HITECH Act and Technology Requirements Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 HITECH Act and Technology Requirements flashcards as text
What technology standard does HITECH specifically reference as a safe harbor for breach notification involving PHI?
Answer: Encryption and destruction
HITECH's breach notification safe harbor applies when PHI is rendered unusable, unreadable, or indecipherable through encryption or destruction.
Which federal agency issued the guidance specifying encryption standards that qualify for HITECH's breach notification safe harbor?
Answer: NIST
NIST issued the guidance on encryption standards and destruction methods that qualify PHI for HITECH's breach notification safe harbor.
The HITECH Act's Meaningful Use program incentivized healthcare providers to adopt EHRs primarily through which mechanism?
Answer: Medicare and Medicaid payment incentives
Meaningful Use provided Medicare and Medicaid payment incentives to eligible professionals and hospitals that demonstrated meaningful use of certified EHR technology.
Under HITECH, what restriction applies to fundraising communications sent using electronic PHI?
Answer: Patients must be given an opportunity to opt out of future fundraising
HITECH requires that fundraising communications include a clear opportunity for recipients to opt out of receiving future fundraising communications.
What does the HITECH Act require covered entities to include in their Notice of Privacy Practices regarding PHI sale?
Answer: A statement that authorization is required before selling PHI
HITECH requires covered entities to state in their Notice of Privacy Practices that patient authorization is required before the entity may sell PHI.
Which HITECH provision most directly addressed the concern that business associates were not sufficiently accountable for PHI they handled?
Answer: Direct application of HIPAA Security Rule to business associates
HITECH directly applied the HIPAA Security Rule to business associates, making them independently liable rather than relying solely on contractual obligations.
A hospital uses a certified EHR but fails to conduct a required security risk analysis. Under HITECH, which penalty tier most likely applies?
Answer: Willful neglect corrected within 30 days ($10,000–$50,000)
Failing to conduct a required security risk analysis while operating an EHR system typically indicates willful neglect, and prompt correction would place it in the $10,000–$50,000 tier.