โ† All CHP Flashcard Decks

HIPAA Privacy & Security Rules Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 HIPAA Privacy & Security Rules flashcards as text
  1. Under the HIPAA Security Rule, which of the following is classified as a Physical Safeguard?

    Answer: Workstation use policy

    Workstation use is a physical safeguard standard that governs the proper functions performed at workstations and the physical environment of those workstations.

  2. The Minimum Necessary Standard under HIPAA requires covered entities to:

    Answer: Share only the minimum amount of PHI needed to accomplish the intended purpose

    The Minimum Necessary Standard requires covered entities to make reasonable efforts to limit PHI access and disclosures to the minimum needed to accomplish the intended purpose.

  3. Which entity enforces the HIPAA Privacy and Security Rules against covered entities?

    Answer: The Office for Civil Rights (OCR) within HHS

    The HHS Office for Civil Rights (OCR) is the primary enforcer of the HIPAA Privacy and Security Rules and investigates complaints and conducts audits.

  4. A covered entity's Notice of Privacy Practices (NPP) must be provided to patients:

    Answer: At the time of first service delivery

    Covered entities must provide the NPP no later than the date of first service delivery and make a good-faith effort to obtain written acknowledgment of receipt.

  5. Under the HITECH Act, business associates became directly liable for HIPAA compliance in which year?

    Answer: 2013

    The HIPAA Omnibus Rule (2013) implemented HITECH Act provisions making business associates directly liable for compliance with applicable HIPAA Privacy and Security Rule requirements.

  6. Which of the following is an example of PHI under the HIPAA Privacy Rule?

    Answer: A patient's name combined with their diagnosis

    PHI is individually identifiable health information, and combining a patient's name (an identifier) with their diagnosis (health information) creates PHI.

  7. A Security Risk Analysis under the HIPAA Security Rule must assess:

    Answer: Potential threats and vulnerabilities to all ePHI the entity creates, receives, maintains, or transmits

    The Security Rule requires a thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI in the entity's environment.