← All CHP Flashcard Decks

HIPAA Privacy & Security Rules Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 HIPAA Privacy & Security Rules flashcards as text
  1. Under the HIPAA Privacy Rule, what is the maximum period a covered entity may maintain an authorization form signed by an individual?

    Answer: 6 years from the date of creation or last effective date

    The Privacy Rule requires covered entities to retain documentation, including signed authorizations, for 6 years from the date of creation or the date it was last in effect, whichever is later.

  2. Which of the following constitutes a valid expiration for a HIPAA authorization?

    Answer: All of the above

    A valid authorization must include an expiration date, event, or condition, and any of these three options satisfies that requirement under the Privacy Rule.

  3. A hospital's Privacy Officer discovers a workforce member improperly accessed 15 patient records out of curiosity with no malicious intent. What is the FIRST step the Privacy Officer should take?

    Answer: Document the breach and assess whether notification is required

    The first step is to document the incident and perform a breach risk assessment to determine if notification obligations under the Breach Notification Rule are triggered.

  4. Under the Security Rule, which of the following is an ADDRESSABLE implementation specification?

    Answer: Automatic logoff

    Automatic logoff is an addressable specification, meaning covered entities must implement it if reasonable and appropriate, or document why an equivalent alternative was chosen.

  5. A business associate experiences a ransomware attack that encrypts ePHI. Under HIPAA, when does the covered entity's breach notification clock typically start?

    Answer: When the BA notifies the covered entity

    Under the Breach Notification Rule, the 60-day notification clock for the covered entity starts when the business associate notifies the covered entity of the breach.

  6. Which of the following is NOT one of the five titles of HIPAA?

    Answer: Electronic Health Record Mandate

    HIPAA's five titles cover portability, fraud prevention, tax provisions, group health plan requirements, and revenue offsets — there is no EHR mandate title.

  7. A patient requests an amendment to their medical record. The covered entity may deny the amendment if:

    Answer: The information was not created by the covered entity

    A covered entity may deny an amendment request if the information was not created by that entity and the originating entity is still available to process the amendment.