HIPAA Privacy and Security Flashcards
7 cards from real CHC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 HIPAA Privacy and Security flashcards as text
A workforce member accesses the records of a celebrity patient out of curiosity without clinical need. This is best described as:
Answer: A HIPAA Privacy Rule violation due to impermissible access
Accessing PHI without a legitimate purpose violates the minimum necessary and permissible use standards of the HIPAA Privacy Rule.
Under HIPAA, when must a covered entity obtain a patient's written authorization before disclosing PHI?
Answer: For most marketing communications using PHI
Most marketing communications that use PHI require the patient's written authorization under the HIPAA Privacy Rule.
Which of the following correctly describes the HIPAA 'Safe Harbor' method of de-identification?
Answer: 18 specific categories of identifiers are removed and the entity has no actual knowledge the data could re-identify the individual
The Safe Harbor method requires removal of 18 specific identifier categories and a statement that the covered entity has no actual knowledge the remaining information could identify the individual.
Under the HITECH Act, which party became directly liable for compliance with certain HIPAA Security Rule provisions?
Answer: Business associates directly, not just through BAAs
HITECH made business associates directly liable for compliance with many HIPAA Security Rule and Privacy Rule provisions, not just contractually liable through BAAs.
A hospital workforce member loses an unencrypted laptop containing PHI for 800 patients. Which statement is correct?
Answer: This is a presumed breach requiring notification unless the four-factor risk assessment shows low probability of compromise
Loss of an unencrypted laptop with PHI is a presumed breach under the Omnibus Rule, requiring notification unless a risk assessment demonstrates low probability that PHI was compromised.
What is the role of the HIPAA Privacy Officer in a covered entity?
Answer: To be responsible for development and implementation of privacy policies and procedures
The HIPAA Privacy Rule requires covered entities to designate a Privacy Officer responsible for developing and implementing privacy policies and procedures.
Which of the following scenarios describes a permissible incidental disclosure under HIPAA?
Answer: A hospital staff member discusses a patient's condition in a hallway while taking reasonable precautions to limit overheard information
Incidental disclosures that occur as a byproduct of otherwise permissible communications are allowed if the covered entity has reasonable safeguards in place and follows minimum necessary standards.