HIPAA Privacy and Security Flashcards
7 cards from real CHC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 HIPAA Privacy and Security flashcards as text
Under HIPAA, which of the following is NOT considered Protected Health Information (PHI)?
Answer: De-identified health data that meets Safe Harbor standards
De-identified data that meets HIPAA's Safe Harbor or Expert Determination standards is not PHI and is not subject to HIPAA protections.
A covered entity experiences a breach affecting 600 individuals. What is the notification deadline to the Secretary of HHS?
Answer: Within 60 days of discovery
Breaches affecting 500 or more individuals must be reported to HHS within 60 days of discovery.
What is the HIPAA Security Rule's requirement for a covered entity's risk analysis?
Answer: It must be an accurate and thorough assessment of risks to ePHI
The Security Rule requires covered entities to conduct an accurate and thorough assessment of potential risks and vulnerabilities to ePHI confidentiality, integrity, and availability.
Under the HIPAA Privacy Rule, a patient's right to request restrictions on use or disclosure of their PHI means the covered entity:
Answer: Must honor requests to restrict disclosures to health plans for services paid out-of-pocket in full
Covered entities must agree to a patient's request to restrict disclosures to health plans when the patient pays for the service entirely out-of-pocket.
Which HIPAA Security Rule safeguard category includes policies and procedures to manage the selection and use of technical security measures?
Answer: Administrative safeguards
Administrative safeguards include policies and procedures that govern the selection and use of technical and physical security measures to protect ePHI.
A healthcare provider shares PHI with a medical billing company. Under HIPAA, the billing company is classified as a:
Answer: Business associate
A medical billing company that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a business associate under HIPAA.
The HIPAA Breach Notification Rule's 'harm threshold' was eliminated by which regulation, requiring notification for all breaches unless the low probability of compromise is demonstrated?
Answer: The Omnibus Rule of 2013
The 2013 Omnibus Rule replaced the harm threshold with a four-factor risk assessment, requiring notification unless the covered entity demonstrates a low probability that PHI was compromised.