HITECH Act & Electronic Health Records Compliance Flashcards
7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 HITECH Act & Electronic Health Records Compliance flashcards as text
What are the four tiers of civil monetary penalties established by HITECH, listed from least to most severe?
Answer: Did not know, reasonable cause, willful neglect corrected, willful neglect not corrected
HITECH established four penalty tiers based on culpability: (1) did not know, (2) reasonable cause, (3) willful neglect corrected within 30 days, and (4) willful neglect not corrected.
Under HITECH's breach notification rule, what is the maximum timeframe for notifying affected individuals after discovery of a breach?
Answer: 60 days
Covered entities must notify affected individuals without unreasonable delay and no later than 60 days following the discovery of a breach of unsecured PHI.
Under HITECH, when must breaches affecting fewer than 500 individuals be reported to the Secretary of HHS?
Answer: Annually, within 60 days after the end of each calendar year
Small breaches affecting fewer than 500 individuals must be logged and reported to HHS annually, submitting the log within 60 days after the close of each calendar year.
Which HITECH provision requires a covered entity to honor a patient's request to restrict disclosure of PHI to a health plan?
Answer: The right to restrict disclosures when a patient pays out of pocket in full
HITECH requires covered entities to honor a patient's request to restrict disclosure to a health plan if the patient pays out of pocket in full for the item or service.
What is the purpose of Health Information Exchanges (HIEs) as promoted under the HITECH Act?
Answer: To enable secure electronic sharing of patient health information across organizations to improve care coordination
HIEs facilitate the secure electronic movement of health information among organizations, improving care coordination, reducing duplicate testing, and enhancing patient safety.
Which of the following workforce actions would most likely result in criminal penalties under HIPAA as strengthened by HITECH?
Answer: Intentionally accessing and selling patient records for personal financial gain
Knowingly and intentionally obtaining or disclosing PHI for personal gain, commercial advantage, or malicious harm can result in criminal penalties including fines and imprisonment.
Under HITECH, which element is NOT required to be included in a breach notification letter sent to affected individuals?
Answer: The name and title of the specific employee responsible for the breach
Breach notifications must include a description of the breach, the types of PHI involved, protective steps, and contact information, but do not require identifying the responsible employee.