HIPAA Privacy and Security Flashcards
7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 HIPAA Privacy and Security flashcards as text
Which of the following transactions is covered under HIPAA's Electronic Transaction Standards?
Answer: Electronic claims submission (837 transaction set)
HIPAA's Transaction Standards mandate the use of standard electronic formats (like the 837 claim) for healthcare financial and administrative transactions.
What is the primary purpose of a HIPAA Risk Analysis?
Answer: To identify potential threats and vulnerabilities to ePHI confidentiality, integrity, and availability
A HIPAA Risk Analysis identifies threats, vulnerabilities, and the likelihood and impact of potential risks to ePHI as the foundation of the security management process.
Under HIPAA, 'treatment' as a basis for PHI use/disclosure refers to:
Answer: Provision, coordination, or management of healthcare and related services by providers
HIPAA broadly defines 'treatment' to include provision, coordination, and management of healthcare by one or more providers, including referrals.
An individual's right to an accounting of disclosures under HIPAA applies to disclosures made for which purpose?
Answer: Public interest disclosures made without authorization
The right to an accounting of disclosures covers most disclosures made without authorization, but generally excludes those for TPO (treatment, payment, operations).
Which office within HHS is primarily responsible for enforcing HIPAA Privacy and Security Rules?
Answer: Office for Civil Rights (OCR)
The HHS Office for Civil Rights (OCR) is responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules.
Under HIPAA, psychotherapy notes receive special protection because:
Answer: They are separated from the medical record and require explicit authorization for most disclosures
Psychotherapy notes are singled out under HIPAA for heightened protection and generally require individual authorization for disclosure, even for TPO purposes.
A small physician practice with fewer than 10 full-time employees that transmits claims electronically is considered a:
Answer: Covered entity
Any healthcare provider that transmits health information in electronic form in connection with a HIPAA-covered transaction is a covered entity, regardless of size.