โ† All RHIT Flashcard Decks

HIPAA Privacy and Security Flashcards

7 cards from real RHIT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 HIPAA Privacy and Security flashcards as text
  1. Under HIPAA, which of the following is considered a 'covered entity'?

    Answer: A health plan that pays for medical care

    Health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically are the three categories of covered entities under HIPAA.

  2. A patient requests access to their medical records. Under HIPAA, the covered entity must provide access within how many days?

    Answer: 30 days

    HIPAA requires covered entities to provide access to requested records within 30 days, with one 30-day extension allowed if the entity notifies the patient.

  3. Which HIPAA rule establishes national standards for protecting electronic PHI?

    Answer: Security Rule

    The HIPAA Security Rule specifically addresses the protection of electronic protected health information (ePHI) through administrative, physical, and technical safeguards.

  4. A business associate agreement (BAA) is required when a vendor performs which type of function?

    Answer: Processes PHI on behalf of a covered entity

    A BAA is required when a vendor creates, receives, maintains, or transmits PHI on behalf of a covered entity.

  5. Which of the following is an example of a physical safeguard under the HIPAA Security Rule?

    Answer: Using facility access controls to limit entry to data centers

    Physical safeguards include facility access controls, workstation use policies, and device and media controls to protect physical access to ePHI.

  6. Under HIPAA's minimum necessary standard, how much PHI should be disclosed?

    Answer: Only the information reasonably necessary to accomplish the purpose

    The minimum necessary standard requires covered entities to disclose only the amount of PHI needed to fulfill the specific purpose of the request.

  7. Which of the following is NOT included in HIPAA's definition of protected health information (PHI)?

    Answer: De-identified health information

    De-identified information has had all 18 HIPAA identifiers removed and is no longer considered PHI, making it not subject to HIPAA protections.