Privacy & Data Security Flashcards
6 cards from real HMCC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Privacy & Data Security flashcards as text
What is the HIPAA Privacy Rule?
Answer: Federal regulations establishing standards for how covered entities must protect and handle patients' protected health information
The Privacy Rule establishes national standards for the use and disclosure of PHI by covered entities (health plans, healthcare clearinghouses, providers), including patient rights to access and control their health information.
What is the HIPAA Security Rule?
Answer: Federal regulations requiring covered entities to implement administrative, physical, and technical safeguards to protect electronic PHI
The Security Rule requires covered entities to ensure the confidentiality, integrity, and availability of electronic PHI through administrative safeguards (policies, training), physical safeguards (facility access), and technical safeguards (encryption, access controls).
What is a Business Associate Agreement (BAA)?
Answer: A contract between a covered entity and a business associate that establishes permitted uses and required protections for PHI
BAAs are required when covered entities share PHI with business associates (billing companies, IT vendors, cloud providers). The agreement specifies how the associate will protect PHI and report breaches.
What is the HIPAA Breach Notification Rule?
Answer: A requirement to notify affected individuals, HHS, and sometimes the media when unsecured PHI is accessed or disclosed without authorization
The Breach Notification Rule requires notification to affected individuals within 60 days, to HHS (and media for breaches affecting 500+ individuals), with specific content requirements for each notification.
What is the minimum necessary standard under HIPAA?
Answer: The requirement to limit PHI use, disclosure, and requests to the minimum amount necessary to accomplish the intended purpose
The minimum necessary standard requires covered entities to make reasonable efforts to use, disclose, and request only the minimum PHI needed for the particular purpose, limiting unnecessary exposure of patient information.
What are a patient's rights under the HIPAA Privacy Rule?
Answer: Right to access their records, request amendments, receive an accounting of disclosures, request restrictions, and receive a notice of privacy practices
HIPAA grants patients significant rights: accessing and obtaining copies of their PHI, requesting corrections, knowing who has received their information, requesting communication preferences, and understanding privacy practices.