Compliance, Privacy, and Security Flashcards
6 cards from real RHIA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Compliance, Privacy, and Security flashcards as text
What patient right under HIPAA allows individuals to request corrections to their health information?
Answer: Right to amend
The HIPAA right to amend allows patients to request corrections to PHI in a covered entity's designated record set if they believe the information is inaccurate or incomplete.
Which HIPAA provision requires covered entities to provide patients with a list of certain disclosures made of their PHI?
Answer: Right to an accounting of disclosures
The right to an accounting of disclosures requires covered entities to provide patients with a list of certain disclosures made outside of TPO purposes upon request.
What is required for a valid HIPAA-compliant authorization for release of PHI?
Answer: Written signed authorization with required elements including expiration date and right to revoke
A valid HIPAA authorization must be written, signed, and include required elements such as a description of PHI, purpose, expiration date, and notice of the right to revoke.
Under the 21st Century Cures Act, what are 'information blocking' practices?
Answer: Practices that unreasonably interfere with the access, exchange, or use of electronic health information (EHI)
Information blocking under the 21st Century Cures Act refers to practices by health IT developers, networks, or providers that unreasonably restrict the access, exchange, or use of EHI.
What is the purpose of a Notice of Privacy Practices (NPP) under HIPAA?
Answer: Inform patients of their privacy rights and how their PHI may be used and disclosed
The NPP informs patients of their HIPAA privacy rights and how the covered entity may use and disclose their PHI, and must be provided at first contact.
Which HIPAA-required safeguard type includes policies, training, and workforce management procedures?
Answer: Administrative safeguards
Administrative safeguards under the HIPAA Security Rule include security management processes, workforce training, contingency planning, and other policy-driven controls.