← All CHP Flashcard Decks

HIPAA Privacy & Security Rules Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 HIPAA Privacy & Security Rules flashcards as text
  1. Under the HIPAA Breach Notification Rule, what threshold determines whether a breach requires notification to HHS and potentially the media?

    Answer: A breach affecting more than 500 individuals in a state or jurisdiction

    Breaches affecting more than 500 individuals in a state or jurisdiction require immediate HHS notification and prominent media notice in that area.

  2. Which of the following is NOT one of the 18 identifiers that must be removed to achieve safe harbor de-identification under HIPAA?

    Answer: Blood type

    Blood type is not one of the 18 enumerated identifiers under HIPAA's Safe Harbor de-identification method; it is clinical data that cannot be used to identify an individual.

  3. A covered entity's workforce member sees a celebrity patient in the ED and texts a friend the diagnosis. This is best described as a:

    Answer: Unauthorized disclosure and potential breach

    Texting patient PHI to unauthorized individuals is an impermissible disclosure and must undergo a breach risk assessment to determine if notification is required.

  4. The HIPAA Security Rule's Technical Safeguard standard for Transmission Security requires covered entities to:

    Answer: Implement technical security measures to guard against unauthorized access to ePHI transmitted over electronic networks

    Transmission Security requires measures — such as encryption — to protect ePHI transmitted over electronic communications networks from unauthorized interception.

  5. Under HIPAA, a 'covered entity' includes which of the following?

    Answer: A health plan, health care clearinghouse, or health care provider that transmits PHI electronically

    HIPAA defines covered entities as health plans, health care clearinghouses, and health care providers that transmit any PHI in electronic form in connection with covered transactions.

  6. Which of the following best describes the 'Conduit Exception' in HIPAA?

    Answer: Organizations that only transport PHI without accessing it are not business associates

    The Conduit Exception applies to entities like postal services or ISPs that merely transport PHI without accessing its content, exempting them from the business associate definition.

  7. A covered entity must designate which role to be responsible for developing and implementing HIPAA Privacy Rule policies?

    Answer: Privacy Officer

    The Privacy Rule requires covered entities to designate a Privacy Officer responsible for developing and implementing the entity's privacy policies and procedures.

HIPAA Privacy & Security Rules Flashcards — CHP Study Cards with Answers