← All CHP Flashcard Decks

Mixed Deck — All CHP Topics Flashcards

100 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CHP Topics flashcards as text
  1. Which element is NOT required to be included in a Business Associate Agreement under HIPAA?

    Answer: The specific dollar amount of penalties if the business associate causes a breach

    BAAs must include permitted uses, breach reporting obligations, and PHI return/destruction terms, but they are not required to specify exact penalty dollar amounts.

  2. Which of the following HIPAA audit scenarios would most likely result in the highest civil money penalty tier?

    Answer: Willful neglect of HIPAA requirements that was not corrected within the required timeframe

    The highest penalty tier applies to violations due to willful neglect that are not corrected, with penalties up to $1.9 million per violation category per year.

  3. Who enforces HIPAA compliance audits?

    Answer: OCR

    The Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS) is the primary federal agency responsible for enforcing HIPAA compliance. The OCR investigates complaints, conducts compliance reviews, and performs audits to ensure covered entities and business associates adhere to the Privacy, Security, and Breach Notification Rules. They have the authority to impose civil monetary penalties for violations.

  4. A nurse's personal smartphone is used to photograph wound progress for the patient record. Under HIPAA, this practice requires:

    Answer: A formal BYOD policy that addresses ePHI handling, encryption, and remote wipe capability

    BYOD (Bring Your Own Device) programs must include formal policies covering ePHI safeguards such as encryption, containerization, and remote wipe to comply with the HIPAA Security Rule.

  5. A clinical workstation has not received operating system security patches in 18 months due to compatibility concerns with legacy software. Under HIPAA, this situation requires:

    Answer: A documented risk analysis and compensating controls to mitigate known vulnerabilities

    When patching is not feasible, HIPAA requires a documented risk analysis identifying the risk level and implementation of compensating controls (e.g., network isolation) to reduce risk.

  6. In physiology, 'peristalsis' refers to the wave-like muscle contractions that move substances through which organ system?

    Answer: Digestive system

    Peristalsis is the rhythmic, wave-like muscular contractions that propel food and waste through the digestive tract.

  7. What is the penalty for a HIPAA violation due to willful neglect?

    Answer: Fines ranging from $10,000 to $50,000 per violation

    HIPAA violations are categorized by culpability, with willful neglect being the most severe. Willful neglect means a conscious indifference or reckless disregard of the HIPAA rules. Penalties for such violations are substantial, ranging from $10,000 to $50,000 per violation, and can accumulate to a maximum of $1.5 million per calendar year for identical violations, underscoring the importance of strict compliance.

  8. When a patient's clinical evaluation reveals information about a communicable disease, a covered entity may disclose PHI to public health authorities:

    Answer: Without authorization as a permitted public health activity

    HIPAA permits disclosure to public health authorities to prevent or control disease without patient authorization under the public health activities exception.

  9. Which of the following is an example of a technical safeguard that also supports infection control by reducing the need for physical contact with shared input devices?

    Answer: Implementing voice-activated or hands-free authentication and documentation systems

    Voice-activated or hands-free systems reduce touchpoint contamination risks while also leveraging advanced authentication methods that can satisfy HIPAA technical safeguard requirements.

  10. Which of the following PHI disclosure scenarios qualifies for the 'limited data set' exception and is NOT treated as a breach?

    Answer: Disclosing a limited data set under a data use agreement for research

    Disclosure of a limited data set (with direct identifiers removed) under a proper data use agreement (DUA) is a permitted HIPAA disclosure and does not constitute a breach.

  11. A third-party technician needs to repair a server containing ePHI. What must be in place before granting access?

    Answer: A Business Associate Agreement (BAA) with the vendor

    Any vendor whose work may expose them to ePHI must have a BAA with the covered entity before being granted access, as required by the HIPAA Privacy and Security Rules.

  12. A covered entity that shares PHI with a vendor without executing a required BAA is subject to:

    Answer: HIPAA civil monetary penalties and potential corrective action

    Sharing PHI without a required BAA is itself a HIPAA violation exposing the covered entity to civil monetary penalties and OCR corrective action, regardless of whether a breach occurs.

  13. A physician discovers that a colleague is impaired while on duty. The physician's ethical obligation under most professional codes is to:

    Answer: Report the impairment to appropriate supervisory or licensing authorities

    Professional ethics require reporting an impaired colleague to protect patient safety, which takes precedence over collegial loyalty.

  14. A patient involved in a clinical trial has treatment protocols managed by both the trial sponsor and a covered entity. HIPAA applies to:

    Answer: Only the covered entity's use and disclosure of PHI

    HIPAA obligations apply specifically to covered entities; the trial sponsor is governed by HIPAA only if it independently qualifies as a covered entity or business associate.

  15. Which HIPAA Security Rule standard governs procedures for creating and restoring ePHI backup copies from medical equipment?

    Answer: Contingency Plan — Data Backup Plan (§164.308(a)(7)(ii)(A))

    The Contingency Plan's Data Backup Plan implementation specification requires establishing and implementing procedures to create and maintain exact retrievable copies of ePHI.

  16. What is the primary purpose of conducting a comprehensive patient assessment in Certified Hijama Practitioner practice?

    Answer: To establish baseline measurements and identify treatment needs

    Comprehensive patient assessment establishes baseline measurements and identifies specific treatment needs, forming the foundation for effective care planning.

  17. A research hospital wants to use patient data for a new study. To maintain ethical standards, participants must provide:

    Answer: Written informed consent that is voluntary and comprehension-based

    Research ethics require prospective, voluntary, written informed consent that ensures participants understand risks and benefits.

  18. Which of the following is NOT a required element of a HIPAA Business Associate Agreement?

    Answer: The business associate's annual revenue and profit margins

    Financial figures such as annual revenue are not required elements of a HIPAA Business Associate Agreement.

  19. During a public health emergency involving an infectious disease outbreak, a covered entity wants to share patient PHI with public health authorities without patient authorization. Which HIPAA provision permits this?

    Answer: The Public Health Activities exception allows disclosure to public health authorities authorized by law to collect data

    HIPAA's Public Health Activities exception (45 CFR § 164.512(b)) permits covered entities to disclose PHI to authorized public health authorities for activities such as disease surveillance and outbreak response.

  20. A healthcare organization's contingency plan must address maintaining access to ePHI during facility emergencies such as a fire or infectious disease outbreak. This plan is primarily required by which HIPAA standard?

    Answer: Administrative Safeguards — Contingency Plan

    The Contingency Plan standard under Administrative Safeguards (45 CFR § 164.308(a)(7)) requires covered entities to have policies for responding to emergencies that damage systems containing ePHI.