HIPAA Privacy and Security Flashcards
7 cards from real RHIT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 HIPAA Privacy and Security flashcards as text
Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals of a breach within:
Answer: 60 days of discovery
Covered entities must notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach.
A healthcare worker accesses a colleague's medical record out of curiosity without any treatment purpose. This is a violation of which HIPAA concept?
Answer: Minimum necessary standard
Accessing records without a job-related need violates the minimum necessary standard, which prohibits accessing more PHI than required for one's role.
Which of the following is a required implementation specification under the HIPAA Security Rule's administrative safeguards?
Answer: Security management process
Security management process is a required administrative safeguard that includes conducting risk analyses and implementing risk management procedures.
A patient asks a covered entity to restrict disclosure of PHI to their health plan for services paid out-of-pocket. The covered entity must:
Answer: Comply with the restriction
Under the HITECH Act amendment to HIPAA, covered entities must honor a patient's request to restrict disclosure to a health plan when the patient has paid out-of-pocket in full.
Which HIPAA provision allows patients to request corrections to their medical records?
Answer: Right to amend
The right to amend allows patients to request corrections to inaccurate or incomplete PHI in a covered entity's designated record set.
Which of the following constitutes a permissible disclosure of PHI without patient authorization?
Answer: Disclosing PHI to public health authorities for disease reporting
HIPAA permits disclosure to public health authorities for activities such as disease reporting, injury surveillance, and public health investigations.
The HIPAA Privacy Rule's 'treatment, payment, and operations' (TPO) provision allows covered entities to:
Answer: Use and disclose PHI without patient authorization for TPO purposes
HIPAA allows covered entities to use and disclose PHI without patient authorization when the purpose is treatment, payment, or healthcare operations.