← All RHIT Flashcard Decks

HIPAA Privacy and Security Flashcards

7 cards from real RHIT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 HIPAA Privacy and Security flashcards as text
  1. Under HIPAA, which of the following is a 'hybrid entity'?

    Answer: An organization that is only partially a covered entity but performs both covered and non-covered functions

    A hybrid entity is an organization whose covered functions are not its primary business, allowing it to designate specific healthcare components as subject to HIPAA.

  2. What is the maximum civil monetary penalty per violation category under HIPAA if the covered entity did not know of the violation?

    Answer: $100 per violation, up to $25,000 annually

    For violations where the entity did not know and could not have known, the penalty is $100–$50,000 per violation, with a $25,000 annual cap for identical violations.

  3. Which safeguard category under the HIPAA Security Rule includes unique user identification and automatic logoff?

    Answer: Technical safeguards

    Technical safeguards include access controls such as unique user IDs, automatic logoff, and encryption mechanisms to protect ePHI.

  4. A covered entity discovers a potential breach. The HIPAA breach notification rule presumes that an impermissible use or disclosure is a breach unless:

    Answer: A low probability assessment shows the PHI was not compromised

    The covered entity can rebut the presumption of breach by demonstrating through a four-factor risk assessment that there is a low probability the PHI was compromised.

  5. Which of the following must be included in an accounting of disclosures provided to a patient?

    Answer: Disclosures made without authorization for purposes other than TPO

    Accounting of disclosures covers disclosures made without authorization, excluding those for treatment, payment, and operations.

  6. A covered entity receives a subpoena for a patient's medical records. Under HIPAA, the covered entity may disclose the records if:

    Answer: Satisfactory assurances are provided that the patient was notified or a protective order is in place

    HIPAA allows disclosure pursuant to a subpoena if satisfactory assurances are received that the individual was notified or that a qualified protective order has been issued.

  7. Which of the following best describes 'addressable' implementation specifications under the HIPAA Security Rule?

    Answer: They must be implemented if reasonable and appropriate, or an equivalent alternative used

    Addressable specifications require covered entities to assess whether the specification is reasonable and appropriate; if not, they must document why and implement an equivalent measure.