← All CHAA Flashcard Decks

CHAA HIPAA Privacy and Security Flashcards

6 cards from real CHAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 CHAA HIPAA Privacy and Security flashcards as text
  1. What does HIPAA stand for?

    Answer: Health Insurance Portability and Accountability Act

    HIPAA stands for the Health Insurance Portability and Accountability Act, enacted in 1996. It established national standards for the protection of health information, ensuring privacy and security of patient data. HIPAA is the foundational law governing how healthcare organizations handle protected health information.

  2. What is Protected Health Information (PHI)?

    Answer: Any individually identifiable health information that relates to a patient's health condition, treatment, or payment for healthcare

    PHI includes any individually identifiable health information that relates to an individual's past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare services. PHI can be in any form — written, oral, or electronic. There are 18 specific identifiers that can make health information identifiable, including name, date of birth, and Social Security number.

  3. What is the HIPAA Privacy Rule?

    Answer: A federal regulation that sets standards for the use and disclosure of PHI by covered entities and business associates

    The HIPAA Privacy Rule establishes national standards for the protection of individuals' medical records and other personal health information. It sets limits on who can access and receive PHI, gives patients rights over their health information, and requires appropriate safeguards. It applies to covered entities (health plans, healthcare clearinghouses, and healthcare providers) and their business associates.

  4. What is the HIPAA Security Rule?

    Answer: A regulation that specifically addresses the protection of electronic PHI through administrative, physical, and technical safeguards

    The HIPAA Security Rule specifically addresses the protection of electronic Protected Health Information (ePHI). It requires covered entities to implement administrative safeguards (policies and procedures), physical safeguards (facility access controls), and technical safeguards (access controls, audit controls, encryption) to ensure the confidentiality, integrity, and availability of ePHI.

  5. What is the 'minimum necessary' standard under HIPAA?

    Answer: The principle that covered entities should limit PHI use, disclosure, and requests to the minimum amount needed to accomplish the intended purpose

    The minimum necessary standard requires that covered entities make reasonable efforts to limit the use, disclosure, and requests of PHI to the minimum amount necessary to accomplish the intended purpose. For example, a billing department only needs billing-related information, not the patient's full clinical record. This principle does not apply to treatment disclosures between providers.

  6. Who is a 'covered entity' under HIPAA?

    Answer: Health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically

    HIPAA covered entities include three categories: health plans (insurance companies, HMOs, Medicare, Medicaid), healthcare clearinghouses (entities that process health information), and healthcare providers who conduct certain electronic transactions (physicians, hospitals, clinics). All covered entities must comply with HIPAA Privacy, Security, and Breach Notification Rules.