HIPAA Privacy & Security Rules Flashcards
7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 HIPAA Privacy & Security Rules flashcards as text
Under HIPAA, which of the following is a permitted disclosure of PHI WITHOUT patient authorization?
Answer: Reporting a gunshot wound to law enforcement as required by state law
HIPAA permits disclosures required by law, including mandatory reporting of certain injuries like gunshot wounds to law enforcement authorities.
What is the civil monetary penalty range for a HIPAA violation resulting from willful neglect that is not corrected?
Answer: $50,000 per violation up to $1.9 million per year
Willful neglect not corrected carries a minimum penalty of $50,000 per violation and an annual cap of $1.9 million for identical violations.
Which HIPAA standard governs the contingency plan for responding to emergencies that damage systems containing ePHI?
Answer: Contingency Plan standard under Administrative Safeguards
The Contingency Plan standard (Administrative Safeguard) requires covered entities to establish policies for responding to emergencies that damage systems containing ePHI.
A covered entity may share PHI with a Business Associate only if a:
Answer: Business Associate Agreement (BAA) is in place
The Privacy Rule requires covered entities to obtain satisfactory assurances in the form of a Business Associate Agreement before sharing PHI with a business associate.
Under the Privacy Rule, an individual's right to request restrictions on PHI use applies to disclosures to:
Answer: Health plans for payment purposes when the individual pays out-of-pocket in full
Under the HITECH Act, covered entities MUST honor a patient's restriction request when the individual pays out-of-pocket for a service and requests the disclosure to their health plan be restricted.
What is the timeframe within which a covered entity must provide an individual access to their PHI upon request?
Answer: 30 calendar days, with one possible 30-day extension
The Privacy Rule requires covered entities to act on an access request within 30 calendar days, with one 30-day extension permitted if the entity notifies the individual in writing.
Which of the following is TRUE about the HIPAA Security Rule's applicability?
Answer: It applies only to ePHI created or maintained by covered entities and their business associates
The Security Rule applies exclusively to electronic protected health information (ePHI) and covers both covered entities and, since 2013, their business associates.