HIPAA Privacy and Security Flashcards
7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 HIPAA Privacy and Security flashcards as text
What is a 'hybrid entity' under HIPAA?
Answer: A single legal entity that performs both covered and non-covered functions, and has designated its healthcare components
A hybrid entity is a single organization that performs both covered and non-covered functions, and HIPAA applies only to its designated healthcare component(s).
Under the HIPAA Security Rule, which of the following is a 'required' (not addressable) implementation specification?
Answer: Unique user identification for each system user
Unique user identification is a required implementation specification under the Access Control standard of the HIPAA Security Rule's Technical Safeguards.
If a business associate discovers a breach of PHI, they must notify the covered entity within:
Answer: Without unreasonable delay and no later than 60 calendar days of discovery
Business associates must notify covered entities of PHI breaches without unreasonable delay and within 60 calendar days of discovering the breach.
Which of the following scenarios qualifies as a HIPAA-compliant 'de-identification' method?
Answer: Removing all 18 specific identifiers listed in the Safe Harbor method
The Safe Harbor method requires removal of all 18 enumerated identifiers, after which the data is no longer considered PHI under HIPAA.
A covered entity may share PHI with a patient's family member without authorization when:
Answer: The patient is present and does not object, or the covered entity can infer from the circumstances that the patient would not object
When a patient is present and does not object, or when a provider infers non-objection from circumstances, PHI directly relevant to the family member's involvement in care may be shared.
Under HIPAA's 'right to restrict' provision, a covered entity MUST honor a patient's request to restrict disclosure of PHI when:
Answer: The disclosure is to a health plan for payment purposes and the patient paid out-of-pocket in full for the service
HIPAA requires covered entities to honor restriction requests when a patient pays out-of-pocket in full and asks that the information not be disclosed to their health plan for payment purposes.
Which of the following is the correct hierarchy of HIPAA civil monetary penalty tiers (lowest to highest culpability)?
Answer: Unknowing → Reasonable cause → Willful neglect corrected → Willful neglect uncorrected
HIPAA penalty tiers escalate from unknowing violations, to reasonable cause, to willful neglect that is corrected, to willful neglect that is not corrected.