← All HIPAA Flashcard Decks

HITECH Act and Technology Requirements Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 HITECH Act and Technology Requirements flashcards as text
  1. What technology standard does HITECH specifically reference as a safe harbor for breach notification involving PHI?

    Answer: Encryption and destruction

    HITECH's breach notification safe harbor applies when PHI is rendered unusable, unreadable, or indecipherable through encryption or destruction.

  2. Which federal agency issued the guidance specifying encryption standards that qualify for HITECH's breach notification safe harbor?

    Answer: NIST

    NIST issued the guidance on encryption standards and destruction methods that qualify PHI for HITECH's breach notification safe harbor.

  3. The HITECH Act's Meaningful Use program incentivized healthcare providers to adopt EHRs primarily through which mechanism?

    Answer: Medicare and Medicaid payment incentives

    Meaningful Use provided Medicare and Medicaid payment incentives to eligible professionals and hospitals that demonstrated meaningful use of certified EHR technology.

  4. Under HITECH, what restriction applies to fundraising communications sent using electronic PHI?

    Answer: Patients must be given an opportunity to opt out of future fundraising

    HITECH requires that fundraising communications include a clear opportunity for recipients to opt out of receiving future fundraising communications.

  5. What does the HITECH Act require covered entities to include in their Notice of Privacy Practices regarding PHI sale?

    Answer: A statement that authorization is required before selling PHI

    HITECH requires covered entities to state in their Notice of Privacy Practices that patient authorization is required before the entity may sell PHI.

  6. Which HITECH provision most directly addressed the concern that business associates were not sufficiently accountable for PHI they handled?

    Answer: Direct application of HIPAA Security Rule to business associates

    HITECH directly applied the HIPAA Security Rule to business associates, making them independently liable rather than relying solely on contractual obligations.

  7. A hospital uses a certified EHR but fails to conduct a required security risk analysis. Under HITECH, which penalty tier most likely applies?

    Answer: Willful neglect corrected within 30 days ($10,000–$50,000)

    Failing to conduct a required security risk analysis while operating an EHR system typically indicates willful neglect, and prompt correction would place it in the $10,000–$50,000 tier.

HITECH Act and Technology Requirements Flashcards — HIPAA Study Cards with Answers