โ† All CCT Flashcard Decks

HIPAA Privacy and Security Flashcards

7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 HIPAA Privacy and Security flashcards as text
  1. A hospital's employee inappropriately accesses the medical records of a celebrity patient. Which type of HIPAA breach is this?

    Answer: Unauthorized internal access

    Accessing PHI without a valid treatment, payment, or operations reason by an insider constitutes unauthorized internal access, a common HIPAA violation.

  2. Under the HIPAA Breach Notification Rule, covered entities must notify affected individuals of a breach within:

    Answer: 60 calendar days

    The Breach Notification Rule requires covered entities to notify affected individuals without unreasonable delay and within 60 calendar days of discovering the breach.

  3. What is 'minimum necessary' under HIPAA?

    Answer: Disclosing only the PHI needed to accomplish the intended purpose

    The minimum necessary standard requires covered entities to limit PHI use and disclosure to what is needed for the specific purpose.

  4. Which of the following is a permitted use of PHI WITHOUT patient authorization under HIPAA?

    Answer: Public health activities to control disease

    HIPAA permits disclosure of PHI for public health activities, such as reporting disease outbreaks, without patient authorization.

  5. A covered entity discovers a breach on March 1. By what date must it notify the Secretary of HHS if fewer than 500 individuals are affected?

    Answer: Within 60 days of the following calendar year (by March 1 of the next year)

    For breaches affecting fewer than 500 individuals, covered entities must log and report to HHS annually, no later than 60 days after the end of the calendar year in which the breach occurred.

  6. Under HIPAA, which of the following is a physical safeguard required by the Security Rule?

    Answer: Facility access controls to limit physical access to systems containing ePHI

    Facility access controls are a required physical safeguard under the HIPAA Security Rule, governing who may physically enter areas housing ePHI.

  7. A covered entity may deny a patient's request to amend their PHI if:

    Answer: The PHI was not created by the covered entity

    A covered entity may deny an amendment request if it did not create the PHI and the originating entity is available to act on the request.