← All CET Flashcard Decks

Regulatory Compliance & Legal Framework Flashcards

7 cards from real CET practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Legal Framework flashcards as text
  1. Under HIPAA's minimum necessary standard, a sonographer sharing echocardiography results should disclose:

    Answer: Only the information required for the specific purpose

    The minimum necessary standard limits disclosure to only the information needed to accomplish the intended purpose.

  2. A patient requests a copy of their echocardiogram report. Under HIPAA, the covered entity must provide access within:

    Answer: 30 days, with a possible 30-day extension

    HIPAA requires covered entities to provide access to PHI within 30 days, extendable by another 30 days with written notice.

  3. Which situation represents a permitted disclosure of PHI without patient authorization under HIPAA?

    Answer: Reporting a gunshot wound to law enforcement as required by state law

    HIPAA permits disclosures required by law, including mandatory reporting of certain injuries to law enforcement.

  4. When transmitting echocardiography images electronically, HIPAA Security Rule requires:

    Answer: Encryption and access controls for all ePHI in transit and at rest

    The HIPAA Security Rule requires administrative, physical, and technical safeguards—including encryption and access controls—for all electronic PHI.

  5. A HIPAA breach involving unsecured PHI of 600 patients requires notification to:

    Answer: Patients and HHS; media notification is also required for breaches over 500 in a state

    Breaches affecting 500+ individuals in a state or jurisdiction require notification to patients, HHS, and prominent media outlets in that state.

  6. Which action would violate the HIPAA Privacy Rule in an echo lab setting?

    Answer: Leaving a printed echo report visible at an unattended workstation

    Leaving PHI visible and unattended violates the Privacy Rule's requirement to protect against incidental disclosures.

  7. A patient revokes their authorization for a research study using their echo images. The covered entity must:

    Answer: Honor the revocation for future use but may retain already-collected data

    Revocation stops future use of PHI but does not retroactively invalidate actions already taken under the original authorization.