HIPAA Privacy and Security Flashcards
7 cards from real RHIT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 HIPAA Privacy and Security flashcards as text
Which of the following scenarios represents a valid use of the HIPAA 'limited data set'?
Answer: Sharing data with a researcher under a data use agreement with 16 identifiers removed
A limited data set excludes most direct identifiers but may include dates and geographic data; it can be shared for research, public health, or healthcare operations under a data use agreement.
Under the HITECH Act, which entities became directly liable for HIPAA compliance?
Answer: Business associates as well as covered entities
The HITECH Act extended direct HIPAA liability to business associates, meaning they are subject to HIPAA Security Rule requirements and civil and criminal penalties.
A hospital posts a notice on its website and in patient areas about its privacy practices. This document is known as the:
Answer: Notice of Privacy Practices (NPP)
The Notice of Privacy Practices (NPP) informs patients how their PHI may be used and disclosed and outlines their rights under HIPAA.
Which of the following is true regarding HIPAA and deceased individuals' PHI?
Answer: PHI of deceased individuals is protected for 50 years after death
HIPAA extends privacy protections to the PHI of deceased individuals for 50 years following their death.
An HIM professional sends a fax containing PHI to the wrong recipient. Under HIPAA, this is considered:
Answer: A potential breach requiring a risk assessment
A misdirected fax is an impermissible disclosure that triggers the four-factor risk assessment to determine if it constitutes a reportable breach.
Which of the following best describes the HIPAA 'right to request confidential communications'?
Answer: Patients can request that communications be made through alternative means or locations
Patients may request that covered entities communicate with them in a specific way or at a specific location, such as calling a work number instead of a home number.
Which office is responsible for enforcing HIPAA Privacy and Security Rules?
Answer: Office for Civil Rights (OCR) within HHS
The Office for Civil Rights (OCR) within the Department of Health and Human Services (HHS) is the primary federal agency responsible for enforcing HIPAA Privacy and Security Rules.