HIPAA Privacy and Security 7 Flashcards
6 cards from real CHAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 HIPAA Privacy and Security 7 flashcards as text
Under HIPAA, which of the following entities is considered a 'covered entity' required to comply with the Privacy and Security Rules?
Answer: A hospital that provides treatment and submits claims electronically
Covered entities under HIPAA include health plans, healthcare clearinghouses, and healthcare providers (such as hospitals) that transmit health information electronically. Marketing firms, janitorial companies, and software vendors are not covered entities, though some may be business associates.
What is the 'minimum necessary' standard under HIPAA?
Answer: Covered entities must limit PHI use and disclosure to the least amount needed to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to use, disclose, or request only the amount of PHI needed to accomplish the purpose, reducing unnecessary exposure of patient information.
A patient requests a copy of their own medical records. Under HIPAA, the covered entity must generally provide access within how many days?
Answer: 30 days
HIPAA's Privacy Rule requires covered entities to provide individuals access to their PHI within 30 days of the request, with one possible 30-day extension if the entity notifies the individual in writing.
Which of the following best describes a Business Associate Agreement (BAA) under HIPAA?
Answer: A written contract requiring a vendor who handles PHI on behalf of a covered entity to protect that information
A BAA is a legally required contract between a covered entity and a business associate (such as a billing company or IT vendor) that handles PHI. It specifies how the business associate must safeguard the information.
Under the HIPAA Breach Notification Rule, a covered entity must notify affected individuals of an unsecured PHI breach within how many days of discovery?
Answer: 60 days
The Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovering an unsecured PHI breach. Breaches affecting 500 or more individuals also require media and HHS notification.
Which of the following is an example of a physical safeguard required by the HIPAA Security Rule?
Answer: Installing locked doors and access controls to limit entry to areas where ePHI is stored
Physical safeguards under the HIPAA Security Rule refer to physical measures and policies to protect electronic systems and related buildings and equipment from unauthorized access. Locked doors and access controls are classic examples. Encryption and unique logins are technical safeguards; risk analysis is an administrative safeguard.