Compliance Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Compliance flashcards as text
The HIPAA Breach Notification Rule defines 'unsecured PHI' as PHI that has NOT been:
Answer: Rendered unusable, unreadable, or indecipherable through approved methods such as encryption or destruction
Unsecured PHI is PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized individuals through encryption or destruction per HHS guidance.
Which of the following scenarios would most likely qualify for the 'limited data set' exception under HIPAA?
Answer: Sharing PHI with direct geographic identifiers removed (but zip codes retained) under a data use agreement for research
A limited data set removes most direct identifiers but may retain zip codes and dates; it requires a data use agreement and is permissible for research, public health, and health care operations.
A healthcare clearinghouse processes claims for multiple covered entities. Under HIPAA, the clearinghouse is classified as:
Answer: A covered entity subject to HIPAA directly
Healthcare clearinghouses are directly defined as covered entities under HIPAA because they process nonstandard health information into standard formats (or vice versa).
Under HIPAA, an individual's right to an accounting of disclosures applies to disclosures made for which of the following purposes?
Answer: Disclosures required by law, for public health purposes, and other non-TPO disclosures
The right to an accounting covers disclosures other than those for TPO, to the individual themselves, or pursuant to an authorization, for the 6 years prior to the request.
A covered entity that is also a hybrid entity must:
Answer: Designate its health care component(s) and apply HIPAA only to those components
A hybrid entity must designate its health care component(s) in writing and ensure HIPAA applies to those components; non-health care components of the organization are generally not covered.
When a covered entity imposes a fee for providing an individual with access to their PHI, HIPAA limits that fee to:
Answer: A reasonable, cost-based fee covering labor, supplies, and postage only
HIPAA limits fees for PHI access to a reasonable, cost-based fee that covers the cost of labor for copying, supplies, postage, and preparing an explanation or summary if requested.
Which of the following best describes the 'conditioned' vs. 'unconditioned' authorization distinction under HIPAA?
Answer: Conditioned authorizations tie treatment to signing a research consent; unconditioned ones do not
HIPAA prohibits conditioning treatment on an individual signing an authorization for a use unrelated to treatment (such as research), making such bundled authorizations 'conditioned' and generally impermissible.