Regulatory Compliance & Standards Flashcards
7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Standards flashcards as text
Under HIPAA, which federal agency is primarily responsible for enforcing the Privacy and Security Rules?
Answer: Office for Civil Rights (OCR) within HHS
The Office for Civil Rights (OCR) within the Department of Health and Human Services enforces HIPAA's Privacy and Security Rules.
Which HIPAA rule specifically requires covered entities to implement administrative, physical, and technical safeguards for electronic PHI?
Answer: Security Rule
The HIPAA Security Rule mandates that covered entities protect electronic PHI through administrative, physical, and technical safeguards.
A covered entity discovers a breach affecting 600 individuals. By what deadline must it notify the Secretary of HHS?
Answer: Within 60 days of the end of the calendar year in which the breach occurred
Breaches affecting fewer than 500 individuals must be reported to HHS within 60 days after the end of the calendar year in which the breach occurred.
The HITECH Act expanded HIPAA compliance requirements by making which entities directly liable for HIPAA violations?
Answer: Business associates
The HITECH Act extended direct HIPAA liability to business associates, who were previously only bound by contract terms.
Which of the following is NOT a required element of a HIPAA-compliant Notice of Privacy Practices (NPP)?
Answer: A list of all business associates and their specific data access rights
NPPs must describe uses/disclosures, patient rights, and contact information for the privacy officer, but do not require listing all business associates and their specific access rights.
Under the HIPAA Enforcement Rule, what is the maximum annual penalty cap per violation category for willful neglect that is corrected?
Answer: $1,900,000
For willful neglect that is corrected within 30 days, the annual cap per identical violation category is $1,900,000 (adjusted for inflation from the original $1,500,000).
Which standard specifies that a covered entity may not use or disclose more PHI than is reasonably necessary to accomplish the intended purpose?
Answer: Minimum Necessary Standard
The Minimum Necessary Standard requires covered entities to limit PHI use and disclosure to the least amount needed to accomplish the purpose.