Mixed Deck — All CHP Topics Flashcards
100 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CHP Topics flashcards as text
Which element is NOT required to be included in a Business Associate Agreement under HIPAA?
Answer: The specific dollar amount of penalties if the business associate causes a breach
BAAs must include permitted uses, breach reporting obligations, and PHI return/destruction terms, but they are not required to specify exact penalty dollar amounts.
Which of the following HIPAA audit scenarios would most likely result in the highest civil money penalty tier?
Answer: Willful neglect of HIPAA requirements that was not corrected within the required timeframe
The highest penalty tier applies to violations due to willful neglect that are not corrected, with penalties up to $1.9 million per violation category per year.
Who enforces HIPAA compliance audits?
Answer: OCR
The Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS) is the primary federal agency responsible for enforcing HIPAA compliance. The OCR investigates complaints, conducts compliance reviews, and performs audits to ensure covered entities and business associates adhere to the Privacy, Security, and Breach Notification Rules. They have the authority to impose civil monetary penalties for violations.
A nurse's personal smartphone is used to photograph wound progress for the patient record. Under HIPAA, this practice requires:
Answer: A formal BYOD policy that addresses ePHI handling, encryption, and remote wipe capability
BYOD (Bring Your Own Device) programs must include formal policies covering ePHI safeguards such as encryption, containerization, and remote wipe to comply with the HIPAA Security Rule.
A clinical workstation has not received operating system security patches in 18 months due to compatibility concerns with legacy software. Under HIPAA, this situation requires:
Answer: A documented risk analysis and compensating controls to mitigate known vulnerabilities
When patching is not feasible, HIPAA requires a documented risk analysis identifying the risk level and implementation of compensating controls (e.g., network isolation) to reduce risk.
In physiology, 'peristalsis' refers to the wave-like muscle contractions that move substances through which organ system?
Answer: Digestive system
Peristalsis is the rhythmic, wave-like muscular contractions that propel food and waste through the digestive tract.
What is the penalty for a HIPAA violation due to willful neglect?
Answer: Fines ranging from $10,000 to $50,000 per violation
HIPAA violations are categorized by culpability, with willful neglect being the most severe. Willful neglect means a conscious indifference or reckless disregard of the HIPAA rules. Penalties for such violations are substantial, ranging from $10,000 to $50,000 per violation, and can accumulate to a maximum of $1.5 million per calendar year for identical violations, underscoring the importance of strict compliance.
When a patient's clinical evaluation reveals information about a communicable disease, a covered entity may disclose PHI to public health authorities:
Answer: Without authorization as a permitted public health activity
HIPAA permits disclosure to public health authorities to prevent or control disease without patient authorization under the public health activities exception.
Which of the following is an example of a technical safeguard that also supports infection control by reducing the need for physical contact with shared input devices?
Answer: Implementing voice-activated or hands-free authentication and documentation systems
Voice-activated or hands-free systems reduce touchpoint contamination risks while also leveraging advanced authentication methods that can satisfy HIPAA technical safeguard requirements.
Which of the following PHI disclosure scenarios qualifies for the 'limited data set' exception and is NOT treated as a breach?
Answer: Disclosing a limited data set under a data use agreement for research
Disclosure of a limited data set (with direct identifiers removed) under a proper data use agreement (DUA) is a permitted HIPAA disclosure and does not constitute a breach.
A third-party technician needs to repair a server containing ePHI. What must be in place before granting access?
Answer: A Business Associate Agreement (BAA) with the vendor
Any vendor whose work may expose them to ePHI must have a BAA with the covered entity before being granted access, as required by the HIPAA Privacy and Security Rules.
A covered entity that shares PHI with a vendor without executing a required BAA is subject to:
Answer: HIPAA civil monetary penalties and potential corrective action
Sharing PHI without a required BAA is itself a HIPAA violation exposing the covered entity to civil monetary penalties and OCR corrective action, regardless of whether a breach occurs.
A physician discovers that a colleague is impaired while on duty. The physician's ethical obligation under most professional codes is to:
Answer: Report the impairment to appropriate supervisory or licensing authorities
Professional ethics require reporting an impaired colleague to protect patient safety, which takes precedence over collegial loyalty.
A patient involved in a clinical trial has treatment protocols managed by both the trial sponsor and a covered entity. HIPAA applies to:
Answer: Only the covered entity's use and disclosure of PHI
HIPAA obligations apply specifically to covered entities; the trial sponsor is governed by HIPAA only if it independently qualifies as a covered entity or business associate.
Which HIPAA Security Rule standard governs procedures for creating and restoring ePHI backup copies from medical equipment?
Answer: Contingency Plan — Data Backup Plan (§164.308(a)(7)(ii)(A))
The Contingency Plan's Data Backup Plan implementation specification requires establishing and implementing procedures to create and maintain exact retrievable copies of ePHI.
What is the primary purpose of conducting a comprehensive patient assessment in Certified Hijama Practitioner practice?
Answer: To establish baseline measurements and identify treatment needs
Comprehensive patient assessment establishes baseline measurements and identifies specific treatment needs, forming the foundation for effective care planning.
A research hospital wants to use patient data for a new study. To maintain ethical standards, participants must provide:
Answer: Written informed consent that is voluntary and comprehension-based
Research ethics require prospective, voluntary, written informed consent that ensures participants understand risks and benefits.
Which of the following is NOT a required element of a HIPAA Business Associate Agreement?
Answer: The business associate's annual revenue and profit margins
Financial figures such as annual revenue are not required elements of a HIPAA Business Associate Agreement.
During a public health emergency involving an infectious disease outbreak, a covered entity wants to share patient PHI with public health authorities without patient authorization. Which HIPAA provision permits this?
Answer: The Public Health Activities exception allows disclosure to public health authorities authorized by law to collect data
HIPAA's Public Health Activities exception (45 CFR § 164.512(b)) permits covered entities to disclose PHI to authorized public health authorities for activities such as disease surveillance and outbreak response.
A healthcare organization's contingency plan must address maintaining access to ePHI during facility emergencies such as a fire or infectious disease outbreak. This plan is primarily required by which HIPAA standard?
Answer: Administrative Safeguards — Contingency Plan
The Contingency Plan standard under Administrative Safeguards (45 CFR § 164.308(a)(7)) requires covered entities to have policies for responding to emergencies that damage systems containing ePHI.