← All CMRT Flashcard Decks

Privacy & Security Flashcards

7 cards from real CMRT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Privacy & Security flashcards as text
  1. Which HIPAA provision gives patients the right to request restrictions on how their PHI is used for treatment, payment, or operations?

    Answer: Right to Request Restrictions

    The HIPAA Privacy Rule grants patients the right to request that a covered entity restrict uses or disclosures of PHI, though the entity is generally not required to agree.

  2. When a covered entity discloses PHI for public health reporting purposes, this is considered:

    Answer: A permitted disclosure under HIPAA without patient consent

    HIPAA permits disclosures for public health activities such as reporting communicable diseases to public health authorities without patient authorization.

  3. Which of the following is a 'technical safeguard' required by the HIPAA Security Rule?

    Answer: Implementing encryption for PHI transmitted over open networks

    Technical safeguards include encryption, access controls, audit controls, and integrity controls that protect electronic PHI through technology.

  4. A patient has paid out-of-pocket in full for a service and requests that the covered entity not disclose that encounter to their health plan. The covered entity must:

    Answer: Honor the restriction request

    Under HITECH, when a patient pays out-of-pocket in full and requests restriction from their health plan, the covered entity is required to honor that restriction.

  5. What distinguishes a 'covered entity' from a 'business associate' under HIPAA?

    Answer: Covered entities are healthcare providers, health plans, or clearinghouses that transmit PHI; business associates perform functions for them

    Covered entities are defined entities (providers, plans, clearinghouses) directly subject to HIPAA, while business associates are third parties that perform services involving PHI on their behalf.

  6. An organization conducting a risk analysis under HIPAA is assessing:

    Answer: The potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI

    HIPAA requires a thorough risk analysis to identify threats and vulnerabilities to ePHI as the foundation of a security management process.

  7. Which method ensures that PHI is unreadable to unauthorized parties if a laptop is lost or stolen?

    Answer: Full-disk encryption

    Full-disk encryption renders data on a lost or stolen device unreadable without the decryption key, which is why HIPAA guidelines recognize it as a key safeguard.