HIPAA Privacy and Security 8 Flashcards
6 cards from real CHAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 HIPAA Privacy and Security 8 flashcards as text
Which of the following is NOT one of the three safeguard categories required by the HIPAA Security Rule?
Answer: Financial safeguards
The HIPAA Security Rule requires covered entities to implement three categories of safeguards: administrative, physical, and technical. Financial safeguards are not a recognized category under the Security Rule.
Under HIPAA, a 'covered entity' includes which of the following?
Answer: A health plan that pays for medical services
Covered entities under HIPAA include health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically. Employers, law firms without health data, and unrelated service vendors are generally not covered entities.
What is the maximum period a patient generally has to request their own medical records from a covered entity under the HIPAA Privacy Rule?
Answer: 60 days
The HIPAA Privacy Rule requires covered entities to provide access to a patient's records within 30 days, with a possible 30-day extension if needed, making the outer limit 60 days. Patients do not have to wait 90 days.
Which HIPAA concept allows a covered entity to share PHI for treatment, payment, and healthcare operations WITHOUT obtaining the patient's written authorization?
Answer: Permitted disclosure
HIPAA allows 'permitted disclosures' — sharing PHI for treatment, payment, and healthcare operations (TPO) without written patient authorization. This is distinct from voluntary disclosures that do require authorization.
A hospital employee accesses the medical record of a celebrity patient out of curiosity, even though they are not involved in that patient's care. This is a violation of which HIPAA principle?
Answer: The minimum necessary standard
The minimum necessary standard requires employees to access only the PHI needed to perform their job duties. Accessing records out of curiosity — with no treatment, payment, or operations purpose — violates this core HIPAA principle.
Under the HIPAA Breach Notification Rule, how soon must a covered entity notify affected individuals after discovering a breach of unsecured PHI?
Answer: Within 60 days
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach of unsecured PHI.