← All HIPAA Flashcard Decks

HITECH Act and Technology Requirements Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 HITECH Act and Technology Requirements flashcards as text
  1. Under HITECH, when a covered entity discovers a breach affecting 500 or more individuals in a state, when must media notification occur?

    Answer: Within 60 days of discovery

    Covered entities must notify prominent media outlets in affected states within 60 days of discovering a breach that affects 500 or more state residents.

  2. Which standard specifies the encryption requirements for PHI at rest that satisfy HITECH's breach notification safe harbor?

    Answer: FIPS 140-2

    NIST guidance specifying FIPS 140-2 validated encryption processes is referenced as the standard for PHI at rest to qualify for HITECH's safe harbor.

  3. How did HITECH change the HIPAA requirement for covered entities to obtain patient authorization for psychotherapy notes used in treatment?

    Answer: HITECH did not change psychotherapy note authorization requirements

    HITECH did not change HIPAA's existing requirement that psychotherapy notes require authorization even for treatment purposes—that protection predates HITECH.

  4. Under HITECH, what must a covered entity do if an individual requests a restriction on disclosure of their PHI to a health plan for a service the individual paid for out-of-pocket?

    Answer: The covered entity must agree to the restriction

    HITECH requires covered entities to honor a patient's request to restrict disclosure to a health plan when the patient has paid out-of-pocket in full for the service.

  5. A cloud service provider stores encrypted PHI for a covered entity but cannot access the encryption keys. Under HITECH, is this provider a business associate?

    Answer: Yes, because they create, receive, maintain, or transmit PHI on behalf of the covered entity

    HHS has clarified that a cloud service provider handling encrypted PHI is a business associate even without access to decryption keys, because they maintain PHI on behalf of a covered entity.

  6. Which HITECH program evolved into the Medicare and Medicaid EHR Incentive Programs and later the Promoting Interoperability Programs?

    Answer: Meaningful Use program

    The Meaningful Use program, established under HITECH, evolved through three stages and was eventually rebranded as the Promoting Interoperability Programs.

  7. Under HITECH's penalty framework, which scenario would most likely be classified in the 'reasonable cause' tier rather than 'willful neglect'?

    Answer: A covered entity's security policy had a gap that a reasonable organization would have identified

    Reasonable cause applies when a violation results from circumstances a covered entity knew or should have known about, but does not rise to the level of willful neglect.