โ† All HIPAA Flashcard Decks

Medical Information Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Medical Information flashcards as text
  1. Under HIPAA, which entity is primarily responsible for enforcing the Privacy and Security Rules?

    Answer: The Office for Civil Rights (OCR) within the Department of HHS

    The Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services is the primary federal agency that enforces HIPAA's Privacy and Security Rules.

  2. Which of the following best describes a 'hybrid entity' under HIPAA?

    Answer: An entity that performs both covered and non-covered functions and designates its health care components

    A hybrid entity is an organization whose business activities include both HIPAA-covered and non-covered functions, and it designates the covered components subject to HIPAA.

  3. A patient exercises their right to an Accounting of Disclosures. Which type of disclosure is EXCLUDED from this accounting?

    Answer: Disclosures for treatment, payment, and healthcare operations (TPO)

    Disclosures made for treatment, payment, and healthcare operations are excluded from the required Accounting of Disclosures under the Privacy Rule.

  4. Under HIPAA, what is the maximum civil monetary penalty per violation category for violations due to willful neglect that are not corrected?

    Answer: $50,000 per violation with a $1.5 million annual cap

    For willful neglect violations that are not corrected, the penalty is $50,000 per violation with an annual maximum of $1.5 million for identical violations.

  5. A researcher wants to use patient medical records for a study without patient authorization. Under HIPAA, this is permissible when:

    Answer: An Institutional Review Board (IRB) or Privacy Board waives the authorization requirement

    Research use of PHI without authorization is permitted when an IRB or Privacy Board has reviewed the research and waived the authorization requirement under established criteria.

  6. Which of the following is TRUE about the HIPAA Security Rule's administrative safeguards?

    Answer: They include a security management process requiring risk analysis and risk management

    Administrative safeguards include a security management process that requires covered entities to conduct a risk analysis and implement risk management measures to protect ePHI.

  7. A covered entity shares a patient's HIV status with an employer without authorization. This violates HIPAA because:

    Answer: HIV status is PHI and disclosure to employers is not a permissible purpose without authorization

    HIV status is PHI, and sharing it with an employer is not a permissible purpose under HIPAA, so patient authorization would be required for such disclosure.