← All CHC Flashcard Decks

HIPAA Privacy and Security Flashcards

7 cards from real CHC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 HIPAA Privacy and Security flashcards as text
  1. Under the HIPAA Privacy Rule, the 'minimum necessary' standard does NOT apply to which type of disclosure?

    Answer: Disclosures for treatment purposes to healthcare providers

    The minimum necessary standard does not apply to disclosures made to or requests by a healthcare provider for treatment purposes.

  2. A covered entity may use or disclose PHI without patient authorization for which of the following purposes?

    Answer: Reporting a gunshot wound to law enforcement as required by state law

    HIPAA permits disclosure to law enforcement when required by law, such as mandatory reporting of gunshot wounds.

  3. What is the maximum civil monetary penalty per violation category for violations where the covered entity did not know and could not have known of the violation?

    Answer: $100 per violation, up to $25,000 per year

    The lowest tier of civil monetary penalties applies to unknowing violations at $100–$50,000 per violation, up to $25,000 per identical violation per year.

  4. Under HIPAA's Security Rule, which implementation specification is 'required' versus 'addressable' for the Workstation Use standard?

    Answer: Workstation Use is required; covered entities must implement it

    The Workstation Use standard under Physical Safeguards is required, meaning covered entities must implement policies governing proper workstation use.

  5. A patient requests an accounting of disclosures. Which type of disclosure must be included in the accounting?

    Answer: Disclosures to public health authorities as required by law

    Disclosures required by law, such as those to public health authorities, must be included in the accounting of disclosures.

  6. Under the HIPAA Privacy Rule, a covered entity's Notice of Privacy Practices must be provided to patients:

    Answer: No later than the date of first service delivery

    Covered entities must provide the Notice of Privacy Practices no later than the date of first service delivery to the individual.

  7. Which of the following entities is DIRECTLY covered under HIPAA as a covered entity?

    Answer: A health insurance company that processes claims electronically

    Health plans that process standard electronic transactions are covered entities directly subject to HIPAA regulations.