← All CCT Flashcard Decks

HIPAA Privacy and Security Flashcards

7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 HIPAA Privacy and Security flashcards as text
  1. Under HIPAA, which of the following is an example of a 'limited data set'?

    Answer: Dates of service and geographic data below state level with no direct identifiers

    A limited data set excludes direct identifiers but may include dates and geographic subdivisions below state level, and requires a data use agreement.

  2. Which HIPAA rule requires covered entities to implement policies protecting electronic protected health information (ePHI)?

    Answer: Security Rule

    The HIPAA Security Rule specifically governs the protection of ePHI through administrative, physical, and technical safeguards.

  3. A patient requests access to their medical records. Under HIPAA, the covered entity must provide access within how many days?

    Answer: 30 days

    HIPAA requires covered entities to act on a patient's request for access to their PHI within 30 days, with one 30-day extension allowed.

  4. What is the maximum civil monetary penalty per violation category under HIPAA for 'reasonable cause' (not willful neglect)?

    Answer: $10,000

    HIPAA penalties for 'reasonable cause' (not willful neglect) range up to $10,000 per violation, up to $100,000 per calendar year.

  5. Which of the following is NOT a required element of a valid HIPAA authorization?

    Answer: Signature of the covered entity's Privacy Officer

    A valid HIPAA authorization requires the individual's (not the Privacy Officer's) signature, along with description of PHI, expiration, and revocation rights.

  6. Under the HIPAA Security Rule, an 'addressable' implementation specification means:

    Answer: The covered entity must assess whether it is reasonable and appropriate, and document the decision

    Addressable specifications require covered entities to assess their applicability and either implement them, implement an alternative, or document why they are not reasonable and appropriate.

  7. Which entity type is primarily responsible for signing a Business Associate Agreement (BAA) with a covered entity?

    Answer: An organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity

    A BAA is required with business associates — entities that perform functions involving PHI on behalf of a covered entity.