โ† All CHC Flashcard Decks

HIPAA Privacy and Security Flashcards

7 cards from real CHC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 HIPAA Privacy and Security flashcards as text
  1. Under HIPAA's Security Rule, 'integrity' of ePHI means:

    Answer: ePHI is not altered or destroyed in an unauthorized manner

    Integrity under the Security Rule means ensuring that ePHI is not altered or destroyed in an unauthorized manner.

  2. A Business Associate Agreement (BAA) must include which of the following provisions?

    Answer: Permitted and required uses and disclosures of PHI by the business associate

    A BAA must describe the permitted and required uses and disclosures of PHI that the business associate may make on behalf of the covered entity.

  3. Which HIPAA standard governs the electronic exchange of health information for claims and remittance advice?

    Answer: The Transactions and Code Sets Rule

    The HIPAA Transactions and Code Sets Rule establishes standards for electronic health care transactions, including claims and remittance advice using ASC X12 standards.

  4. A covered entity discovers a breach on March 1. By what date must affected individuals be notified?

    Answer: April 30 (within 60 days)

    Individuals must be notified of a breach without unreasonable delay and no later than 60 days following discovery of the breach.

  5. Under HIPAA, which of the following represents a permissible secondary use of PHI for research without patient authorization?

    Answer: Using a limited data set with a data use agreement for research

    A covered entity may share a limited data set (with certain direct identifiers removed) for research under a data use agreement without patient authorization.

  6. Which of the following is an example of a 'physical safeguard' required under the HIPAA Security Rule?

    Answer: Facility access controls limiting physical access to systems containing ePHI

    Facility access controls, such as locked server rooms and badge access, are physical safeguards under the Security Rule.

  7. Under the HIPAA Privacy Rule, which of the following is a required element of a valid patient authorization?

    Answer: A statement that the individual may revoke the authorization in writing

    A valid HIPAA authorization must include a statement that the individual has the right to revoke the authorization in writing.