Medical Information Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Medical Information flashcards as text
Under HIPAA, which of the following is considered Protected Health Information (PHI)?
Answer: A patient's name combined with their diagnosis
PHI is individually identifiable health information, meaning a name combined with a diagnosis links a person to their health condition and qualifies as PHI.
A hospital shares a patient's medical records with a billing company to process insurance claims. Under HIPAA, this sharing is:
Answer: Permitted as a Treatment, Payment, or Healthcare Operations (TPO) activity
HIPAA permits disclosure of PHI for treatment, payment, and healthcare operations (TPO) without requiring patient authorization.
What does the HIPAA Minimum Necessary Standard require when accessing medical information?
Answer: Covered entities must share the least amount of PHI needed to accomplish the intended purpose
The Minimum Necessary Standard requires that only the PHI needed to accomplish a specific purpose be accessed, used, or disclosed.
A nurse looks up the medical records of a neighbor out of curiosity, without any treatment purpose. This action violates which HIPAA principle?
Answer: The Minimum Necessary Standard and permissible purpose requirements
Accessing PHI without a permissible purpose and beyond what is necessary violates the Minimum Necessary Standard and HIPAA's use/disclosure rules.
Which of the following best describes 'de-identified' health information under HIPAA's Safe Harbor method?
Answer: Information from which all 18 specified identifiers have been removed
Under the Safe Harbor method, health information is de-identified when all 18 specific identifiers listed in the HIPAA Privacy Rule have been removed.
A patient requests a copy of their medical records. Under the HIPAA Right of Access, how long does a covered entity generally have to fulfill this request?
Answer: 30 calendar days, with one possible 30-day extension
Covered entities must provide access within 30 calendar days of the request, with one 30-day extension allowed if the entity notifies the patient.
Under HIPAA, psychotherapy notes receive a higher level of protection than other medical records because:
Answer: They require separate patient authorization for most disclosures, beyond standard TPO
Psychotherapy notes are afforded extra protection and generally require specific patient authorization for disclosure even for treatment, payment, or operations purposes.