Protected Health Information (PHI) Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Protected Health Information (PHI) flashcards as text
Which of the following is NOT considered one of the 18 HIPAA identifiers that make health information PHI?
Answer: Blood type alone
Blood type alone is not one of the 18 identifiers listed under HIPAA; it only becomes PHI when combined with an identifier that links it to a specific individual.
A hospital shares a patient's treatment records with a business associate for billing purposes. Under HIPAA, this disclosure is:
Answer: Permitted as part of Treatment, Payment, or Operations (TPO)
HIPAA permits covered entities to disclose PHI to business associates for Treatment, Payment, and Healthcare Operations (TPO) without additional patient authorization.
Under HIPAA, 'de-identification' of PHI can be achieved through which two accepted methods?
Answer: Expert determination and safe harbor
HIPAA recognizes two official de-identification methods: Expert Determination (statistical verification of re-identification risk) and the Safe Harbor method (removal of all 18 identifiers).
A patient's name combined with their appointment date at a mental health clinic is considered PHI because:
Answer: It links an identifier to information that reveals health status or treatment
PHI is created when an identifier (like a name) is combined with information that relates to a person's health condition, treatment, or payment for healthcare.
Which entity is primarily responsible for enforcing HIPAA's Privacy Rule?
Answer: The Office for Civil Rights (OCR) within HHS
The Office for Civil Rights (OCR) within the Department of Health and Human Services (HHS) is the primary enforcement agency for HIPAA's Privacy and Security Rules.
A researcher wants to use patient data without obtaining individual authorizations. Under HIPAA, this is permissible if:
Answer: An Institutional Review Board (IRB) waives the authorization requirement
HIPAA allows use of PHI for research without individual authorization when an IRB or Privacy Board grants a waiver based on criteria protecting patients' privacy interests.
What is the HIPAA 'minimum necessary' standard as it applies to PHI?
Answer: Only the minimum amount of PHI needed to accomplish a purpose should be used or disclosed
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to the least amount needed to accomplish the intended purpose.