HIPAA and Patient Confidentiality Flashcards
7 cards from real CMAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 HIPAA and Patient Confidentiality flashcards as text
A patient calls the office asking for their test results to be left on their home answering machine. The medical administrative assistant should:
Answer: Honor the request by leaving only the minimum necessary information and a callback number
HIPAA allows covered entities to communicate with patients by their preferred method, including voicemail, but only the minimum necessary information should be left.
Under HIPAA, a 'business associate' is best described as:
Answer: A person or entity that performs functions involving PHI on behalf of a covered entity
A business associate is a person or organization that performs certain functions or activities that involve the use or disclosure of PHI on behalf of, or in service to, a covered entity.
Which of the following represents an appropriate 'minimum necessary' practice when sharing PHI?
Answer: Providing only the specific information needed to fulfill a request for treatment purposes
The minimum necessary standard requires that covered entities limit the PHI disclosed to only what is needed to accomplish the intended purpose.
If a HIPAA breach is discovered, the covered entity must notify affected individuals within:
Answer: 60 days of discovery
HIPAA's Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovering a breach of unsecured PHI.
A patient's 16-year-old child calls to ask about a parent's medical records. Under HIPAA, the administrative assistant should:
Answer: Verify whether the minor child is listed as an authorized representative before releasing any information
HIPAA requires verification that an individual is an authorized personal representative before disclosing a patient's PHI to a third party, including family members.
Which of the following is an example of a physical safeguard required under the HIPAA Security Rule?
Answer: Using locked cabinets or restricted-access areas for workstations containing ePHI
Physical safeguards include facility access controls, workstation security, and device and media controls — such as locked areas — to protect ePHI from unauthorized physical access.
An employee shares a patient's diagnosis with a coworker out of curiosity. This is a violation of which HIPAA principle?
Answer: The minimum necessary standard and Privacy Rule prohibitions on unauthorized disclosure
Sharing a patient's diagnosis without a legitimate treatment, payment, or operations purpose violates the Privacy Rule's minimum necessary standard and prohibition on unauthorized PHI disclosures.