The HIPAA Privacy Rule Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 The HIPAA Privacy Rule flashcards as text
Which of the following is NOT considered Protected Health Information (PHI) under the HIPAA Privacy Rule?
Answer: De-identified health information with all 18 identifiers removed
Once all 18 identifiers are removed using an approved de-identification method, the information is no longer PHI and is not subject to HIPAA Privacy Rule protections.
Under the HIPAA Privacy Rule, what is the 'minimum necessary' standard?
Answer: Covered entities must limit PHI use and disclosure to the minimum needed to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI access and disclosure to only what is needed for the intended purpose.
A covered entity may disclose PHI without patient authorization for which of the following purposes?
Answer: Reporting a gunshot wound to law enforcement as required by state law
HIPAA permits disclosure of PHI without authorization when required by law, such as mandatory reporting of gunshot wounds to law enforcement.
How long must a covered entity retain its HIPAA Privacy Rule policies and documentation?
Answer: 6 years from the date of creation or last effective date
The HIPAA Privacy Rule requires covered entities to retain policies, procedures, and documentation for 6 years from the date of creation or the date when last in effect.
Which individual within a covered entity is specifically required by the HIPAA Privacy Rule?
Answer: Privacy Officer
The HIPAA Privacy Rule requires covered entities to designate a Privacy Officer responsible for developing and implementing privacy policies and procedures.
Under what circumstance may a covered entity deny a patient's request to access their own PHI?
Answer: A licensed healthcare professional determines access is likely to cause substantial harm to the patient
A covered entity may deny access if a licensed healthcare professional believes the information could endanger the life or safety of the patient or another person.
What must a covered entity include in its Notice of Privacy Practices (NPP)?
Answer: A description of the types of uses and disclosures the covered entity may make of PHI
The NPP must describe how the covered entity may use and disclose PHI, patient rights, and the covered entity's legal duties regarding PHI.