โ† All CHP Flashcard Decks

Regulatory Compliance & Standards Flashcards

7 cards from real CHP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Standards flashcards as text
  1. A covered entity uses a cloud service provider to store electronic PHI. Under HIPAA, the cloud provider is classified as:

    Answer: A business associate requiring a BAA

    Cloud service providers that store or process ePHI on behalf of a covered entity are business associates and require a BAA, even if they only maintain encrypted data.

  2. Which of the following best describes the 'conduit exception' under HIPAA?

    Answer: Entities that only transmit PHI without routine access are not business associates

    The conduit exception applies to entities like postal services or certain telecommunications firms that transport PHI without routine access to its content.

  3. Under the HIPAA Security Rule, a risk analysis is classified under which type of safeguard?

    Answer: Administrative safeguard

    Conducting a risk analysis is an administrative safeguard requirement under the Security Rule and is foundational to a covered entity's security program.

  4. A hospital's privacy officer learns that a workforce member accessed the medical records of a neighbor without a treatment relationship. This is best described as:

    Answer: A workforce sanction event and potential breach requiring investigation

    Unauthorized access by a workforce member to records without a legitimate purpose constitutes an impermissible use of PHI and triggers breach investigation and potential sanction.

  5. Which element is NOT required to be included in a Business Associate Agreement under HIPAA?

    Answer: The specific dollar amount of penalties if the business associate causes a breach

    BAAs must include permitted uses, breach reporting obligations, and PHI return/destruction terms, but they are not required to specify exact penalty dollar amounts.

  6. Which scenario qualifies as a 'healthcare operation' under HIPAA, permitting PHI use without patient authorization?

    Answer: Conducting internal quality improvement reviews of patient care

    Internal quality improvement and competency evaluations are healthcare operations under HIPAA, permitting PHI use without individual authorization.

  7. When must a covered entity provide an individual with an accounting of disclosures of their PHI?

    Answer: Within 60 days of receiving a written request, with one 30-day extension available

    Covered entities must provide the accounting within 60 days, with a single 30-day extension allowed if the individual is notified of the delay.