← All AAPC Flashcard Decks

HIPAA & Healthcare Compliance Regulations Flashcards

6 cards from real AAPC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 HIPAA & Healthcare Compliance Regulations flashcards as text
  1. What is the 'minimum necessary' standard under HIPAA?

    Answer: The principle that only the minimum amount of PHI necessary to accomplish the purpose should be used or disclosed

    The minimum necessary standard requires that covered entities limit PHI use and disclosure to only what is reasonably necessary for the intended purpose.

  2. Under HIPAA, when is a patient authorization required to disclose PHI?

    Answer: For disclosures to third parties for purposes other than treatment, payment, or healthcare operations

    A written patient authorization is required for disclosures beyond treatment, payment, healthcare operations, and other permitted purposes outlined in the Privacy Rule.

  3. Which federal agency is primarily responsible for enforcing HIPAA?

    Answer: Office for Civil Rights (OCR) within HHS

    The HHS Office for Civil Rights (OCR) enforces the HIPAA Privacy, Security, and Breach Notification Rules.

  4. What is a Notice of Privacy Practices (NPP) under HIPAA?

    Answer: A document that informs patients how their health information may be used and their privacy rights

    Covered entities must provide patients with an NPP describing how PHI is used, patient rights, and the entity's legal duties regarding PHI.

  5. What is the maximum civil penalty per violation category under HIPAA for 'willful neglect — not corrected'?

    Answer: $50,000 per violation with a $1.9 million annual cap

    The highest HIPAA penalty tier for willful neglect that is not corrected is $50,000 per violation, with an annual cap of $1.9 million for identical violations.

  6. What is the HIPAA Breach Notification Rule?

    Answer: A requirement to notify affected individuals, HHS, and sometimes the media following a breach of unsecured PHI

    The Breach Notification Rule requires covered entities to notify patients within 60 days of discovering a breach, and to notify HHS and possibly media for large breaches.