Insurance Laws and Regulations Flashcards
11 cards from real RIBO practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 11 Insurance Laws and Regulations flashcards as text
Which of the following is NOT a best practice for privacy and security?
Answer: Documents containing PHI do not need to be shredded
The statement 'Documents containing PHI do not need to be shredded' is NOT a best practice for privacy and security; it is a false statement. Documents containing Protected Health Information (PHI) must be securely disposed of, typically through shredding, to prevent unauthorized access and maintain patient privacy. The other options listed are all examples of best practices.
You always abide by the HIPAA privacy rule.
Answer: FALSE
The statement 'You always abide by the HIPAA privacy rule' is FALSE. While one *should* always strive to abide by HIPAA, claiming absolute, unwavering adherence 100% of the time is unrealistic. Unintentional errors or minor oversights can occur, making a blanket statement of 'always' practically false for any individual or organization.
pHI stands for Private Health Information.
Answer: FALSE
The statement 'pHI stands for Private Health Information' is FALSE. pHI actually stands for Protected Health Information. This is a specific term defined under HIPAA (Health Insurance Portability and Accountability Act) to refer to individually identifiable health information that is transmitted or maintained in any form or medium.
Clients need to receive a copy of the Notice of Privacy Practices.
Answer: TRUE
Under HIPAA, it is TRUE that clients need to receive a copy of the Notice of Privacy Practices (NPP). This document informs them about how their Protected Health Information (PHI) may be used and disclosed, and outlines their rights regarding their health information, ensuring transparency and empowering individuals.
Confidentiality means that data is not to be made available to unauthorized persons.
Answer: TRUE
The statement 'Confidentiality means that data is not to be made available to unauthorized persons' is TRUE. This is the fundamental definition of confidentiality in the context of information security and privacy. It ensures that sensitive information is protected from inappropriate access or disclosure to individuals who do not have a legitimate need or authorization to view it.
How many major concepts are associated with the privacy rule?
Answer: Two
The HIPAA Privacy Rule is primarily associated with two major concepts: the 'Use and Disclosure of PHI' and 'Individual Rights.' These concepts govern how Protected Health Information can be handled by covered entities and the rights individuals have concerning their own health information, such as the right to access or amend their records.
Which of the following information is generally considered confidential?
Answer: All of the Above
All the listed categories—demographics, diagnosis, billing information, and dates of service—are generally considered confidential and fall under Protected Health Information (PHI) when linked to an individual. Any information that can identify a person and relates to their health condition, healthcare provision, or payment for healthcare is protected under HIPAA.
A person's phone number is not considered pHI because it can be located in an online or paper telephone directory.
Answer: FALSE
The statement 'A person's phone number is not considered pHI because it can be located in an online or paper telephone directory' is FALSE. A phone number, when linked to an individual's health information or used in a healthcare context, is considered Protected Health Information (PHI). Its public availability does not negate its status as PHI when it's part of a medical record or used in conjunction with other identifying health information.
If you see other staff violating privacy policies, you should
Answer: Both answer B & C
If you see other staff violating privacy policies, the best course of action is to both give them a helpful, gentle reminder and report problems and violations. A gentle reminder can correct immediate issues and educate colleagues, while reporting ensures that serious or persistent violations are addressed by management to maintain compliance and prevent future breaches.
You work in the billing department of your agency, and while processing claims, you notice the name of someone you know. Since you are curious, you decide to investigate, and you pull their medical record and read it. Is this appropriate?
Answer: No
No, accessing a client's medical record out of personal curiosity is inappropriate and a violation of privacy policies and ethical conduct. You should only access Protected Health Information (PHI) when it is necessary for your job duties and within the scope of your authorized access. This action constitutes a clear breach of confidentiality.
You receive a call from staff at a local hospital stating that they need information regarding a former client of yours who is scheduled for surgery. They fax you a release of information form that only authorizes the release of medications, but the person on the phone is asking for dates of treatment and diagnoses. How would you respond?
Answer: Release information regarding medications only
You should release information regarding medications only. The release of information form specifically authorizes only the release of medications. Releasing additional information like dates of treatment and diagnoses, even if requested by hospital staff, would be a violation of the client's privacy rights and HIPAA, as it exceeds the scope of the authorized consent.