Mixed Deck — All HIPAA Topics Flashcards
100 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All HIPAA Topics flashcards as text
Which entity type is subject to 42 CFR Part 2 but would NOT automatically be a HIPAA covered entity?
Answer: A federally assisted non-medical substance abuse counseling program that does not transmit health information electronically
A federally assisted SUD counseling program that doesn't bill electronically or transmit health information electronically is subject to Part 2 but may not meet HIPAA's definition of a covered entity.
A hospital migrates to a new EHR system. What HIPAA requirement applies to PHI stored in the old system?
Answer: It must be retained according to applicable retention laws and securely disposed of when no longer needed
HIPAA requires that PHI be retained per applicable state and federal retention laws, and disposed of securely when retention periods expire.
A covered entity discovers that a business associate has experienced a breach of PHI. Who is primarily responsible for notifying affected individuals?
Answer: The covered entity is responsible for notifying affected individuals
Under the HIPAA Breach Notification Rule, the covered entity bears primary responsibility for notifying affected individuals, even when the breach occurred at a business associate.
What is the annual cap on civil monetary penalties for identical violations under a single HIPAA provision?
Answer: $1,919,173 (inflation-adjusted)
The annual cap per identical violation category is $1.5 million, adjusted periodically for inflation (currently approximately $1.919 million).
A covered entity's employee discovers that a family member is a patient at their organization. Under HIPAA, what is the employee's obligation?
Answer: The employee must not access the family member's records unless they are directly involved in that person's care
Workforce members may not access PHI of patients they are not involved in treating — 'snooping' on family members' records is a HIPAA violation even with good intentions.
Which of the following is NOT a factor OCR considers when determining the amount of a civil monetary penalty?
Answer: The political affiliation of the covered entity's leadership
OCR considers factors such as harm, number of individuals affected, and financial condition, but political affiliation is not a relevant factor.
A marketing firm offers to analyze patient data and share aggregated results with third parties for profit. A covered entity wants to hire this firm. What HIPAA concern arises?
Answer: The BAA would need to explicitly prohibit the firm from using PHI for its own commercial purposes
A BAA must prohibit business associates from using PHI for their own purposes, including commercial gain, beyond what the agreement permits.
Under HIPAA, a 'covered entity' includes all of the following EXCEPT:
Answer: Employers who sponsor self-insured health plans
Employers who sponsor self-insured health plans are not themselves covered entities; however, the plan itself may be a covered entity, and employers must separate plan functions from employment functions.
What are 'psychotherapy notes' under HIPAA, and how do they differ from other mental health records?
Answer: Psychotherapy notes are notes from a therapist's private files capturing mental impressions during therapy, separate from formal treatment records, and requiring specific authorization for disclosure
Psychotherapy notes are mental impressions and analysis captured in a therapist's private files — distinct from treatment records — and require specific authorization for most disclosures.
Which entity has primary enforcement authority over HIPAA compliance?
Answer: The Office for Civil Rights (OCR) within HHS
The HHS Office for Civil Rights (OCR) is the primary federal agency responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules.
Under the HIPAA Security Rule, which standard requires covered entities to have policies for responding to a security incident?
Answer: Security Incident Procedures
The Security Incident Procedures standard requires covered entities to identify, respond to, mitigate, and document security incidents involving ePHI.
Which HIPAA technical safeguard standard requires covered entities to implement controls ensuring only authorized users can access ePHI systems?
Answer: Access Control
The Access Control standard requires technical policies and procedures allowing only authorized persons or software programs to access ePHI.
A patient's legal guardian submits a request to access the patient's PHI. Under HIPAA, the guardian is treated as:
Answer: A personal representative with the same rights as the patient
HIPAA recognizes personal representatives, including legal guardians, as having the same access rights as the patient.
When can a covered entity DENY a patient's request to restrict disclosure of their PHI?
Answer: When the disclosure is required for emergency treatment
A covered entity may deny a restriction request if the PHI is needed to provide emergency treatment to the patient.
A patient requests an accounting of disclosures of their Protected Health Information (PHI) from a hospital. Which of the following disclosures must be EXCLUDED from this accounting report?
Answer: A disclosure made to the patient's health plan for payment purposes.
The HIPAA Privacy Rule specifically exempts disclosures made for Treatment, Payment, and healthcare Operations (TPO) from the accounting of disclosures requirement. Disclosures for public health activities, in response to court orders, or for health oversight are not part of TPO and must be included in an accounting if requested.
A patient requests access to their PHI in an electronic format. If the covered entity maintains the records electronically, it must:
Answer: Provide the records in the electronic format requested by the individual if readily producible
Under HIPAA and HITECH, if a covered entity maintains PHI electronically, it must provide that PHI in the electronic format requested by the individual if it is readily producible in that format.
Under the HIPAA Privacy Rule, which of the following entities is considered a 'covered entity'?
Answer: A health plan that pays for medical care
Health plans are one of the three categories of covered entities under HIPAA, along with healthcare providers and healthcare clearinghouses.
What is 'top-coding' and 'bottom-coding' in the context of health data de-identification?
Answer: Capping extreme values at a threshold to prevent identification of outliers — e.g., capping age at '65+' or capping charges at '$100,000+'
Top-coding and bottom-coding cap extreme values at a threshold, preventing identification of outliers who might be identifiable by unusual values.
Which HITECH provision specifically addressed the problem of organizations that lacked proper safeguards but had never been investigated by HHS?
Answer: The mandate for HHS to conduct periodic audits of covered entities and business associates
HITECH directed HHS to conduct regular compliance audits, creating proactive oversight rather than relying solely on complaint-driven enforcement.
A hospital's de-identification policy strips birth years from all records. Under Safe Harbor, is this required for patients under age 90?
Answer: No, only the full date of birth must be removed; the year of birth may be retained for patients under 90
Safe Harbor requires removal of the full date of birth (month, day, and year) but permits retention of the year of birth for patients aged 89 or younger.