← All CHAA Flashcard Decks

HIPAA Privacy and Security 9 Flashcards

6 cards from real CHAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 HIPAA Privacy and Security 9 flashcards as text
  1. Under HIPAA's 'minimum necessary' standard, a healthcare access associate should:

    Answer: Access or disclose only the amount of PHI needed to accomplish the intended purpose

    The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to what is needed for the specific purpose — not more.

  2. A HIPAA Notice of Privacy Practices (NPP) must be provided to patients:

    Answer: At the first point of service delivery

    Covered entities are required to provide the NPP no later than the date of first service delivery, giving patients upfront notice of how their PHI may be used and disclosed.

  3. Under HIPAA's Breach Notification Rule, covered entities must notify affected individuals of an unsecured PHI breach within:

    Answer: 60 days of discovery

    HIPAA requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days following discovery of a breach of unsecured PHI.

  4. Which of the following entities would be considered a HIPAA Business Associate?

    Answer: A third-party medical billing company that processes claims on behalf of a hospital

    A Business Associate is an outside person or organization that performs functions or services involving PHI on behalf of a covered entity, such as a third-party billing company.

  5. The HIPAA Security Rule requires covered entities to implement safeguards in which three categories?

    Answer: Administrative, physical, and technical

    The Security Rule mandates administrative safeguards (policies and training), physical safeguards (facility and device controls), and technical safeguards (system access controls and encryption) to protect electronic PHI.

  6. Under HIPAA, a patient has the right to request an amendment to their medical record when:

    Answer: They believe the information is inaccurate or incomplete

    HIPAA gives patients the right to request amendments to their PHI if they believe it is inaccurate or incomplete; the covered entity may accept or deny the request with written justification.