Free Certified in Healthcare Privacy and Security Trivia Questions and Answers — Questions and Answers
Question 1: Which of the following is under HIPAA and involves giving a primary care provider a copy of an emergency department visit report?
- Fair underwriting practices
- Disclosure of protected health information (Correct answer)
- Fair claims practices
- Coordination of benefits
Correct answer: Disclosure of protected health information
Providing a copy of an emergency room visit report to a primary care provider is an example of a "disclosure of protected health information" under HIPAA. <br> <br> HIPAA, the Health Insurance Portability and Accountability Act, establishes rules and regulations to protect the privacy and security of individuals' protected health information (PHI). PHI refers to any individually identifiable health information held or transmitted by a covered entity or its business associates.
Question 2: A covered company has been asked in writing to postpone notifying the public of a data breach because it would complicate an investigation. How long may the covered entity delay sending the notice?
- By the amount time specified in the request. (Correct answer)
- Who is accessing information for business needs within the organization
- Implement based on organizational assessment
- Designated record set
Correct answer: By the amount time specified in the request.
Under the HIPAA Breach Notification Rule, if law enforcement provides a written statement that notification would impede an investigation, the covered entity must delay only for the specific time period stated in that request. The other options describe access-control or record-set concepts unrelated to a notification delay.
Question 3: The organization must take action if a health insurance provider contacts a member to advertise a car insurance plan provided by the same provider.
- After 6 years
- All electronic systems
- Risk avoidance
- Authorization for disclosure for marketing purposes (Correct answer)
Correct answer: Authorization for disclosure for marketing purposes
Under the Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule, covered entities are generally required to provide timely notification to individuals whose protected health information (PHI) has been breached. The notification should be made without unreasonable delay and no later than 60 days from the discovery of the breach.
Question 4: Data is sent between computers in encrypted form. Which of the following best represents the date following the use of the encryption algorithm?
- Endpoint groups
- Device controls (Correct answer)
- Agent installations
- Residual
Correct answer: Device controls
The term that describes the data after the encryption algorithm has been applied is "encrypted data." <br> <br> Encryption is a process of encoding data to make it unreadable or unintelligible to unauthorized individuals. It involves using an encryption algorithm and a key to transform the original data into encrypted form, also known as ciphertext.
Question 5: How much time is allotted for a covered company to reply to an accounting of disclosure request?
- 30 days with one 30 day extension (Correct answer)
- Security update
- Facility security plan
- Acts of man
Correct answer: 30 days with one 30 day extension
A covered entity under the Health Insurance Portability and Accountability Act (HIPAA) has a maximum of 30 days to respond to an accounting of disclosure request from an individual. However, if the covered entity is unable to meet the deadline within the initial 30-day period, they can request a one-time 30-day extension to provide a response.
Question 6: When a patient obtains a treatment, pays out of pocket, and wishes that information not be forwarded to his or her personal account, a healthcare institution must abide by a limitation.
- The board of directors or trustees
- Health insurance company (Correct answer)
- The individual seeking the care
- Treatment
Correct answer: Health insurance company
A healthcare organization must comply with a restriction when a patient receives a service, pays out of pocket, and requests that information is not sent to his/her health insurance company. <br> <br> Under the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule, the disclosure of protected health information (PHI) for marketing purposes generally requires the individual's authorization. PHI includes any individually identifiable health information held or transmitted by a covered entity or its business associates.
Question 7: A new business partner was employed by a covered organization. The business associate asked the covered entity to sign the contract provided by the vendor during the assessment of the business associates agreement. Is this a proper procedure?
- Access establishment and modifications
- Device controls
- Yes, the covered entity must review the documentation in the business associate agreement and agree to it (Correct answer)
- All electronic systems
Correct answer: Yes, the covered entity must review the documentation in the business associate agreement and agree to it
Yes — the covered entity is responsible for reviewing the terms of a Business Associate Agreement and agreeing to them before signing, so reviewing the vendor-provided contract is proper procedure. The other options reference Security Rule administrative controls, not the BAA review process.
Which of the following is under HIPAA and involves giving a primary care provider a copy of an emergency department visit report?