โ† All HIPAA Flashcard Decks

Compliance Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance flashcards as text
  1. The HIPAA Breach Notification Rule defines 'unsecured PHI' as PHI that has NOT been:

    Answer: Rendered unusable, unreadable, or indecipherable through approved methods such as encryption or destruction

    Unsecured PHI is PHI that has not been rendered unusable, unreadable, or indecipherable to unauthorized individuals through encryption or destruction per HHS guidance.

  2. Which of the following scenarios would most likely qualify for the 'limited data set' exception under HIPAA?

    Answer: Sharing PHI with direct geographic identifiers removed (but zip codes retained) under a data use agreement for research

    A limited data set removes most direct identifiers but may retain zip codes and dates; it requires a data use agreement and is permissible for research, public health, and health care operations.

  3. A healthcare clearinghouse processes claims for multiple covered entities. Under HIPAA, the clearinghouse is classified as:

    Answer: A covered entity subject to HIPAA directly

    Healthcare clearinghouses are directly defined as covered entities under HIPAA because they process nonstandard health information into standard formats (or vice versa).

  4. Under HIPAA, an individual's right to an accounting of disclosures applies to disclosures made for which of the following purposes?

    Answer: Disclosures required by law, for public health purposes, and other non-TPO disclosures

    The right to an accounting covers disclosures other than those for TPO, to the individual themselves, or pursuant to an authorization, for the 6 years prior to the request.

  5. A covered entity that is also a hybrid entity must:

    Answer: Designate its health care component(s) and apply HIPAA only to those components

    A hybrid entity must designate its health care component(s) in writing and ensure HIPAA applies to those components; non-health care components of the organization are generally not covered.

  6. When a covered entity imposes a fee for providing an individual with access to their PHI, HIPAA limits that fee to:

    Answer: A reasonable, cost-based fee covering labor, supplies, and postage only

    HIPAA limits fees for PHI access to a reasonable, cost-based fee that covers the cost of labor for copying, supplies, postage, and preparing an explanation or summary if requested.

  7. Which of the following best describes the 'conditioned' vs. 'unconditioned' authorization distinction under HIPAA?

    Answer: Conditioned authorizations tie treatment to signing a research consent; unconditioned ones do not

    HIPAA prohibits conditioning treatment on an individual signing an authorization for a use unrelated to treatment (such as research), making such bundled authorizations 'conditioned' and generally impermissible.