โ† All CHP Flashcard Decks

HITECH Act & Electronic Health Records Compliance Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 HITECH Act & Electronic Health Records Compliance flashcards as text
  1. What does the 'minimum necessary' standard require under HIPAA and HITECH?

    Answer: Only the minimum amount of PHI needed to accomplish the intended purpose should be used, disclosed, or requested

    The minimum necessary standard requires that covered entities make reasonable efforts to limit PHI use, disclosure, and requests to the minimum needed to accomplish the intended purpose.

  2. Under HITECH, what expanded accounting of disclosures right applies specifically to electronic health records?

    Answer: Patients may request a list of all individuals who accessed their EHR for treatment, payment, and operations purposes

    HITECH expanded the accounting of disclosures requirement to include disclosures made through an EHR for treatment, payment, and healthcare operations, allowing patients to see who accessed their records.

  3. The Medicare and Medicaid EHR Incentive Programs created under HITECH are now referred to by which name?

    Answer: Promoting Interoperability Programs

    The Medicare and Medicaid EHR Incentive Programs were rebranded as the Promoting Interoperability Programs to better reflect the current focus on health information exchange and interoperability.

  4. Under HITECH, what is the role of the Office for Civil Rights (OCR) in relation to HIPAA enforcement?

    Answer: Investigating HIPAA complaints, conducting audits, and imposing civil monetary penalties

    OCR within HHS is the primary enforcement authority for HIPAA Privacy and Security Rules, responsible for investigating complaints, conducting compliance reviews, and imposing civil monetary penalties.

  5. A covered entity discovers a breach on March 5th. What is the latest date by which affected individuals must be notified?

    Answer: May 4th (60 days later)

    Under HITECH, affected individuals must be notified without unreasonable delay and no later than 60 calendar days after the breach is discovered, making May 4th the deadline.

  6. Which HITECH provision most directly addressed the gap that previously exempted business associates from direct HIPAA liability?

    Answer: The direct applicability of Security Rule requirements to business associates

    HITECH directly applied HIPAA Security Rule requirements and certain Privacy Rule provisions to business associates, making them independently liable rather than relying solely on contractual obligations.

  7. Under the HITECH Act, what constitutes 'unsecured PHI' for purposes of the breach notification rule?

    Answer: PHI that has not been rendered unusable, unreadable, or indecipherable through encryption or destruction per HHS guidance

    Unsecured PHI is PHI that has not been rendered unusable, unreadable, or indecipherable through the use of encryption or destruction methods specified in HHS guidance, triggering breach notification obligations.