard requires covered entities to make reasonable efforts to limit PHI use and disclosure to what is needed for the specific purpose, reducing unnecessary exposure of patient information.

  2. Which of the following is NOT one of the 18 identifiers that make health information considered Protected Health Information (PHI)?

    Answer: Patient's blood type alone

    Blood type by itself is a clinical value not on HIPAA's list of 18 identifiers. Dates, phone numbers, and medical record numbers are all listed identifiers that, combined with health data, create PHI.

  3. Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals of a breach within how many days of discovery?

    Answer: 60 days

    HIPAA requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured PHI.

  4. What is a Business Associate Agreement (BAA) under HIPAA?

    Answer: An agreement between a covered entity and a vendor who handles PHI on its behalf

    A BAA is a required written contract between a covered entity and a business associate — any third party that creates, receives, or transmits PHI on behalf of that entity — ensuring the associate safeguards the information.

  5. Under the HIPAA Security Rule, which category of safeguards covers physical measures such as workstation security and facility access controls?

    Answer: Physical safeguards

    Physical safeguards are the tangible, real-world measures required to protect electronic PHI, including controls over facility access, workstation use, and device and media handling.

  6. A patient requests an amendment to their medical record under HIPAA. Which of the following is a valid reason for a covered entity to deny that request?

    Answer: The record was not created by the covered entity receiving the request

    HIPAA permits denial of an amendment request when the covered entity did not create the record in question — the patient should direct the request to the originating provider. Age of the record and provider disagreement are not valid grounds for denial.