← All CBCS Flashcard Decks

Regulatory Compliance and HIPAA Flashcards

6 cards from real CBCS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Regulatory Compliance and HIPAA flashcards as text
  1. What are the four HIPAA Administrative Simplification standards?

    Answer: Transactions and Code Sets, Privacy, Security, and National Identifier standards

    HIPAA's Administrative Simplification provisions include: (1) Transactions and Code Sets, (2) Privacy Rule, (3) Security Rule, and (4) National Identifier standards (NPI, employer identifier).

  2. What constitutes Protected Health Information (PHI) under HIPAA?

    Answer: Individually identifiable health information in any form (electronic, paper, oral) held or transmitted by a covered entity or business associate

    PHI is any individually identifiable health information in any format (electronic, paper, verbal) that relates to a person's past, present, or future physical or mental health condition, provision of healthcare, or payment for healthcare.

  3. What is a Business Associate Agreement (BAA) under HIPAA?

    Answer: A written contract between a covered entity and a business associate that specifies permitted uses of PHI and requires the business associate to protect PHI

    A BAA is a legally required contract between a covered entity and any business associate who may access, use, or disclose PHI in the course of performing services. It specifies permitted uses and requires appropriate safeguards.

  4. What is the HIPAA Security Rule's requirement for electronic PHI (ePHI)?

    Answer: Covered entities must implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI

    The Security Rule requires covered entities and business associates to implement three types of safeguards — administrative, physical, and technical — to protect ePHI from unauthorized access, use, or disclosure.

  5. What are patients' rights under the HIPAA Privacy Rule?

    Answer: Rights including access to their PHI, request for amendments, accounting of disclosures, right to restrict certain uses/disclosures, and right to receive confidential communications

    The HIPAA Privacy Rule gives patients specific rights: access their health records, request corrections (amendments), obtain an accounting of certain disclosures, request restrictions on use/disclosure, and receive confidential communications.

  6. What is a HIPAA breach and what are the notification requirements?

    Answer: An impermissible acquisition, access, use, or disclosure of PHI that compromises its security or privacy, requiring notifications to individuals, HHS, and potentially the media

    A HIPAA breach is an impermissible use or disclosure of unsecured PHI that is presumed to be a breach unless a risk assessment shows low probability that PHI was compromised. Notification to affected individuals, HHS, and (for large breaches) media is required.