← All CMRT Flashcard Decks

Privacy & Security Flashcards

7 cards from real CMRT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Privacy & Security flashcards as text
  1. What is a 'designated record set' under HIPAA?

    Answer: The medical and billing records used to make decisions about an individual

    A designated record set includes the medical, billing, and other records a covered entity uses to make decisions about individuals, which patients have rights to access and amend.

  2. Under HIPAA, psychotherapy notes are treated differently from other medical records because:

    Answer: They require specific patient authorization for most disclosures, separate from the general authorization

    Psychotherapy notes held separately from the medical record receive special protection and generally require patient authorization even for disclosures that are otherwise permissible.

  3. A 'chain of trust' agreement in health information exchange ensures that:

    Answer: Each entity in a data-sharing network agrees to protect PHI consistently

    Chain of trust agreements require all participants in a health information network to maintain equivalent privacy and security protections for PHI.

  4. Which action best demonstrates the 'physical safeguard' requirements of the HIPAA Security Rule?

    Answer: Restricting access to server rooms with key card entry

    Physical safeguards include facility access controls such as key card entry, locks, and workstation use policies that physically protect electronic PHI.

  5. When must a covered entity report a breach affecting 500 or more individuals to HHS and the media?

    Answer: Within 60 days of discovery

    Breaches affecting 500 or more individuals in a state or jurisdiction require notification to HHS and prominent media outlets within 60 calendar days of discovery.

  6. Under HIPAA, which of the following is a permissible disclosure of PHI without patient authorization?

    Answer: Disclosing records to a coroner or medical examiner

    HIPAA permits disclosures to coroners and medical examiners for purposes such as identifying a deceased person or determining cause of death.

  7. The HIPAA 'Safe Harbor' de-identification method requires removal of how many specific identifiers?

    Answer: 18

    HIPAA's Safe Harbor method requires removal of 18 specific identifiers (such as names, geographic data, dates, phone numbers, SSNs) to consider data de-identified.