Compliance, Privacy, and Security Flashcards
6 cards from real RHIA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Compliance, Privacy, and Security flashcards as text
Under HIPAA, which rule specifically governs the security of electronic protected health information (ePHI)?
Answer: HIPAA Security Rule
The HIPAA Security Rule establishes national standards for protecting ePHI through administrative, physical, and technical safeguards.
What is the minimum necessary standard under the HIPAA Privacy Rule?
Answer: Covered entities must disclose only the minimum PHI needed to accomplish the intended purpose
The minimum necessary standard requires covered entities to limit PHI use and disclosure to only what is needed to accomplish the purpose of the use or disclosure.
Who is considered a 'covered entity' under HIPAA?
Answer: Health plans, healthcare clearinghouses, and healthcare providers that transmit PHI electronically
HIPAA covered entities include health plans, healthcare clearinghouses, and healthcare providers (hospitals, physicians, etc.) that transmit PHI electronically for covered transactions.
Under the HIPAA Privacy Rule, which of the following does NOT require patient authorization for disclosure?
Answer: Disclosure for treatment, payment, or healthcare operations (TPO)
The HIPAA Privacy Rule permits disclosure of PHI without patient authorization for treatment, payment, and healthcare operations (TPO) activities.
What must a covered entity do when a breach of unsecured PHI affects 500 or more individuals in a state?
Answer: Notify affected individuals, HHS, and prominent media outlets in the affected state within 60 days
For breaches affecting 500 or more individuals in a state, covered entities must notify affected individuals, HHS, and prominent media outlets in that state within 60 days of discovery.
What is a business associate agreement (BAA) under HIPAA?
Answer: A written contract requiring business associates to appropriately safeguard PHI they access on behalf of a covered entity
A BAA is a written contract between a covered entity and a business associate that requires the business associate to protect PHI and comply with applicable HIPAA requirements.