Release of Information and Privacy Practices Flashcards
6 cards from real RHIT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Release of Information and Privacy Practices flashcards as text
Under HIPAA, what is a Business Associate Agreement (BAA)?
Answer: A written contract ensuring vendors who access PHI protect it in accordance with HIPAA
A BAA is a required contract between a covered entity and a business associate that establishes the permitted uses and required safeguards for PHI the associate handles.
What fees may a covered entity charge for releasing records to a patient?
Answer: Only a reasonable, cost-based fee including labor, supplies, and postage
HIPAA and the HITECH Act permit covered entities to charge only reasonable, cost-based fees for providing copies of PHI, which may include labor, supplies, and postage.
When releasing records for legal purposes such as litigation, which best practice protects the facility?
Answer: Document every step of the release process and retain copies of authorizations and release logs
Thorough documentation of the ROI process—including authorizations, release logs, and staff attestations—protects the facility during legal disputes or audits.
What is the retention requirement for adult patient records under most U.S. state laws?
Answer: A minimum of 5 to 10 years, varying by state law
Most states require retention of adult medical records for a minimum of 5 to 10 years, though specific requirements vary; facilities must follow the more stringent of state or federal requirements.
A covered entity discovers that a laptop containing unencrypted PHI was stolen. What is the required action under HIPAA?
Answer: Conduct a breach risk assessment and notify affected individuals, HHS, and possibly the media if required
Under the HIPAA Breach Notification Rule, covered entities must conduct a risk assessment and, if a breach is confirmed, notify affected individuals, HHS, and potentially the media for large breaches.
Which of the following best describes the concept of 'de-identification' under HIPAA?
Answer: Removing 18 specified identifiers so the information cannot identify an individual
HIPAA's Safe Harbor de-identification method requires removal of 18 specific identifiers, after which the information is no longer considered PHI and HIPAA restrictions no longer apply.