Treatment Protocols & Procedures Flashcards
7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Treatment Protocols & Procedures flashcards as text
A covered entity's treatment protocol requires sharing PHI with a social worker employed by a different organization coordinating patient care. This is permissible under HIPAA when:
Answer: A Business Associate Agreement is in place with the social worker's organization
When a social worker's organization performs services involving PHI on behalf of a covered entity, a Business Associate Agreement is required.
Under the HIPAA Security Rule, electronic treatment records (ePHI) transmitted between providers must be protected by:
Answer: Encryption or equivalent safeguard during transmission
The Security Rule requires that ePHI transmitted between providers be protected using encryption or an equivalent safeguard to prevent unauthorized interception.
A patient involved in a clinical trial has treatment protocols managed by both the trial sponsor and a covered entity. HIPAA applies to:
Answer: Only the covered entity's use and disclosure of PHI
HIPAA obligations apply specifically to covered entities; the trial sponsor is governed by HIPAA only if it independently qualifies as a covered entity or business associate.
Which HIPAA provision specifically requires covered entities to implement policies limiting who can access treatment protocols containing PHI?
Answer: The minimum necessary standard under the Privacy Rule
The minimum necessary standard requires covered entities to limit PHI access to workforce members who need it to perform their job functions.
A hospital implements a protocol where all patients receive a copy of their treatment plan. Under HIPAA, patients have the right to request amendments to this plan if they believe the information is:
Answer: Incomplete or inaccurate
Under the HIPAA Privacy Rule, patients may request amendments to their PHI if they believe it is inaccurate or incomplete.
In a multi-provider treatment setting, which of the following is the BEST safeguard to prevent unauthorized PHI access to treatment protocols?
Answer: Assigning unique user credentials and role-based access controls to each provider
Unique credentials and role-based access controls ensure that only authorized providers access the specific PHI needed for their role.
A covered entity's surgical protocol requires documenting patient consent. If this documentation is breached, the covered entity must notify affected individuals within:
Answer: 60 days of discovery
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovery of a breach.