โ† All CHP Flashcard Decks

Treatment Protocols & Procedures Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Treatment Protocols & Procedures flashcards as text
  1. A covered entity's treatment protocol requires sharing PHI with a social worker employed by a different organization coordinating patient care. This is permissible under HIPAA when:

    Answer: A Business Associate Agreement is in place with the social worker's organization

    When a social worker's organization performs services involving PHI on behalf of a covered entity, a Business Associate Agreement is required.

  2. Under the HIPAA Security Rule, electronic treatment records (ePHI) transmitted between providers must be protected by:

    Answer: Encryption or equivalent safeguard during transmission

    The Security Rule requires that ePHI transmitted between providers be protected using encryption or an equivalent safeguard to prevent unauthorized interception.

  3. A patient involved in a clinical trial has treatment protocols managed by both the trial sponsor and a covered entity. HIPAA applies to:

    Answer: Only the covered entity's use and disclosure of PHI

    HIPAA obligations apply specifically to covered entities; the trial sponsor is governed by HIPAA only if it independently qualifies as a covered entity or business associate.

  4. Which HIPAA provision specifically requires covered entities to implement policies limiting who can access treatment protocols containing PHI?

    Answer: The minimum necessary standard under the Privacy Rule

    The minimum necessary standard requires covered entities to limit PHI access to workforce members who need it to perform their job functions.

  5. A hospital implements a protocol where all patients receive a copy of their treatment plan. Under HIPAA, patients have the right to request amendments to this plan if they believe the information is:

    Answer: Incomplete or inaccurate

    Under the HIPAA Privacy Rule, patients may request amendments to their PHI if they believe it is inaccurate or incomplete.

  6. In a multi-provider treatment setting, which of the following is the BEST safeguard to prevent unauthorized PHI access to treatment protocols?

    Answer: Assigning unique user credentials and role-based access controls to each provider

    Unique credentials and role-based access controls ensure that only authorized providers access the specific PHI needed for their role.

  7. A covered entity's surgical protocol requires documenting patient consent. If this documentation is breached, the covered entity must notify affected individuals within:

    Answer: 60 days of discovery

    The HIPAA Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovery of a breach.