โ† All CHAA Flashcard Decks

CHAA HIPAA Privacy and Security Flashcards

6 cards from real CHAA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CHAA HIPAA Privacy and Security flashcards as text
  1. What special protections exist for substance abuse treatment records?

    Answer: 42 CFR Part 2 provides additional protections beyond HIPAA for substance use disorder treatment records, requiring patient consent for most disclosures

    Substance use disorder treatment records maintained by federally assisted programs are protected by 42 CFR Part 2, which provides stricter protections than HIPAA. Part 2 generally requires specific written patient consent for any disclosure, with limited exceptions. Recent amendments have moved toward aligning Part 2 more closely with HIPAA, but additional protections remain. Patient access staff must understand these stricter requirements.

  2. What is 'automatic logoff' and why is it required?

    Answer: A technical safeguard that automatically locks or logs off a workstation after a period of inactivity to prevent unauthorized access to ePHI

    Automatic logoff is a technical safeguard under the HIPAA Security Rule that requires electronic systems to lock or terminate a session after a predetermined period of inactivity. This prevents unauthorized individuals from accessing ePHI on an unattended workstation. Patient access staff workstations should have automatic logoff configured, and staff should also manually lock workstations when stepping away.

  3. How does HIPAA protect psychotherapy notes?

    Answer: Psychotherapy notes receive extra protection and generally require specific patient authorization for use or disclosure, even for treatment, payment, or operations

    HIPAA provides additional protections for psychotherapy notes, which are a therapist's personal notes about counseling sessions kept separate from the medical record. Unlike general PHI, psychotherapy notes generally require specific patient authorization for any use or disclosure, including for treatment, payment, or healthcare operations (with limited exceptions such as the originator's own use). These heightened protections reflect the sensitive nature of therapy documentation.

  4. What is a 'HIPAA sanction policy'?

    Answer: An organization's policy that defines disciplinary actions for workforce members who violate HIPAA policies, ranging from additional training to termination

    A HIPAA sanction policy is a required administrative safeguard that defines the disciplinary measures applied to workforce members who violate HIPAA policies and procedures. Sanctions may range from additional training and verbal warnings to suspension or termination, depending on the severity and nature of the violation. Having and applying a sanction policy demonstrates the organization's commitment to HIPAA compliance.

  5. What is the 'wall of shame' in HIPAA enforcement?

    Answer: The OCR's public online portal listing all reported breaches of unsecured PHI affecting 500 or more individuals

    The 'wall of shame' is the informal name for the OCR's online Breach Portal, which lists all reported breaches of unsecured PHI affecting 500 or more individuals. The portal includes the entity name, type of breach, number of individuals affected, and submission date. This public reporting provides transparency and serves as a deterrent for non-compliance.

  6. How should patient access staff handle a situation where a patient asks them not to file a claim with their insurance?

    Answer: Inform the patient of their right to restrict disclosure to their health plan if they pay the full cost out of pocket, and document the request per organizational policy

    Under HIPAA, patients have the right to request that the provider not disclose PHI to their health plan for services they pay for entirely out of pocket. The provider must agree to this request. Patient access staff should explain the implications (full out-of-pocket payment), document the request, collect payment, and ensure the claim is not submitted to the insurance company. This right was strengthened by the HITECH Act.