- Registered Health Information Technician HIPAA Privacy and Security Flashcards
6 cards from real RHIT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 - Registered Health Information Technician HIPAA Privacy and Security flashcards as text
What is the difference between HIPAA's Privacy Rule and Security Rule?
Answer: The Privacy Rule governs use and disclosure of all PHI while the Security Rule addresses protection of electronic PHI
The Privacy Rule covers all forms of PHI; the Security Rule specifically addresses ePHI protection through three safeguard categories.
A patient requests access to their complete medical record. Within what timeframe must the covered entity respond?
Answer: Within 30 days, with one 30-day extension if needed
HIPAA requires action within 30 days with one possible 30-day extension.
What constitutes a 'breach' under the HIPAA Breach Notification Rule?
Answer: An impermissible use or disclosure of PHI that compromises security or privacy
A breach is an impermissible use or disclosure that compromises PHI security or privacy.
Which HIPAA Security Rule safeguard category includes workforce training?
Answer: Administrative safeguards
Security awareness and training is an administrative safeguard.
What is the HIPAA 'accounting of disclosures' requirement?
Answer: The right of patients to receive a list of certain disclosures of their PHI during the prior six years
Patients can request an accounting of PHI disclosures made in the six years prior to the request.
What is encryption and why is it important for ePHI?
Answer: Converting data into an unreadable coded format that can only be decoded with the proper key
Encryption transforms readable data into an unreadable format using an algorithm and key.